CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4148  CVE-2001-1344  Candidate  WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).  Proposed (20020502)  ACCEPT(2) Frech, Green | NOOP(4) Cole, Cox, Foat, Wall    View
37939  CVE-2009-0504  Candidate  WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.  Assigned (20090210)  None (candidate not yet proposed)    View
51732  CVE-2011-3820  Candidate  WSN Software 6.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/prestart.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
21525  CVE-2006-5421  Candidate  WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies to the attack, not the underlying vulnerability.  Assigned (20061019)  None (candidate not yet proposed)    View
49395  CVE-2011-1483  Candidate  wsf/common/DOMUtils.java in JBossWS Native in Red Hat JBoss Enterprise Application Platform 4.2.0.CP09, 4.3, and 5.1.1; JBoss Enterprise Portal Platform 4.3.CP06 and 5.1.1; JBoss Enterprise SOA Platform 4.2.CP05, 4.3.CP05, and 5.1.0; JBoss Communications Platform 1.2.11 and 5.1.1; JBoss Enterprise BRMS Platform 5.1.0; and JBoss Enterprise Web Platform 5.1.1 does not properly handle recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted request containing an XML document with a DOCTYPE declaration and a large number of nested entity references, a similar issue to CVE-2003-1564.  Assigned (20110321)  None (candidate not yet proposed)    View

Page 128 of 20943, showing 5 records out of 104715 total, starting on record 636, ending on 640

Actions