NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17152  CVE-2016-0790  Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.    Medium  2017-01-19  2016-07-14  View
17153  CVE-2016-0791  Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.    7.5  High  2017-01-19  2016-07-14  View
17154  CVE-2016-0792  Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.    High  2017-01-19  2016-07-14  View
17155  CVE-2016-0793  Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.    Medium  2017-01-19  2016-04-04  View
17156  CVE-2016-0794  The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.    9.3  High  2017-01-19  2016-12-05  View

Page 15281 of 17672, showing 5 records out of 88360 total, starting on record 76401, ending on 76405

Actions