NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82042 | CVE-2016-7036 | python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys. | 2 | 7.5 | High | 2017-02-08 | 2017-01-31 | View | |
21617 | CVE-2016-7034 | The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cross-site request forgery (CSRF) attacks by obtaining an old token. | 2 | 6.8 | Medium | 2017-01-19 | 2016-09-08 | View | |
21616 | CVE-2016-7033 | Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-09-08 | View | |
85344 | CVE-2016-7032 | sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function. | 2 | 6.9 | Medium | 2017-04-27 | 2017-04-24 | View | |
21615 | CVE-2016-7031 | The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 1328 of 17672, showing 5 records out of 88360 total, starting on record 6636, ending on 6640