NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82295 | CVE-2016-0307 | IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses. | 2 | 4 | Medium | 2017-02-15 | 2017-02-09 | View | |
82294 | CVE-2016-0305 | IBM Connections is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim"s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim"s cookie-based authentication credentials. | 2 | 3.5 | Low | 2017-02-15 | 2017-02-09 | View | |
82293 | CVE-2016-0270 | IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-15 | View | |
82292 | CVE-2016-0214 | IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way that file would be executed would be through a phishing attack to trick an unsuspecting victim to execute the file. | 2 | 6.8 | Medium | 2017-02-15 | 2017-02-15 | View | |
82291 | CVE-2016-0210 | IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to obtain sensitive information. By allowing HTTP OPTIONS method, a remote attacker could send a specially-crafted query to a vulnerable server running to cause the server to disclose sensitive information in the HTTP response. | 2 | 5 | Medium | 2017-02-15 | 2017-02-15 | View |
Page 1214 of 17672, showing 5 records out of 88360 total, starting on record 6066, ending on 6070