CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93851 | CVE-2016-7031 | Candidate | The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL. | Assigned (20160823) | None (candidate not yet proposed) | View | |
93852 | CVE-2016-7032 | Candidate | sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function. | Assigned (20160823) | None (candidate not yet proposed) | View | |
93853 | CVE-2016-7033 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20160823) | None (candidate not yet proposed) | View | |
93854 | CVE-2016-7034 | Candidate | The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token. | Assigned (20160823) | None (candidate not yet proposed) | View | |
93855 | CVE-2016-7035 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160823) | None (candidate not yet proposed) | View |
Page 18771 of 20943, showing 5 records out of 104715 total, starting on record 93851, ending on 93855