NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
42114  CVE-2013-7398  main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.    4.3  Medium  2017-02-15  2017-02-09  View
81795  CVE-2016-5949  IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.    Medium  2017-02-15  2017-02-09  View
81796  CVE-2016-5950  IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.    Medium  2017-02-15  2017-02-09  View
81803  CVE-2016-5980  IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.    3.5  Low  2017-02-15  2017-02-09  View
81811  CVE-2016-6020  IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.    5.8  Medium  2017-02-15  2017-02-09  View

Page 2228 of 17672, showing 5 records out of 88360 total, starting on record 11136, ending on 11140

Actions