CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93851  CVE-2016-7031  Candidate  The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.  Assigned (20160823)  None (candidate not yet proposed)    View
93852  CVE-2016-7032  Candidate  sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.  Assigned (20160823)  None (candidate not yet proposed)    View
93853  CVE-2016-7033  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160823)  None (candidate not yet proposed)    View
93854  CVE-2016-7034  Candidate  The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token.  Assigned (20160823)  None (candidate not yet proposed)    View
93855  CVE-2016-7035  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160823)  None (candidate not yet proposed)    View

Page 18771 of 20943, showing 5 records out of 104715 total, starting on record 93851, ending on 93855

Actions