NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82325 | CVE-2016-3102 | The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations. | 2 | 7.5 | High | 2017-02-28 | 2017-02-28 | View | |
82324 | CVE-2016-3101 | Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-15 | View | |
82323 | CVE-2016-2866 | An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user. | 2 | 4 | Medium | 2017-02-15 | 2017-02-13 | View | |
82322 | CVE-2016-2788 | MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command. | 2 | 7.5 | High | 2017-03-18 | 2017-03-13 | View | |
82321 | CVE-2016-2787 | The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors. | 2017-02-15 | 2017-02-13 | View |
Page 1208 of 17672, showing 5 records out of 88360 total, starting on record 6036, ending on 6040