NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82321 | CVE-2016-2787 | The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors. | 2017-02-15 | 2017-02-13 | View | ||||
82322 | CVE-2016-2788 | MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command. | 2 | 7.5 | High | 2017-03-18 | 2017-03-13 | View | |
82323 | CVE-2016-2866 | An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user. | 2 | 4 | Medium | 2017-02-15 | 2017-02-13 | View | |
82324 | CVE-2016-3101 | Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-15 | View | |
82325 | CVE-2016-3102 | The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations. | 2 | 7.5 | High | 2017-02-28 | 2017-02-28 | View |
Page 16465 of 17672, showing 5 records out of 88360 total, starting on record 82321, ending on 82325