NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85166 | CVE-2016-5401 | Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-26 | View | |
85167 | CVE-2016-5409 | Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies. | 2 | 5 | Medium | 2017-04-27 | 2017-04-26 | View | |
85185 | CVE-2016-6519 | Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-26 | View | |
84675 | CVE-2017-5156 | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-26 | View | |
84676 | CVE-2017-5158 | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified. | 2 | 5 | Medium | 2017-04-27 | 2017-04-26 | View |
Page 15926 of 17672, showing 5 records out of 88360 total, starting on record 79626, ending on 79630