NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 88229 | CVE-2017-9812 | The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312) to read arbitrary files with kluser privileges. | 2017-07-18 | 2017-07-17 | View | ||||
| 27285 | CVE-2015-6348 | The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page. | 2 | 4 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 55767 | CVE-2007-3617 | The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries. | 2 | 4 | Medium | 2017-01-07 | 2008-11-13 | View | |
| 16768 | CVE-2016-0315 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation. | 2 | 6.5 | Medium | 2017-01-19 | 2016-07-08 | View | |
| 16767 | CVE-2016-0314 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 allow remote authenticated users to conduct clickjacking attacks via unspecified vectors. | 2 | 4 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 3320 of 17672, showing 5 records out of 88360 total, starting on record 16596, ending on 16600