CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104409  CVE-2017-7589  Candidate  In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js.  Assigned (20170408)  None (candidate not yet proposed)    View
104410  CVE-2017-7590  Candidate  OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.  Assigned (20170408)  None (candidate not yet proposed)    View
104411  CVE-2017-7591  Candidate  OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.  Assigned (20170408)  None (candidate not yet proposed)    View
30116  CVE-2007-6759  Candidate  Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie.  Assigned (20170407)  None (candidate not yet proposed)    View
30117  CVE-2007-6760  Candidate  Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie.  Assigned (20170407)  None (candidate not yet proposed)    View

Page 643 of 20943, showing 5 records out of 104715 total, starting on record 3211, ending on 3215

Actions