NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
82320  CVE-2016-2568  pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal"s input buffer.          2017-02-15  2017-02-13  View
81809  CVE-2016-6000  IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.    4.3  Medium  2017-02-15  2017-02-08  View
82321  CVE-2016-2787  The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.          2017-02-15  2017-02-13  View
81810  CVE-2016-6001  IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.    3.5  Low  2017-02-15  2017-02-15  View
81811  CVE-2016-6020  IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.    5.8  Medium  2017-02-15  2017-02-09  View

Page 15475 of 17672, showing 5 records out of 88360 total, starting on record 77371, ending on 77375

Actions