NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 82297 | CVE-2016-0310 | IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker"s domain. | 2 | 3.5 | Low | 2017-02-15 | 2017-02-09 | View | |
| 16766 | CVE-2016-0313 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-2888 and CVE-2016-0350. | 2 | 3.5 | Low | 2017-01-19 | 2016-07-08 | View | |
| 16767 | CVE-2016-0314 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 16768 | CVE-2016-0315 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation. | 2 | 6.5 | Medium | 2017-01-19 | 2016-07-08 | View | |
| 16769 | CVE-2016-0316 | Cross-site scripting (XSS) vulnerability in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 and 6.0.2 before iFix003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | 2 | 3.5 | Low | 2017-01-19 | 2016-11-28 | View |
Page 15200 of 17672, showing 5 records out of 88360 total, starting on record 75996, ending on 76000