NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
18898  CVE-2016-2954  Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2956 and CVE-2016-3008.    3.5  Low  2017-01-19  2016-11-28  View
18897  CVE-2016-2953  IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.    4.3  Medium  2017-01-19  2016-11-30  View
18896  CVE-2016-2952  IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.    4.3  Medium  2017-01-19  2016-12-02  View
18895  CVE-2016-2951  IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.    4.3  Medium  2017-01-19  2016-12-02  View
18894  CVE-2016-2950  SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.    Medium  2017-01-19  2016-12-02  View

Page 1979 of 17672, showing 5 records out of 88360 total, starting on record 9891, ending on 9895

Actions