CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
31014 | CVE-2008-0897 | Candidate | Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions. | Assigned (20080222) | None (candidate not yet proposed) | View | |
18576 | CVE-2006-2472 | Candidate | Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys. | Assigned (20060519) | None (candidate not yet proposed) | View | |
16535 | CVE-2006-0431 | Candidate | Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server"s SSL identity via unknown attack vectors. | Assigned (20060125) | None (candidate not yet proposed) | View | |
15908 | CVE-2005-4704 | Candidate | Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user credentials to be sent across the network in cleartext and allows remote attackers to gain privileges. | Assigned (20060201) | None (candidate not yet proposed) | View | |
16531 | CVE-2006-0427 | Candidate | Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted. | Assigned (20060125) | None (candidate not yet proposed) | View |
Page 18846 of 20943, showing 5 records out of 104715 total, starting on record 94226, ending on 94230