CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89605  CVE-2016-2786  Candidate  The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.  Assigned (20160229)  None (candidate not yet proposed)    View
24325  CVE-2007-0968  Candidate  Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.  Assigned (20070215)  None (candidate not yet proposed)    View
89861  CVE-2016-3042  Candidate  Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.  Assigned (20160309)  None (candidate not yet proposed)    View
24581  CVE-2007-1224  Candidate  Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).  Assigned (20070302)  None (candidate not yet proposed)    View
90117  CVE-2016-3298  Candidate  Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."  Assigned (20160315)  None (candidate not yet proposed)    View

Page 457 of 20943, showing 5 records out of 104715 total, starting on record 2281, ending on 2285

Actions