NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85182 | CVE-2016-6341 | oVirt Engine before 4.0.3 does not include DWH_DB_PASSWORD in the list of keys to hide in log files, which allows local users to obtain sensitive password information by reading engine log files. | 2 | 2.1 | Low | 2017-04-27 | 2017-04-25 | View | |
87476 | CVE-2016-6342 | elog 3.1.1 allows remote attackers to post data as any username in the logbook. | 2017-06-28 | 2017-06-27 | View | ||||
21130 | CVE-2016-6344 | Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies. | 2 | 5 | Medium | 2017-01-19 | 2016-09-08 | View | |
21131 | CVE-2016-6345 | RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs. | 2 | 4 | Medium | 2017-01-19 | 2016-09-08 | View | |
21132 | CVE-2016-6346 | RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors. | 2 | 5 | Medium | 2017-01-19 | 2016-09-08 | View |
Page 16238 of 17672, showing 5 records out of 88360 total, starting on record 81186, ending on 81190