CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
89605 | CVE-2016-2786 | Candidate | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate. | Assigned (20160229) | None (candidate not yet proposed) | View | |
24325 | CVE-2007-0968 | Candidate | Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections. | Assigned (20070215) | None (candidate not yet proposed) | View | |
89861 | CVE-2016-3042 | Candidate | Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients. | Assigned (20160309) | None (candidate not yet proposed) | View | |
24581 | CVE-2007-1224 | Candidate | Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80). | Assigned (20070302) | None (candidate not yet proposed) | View | |
90117 | CVE-2016-3298 | Candidate | Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | Assigned (20160315) | None (candidate not yet proposed) | View |
Page 457 of 20943, showing 5 records out of 104715 total, starting on record 2281, ending on 2285