NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81784 | CVE-2016-5897 | IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim"s Web browser within the security context of the hosting site. | 2 | 3.5 | Low | 2017-02-08 | 2017-02-07 | View | |
| 81785 | CVE-2016-5898 | IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive information. | 2 | 4 | Medium | 2017-02-08 | 2017-02-07 | View | |
| 81786 | CVE-2016-5899 | IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 2 | 3.5 | Low | 2017-02-08 | 2017-02-07 | View | |
| 82045 | CVE-2016-7544 | Crypto++ 5.6.4 incorrectly uses Microsoft"s stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed. | 2 | 5 | Medium | 2017-02-08 | 2017-02-07 | View | |
| 82047 | CVE-2016-7798 | The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism. | 2 | 5 | Medium | 2017-02-08 | 2017-02-07 | View |
Page 2265 of 17672, showing 5 records out of 88360 total, starting on record 11321, ending on 11325