NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85182  CVE-2016-6341  oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files.    2.1  Low  2017-04-27  2017-04-25  View
87476  CVE-2016-6342  elog 3.1.1 allows remote attackers to post data as any username in the logbook.          2017-06-28  2017-06-27  View
21130  CVE-2016-6344  Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.    Medium  2017-01-19  2016-09-08  View
21131  CVE-2016-6345  RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.    Medium  2017-01-19  2016-09-08  View
21132  CVE-2016-6346  RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.    Medium  2017-01-19  2016-09-08  View

Page 16238 of 17672, showing 5 records out of 88360 total, starting on record 81186, ending on 81190

Actions