NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 18898 | CVE-2016-2954 | Cross-site scripting (XSS) vulnerability in the Web UI in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2956 and CVE-2016-3008. | 2 | 3.5 | Low | 2017-01-19 | 2016-11-28 | View | |
| 18897 | CVE-2016-2953 | IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-30 | View | |
| 18896 | CVE-2016-2952 | IBM BigFix Remote Control before 9.1.3 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 18895 | CVE-2016-2951 | IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 18894 | CVE-2016-2950 | SQL injection vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-12-02 | View |
Page 1979 of 17672, showing 5 records out of 88360 total, starting on record 9891, ending on 9895