NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
15226  CVE-2010-3891  Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action.    6.8  Medium  2017-01-18  2010-12-01  View
15227  CVE-2010-3892  Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID (aka SID) value.    6.8  Medium  2017-01-18  2010-12-01  View
15228  CVE-2010-3893  The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.    7.5  High  2017-01-18  2010-12-01  View
15229  CVE-2010-3894  Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers to execute arbitrary code via a long password.    9.3  High  2017-01-18  2010-12-01  View
15230  CVE-2010-3895  esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.    7.2  High  2017-01-18  2010-12-01  View

Page 3046 of 17672, showing 5 records out of 88360 total, starting on record 15226, ending on 15230

Actions