CVE List

Id CVE No. Status Description Phase Votes Comments Actions
31014  CVE-2008-0897  Candidate  Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.  Assigned (20080222)  None (candidate not yet proposed)    View
18576  CVE-2006-2472  Candidate  Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys.  Assigned (20060519)  None (candidate not yet proposed)    View
16535  CVE-2006-0431  Candidate  Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server"s SSL identity via unknown attack vectors.  Assigned (20060125)  None (candidate not yet proposed)    View
15908  CVE-2005-4704  Candidate  Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user credentials to be sent across the network in cleartext and allows remote attackers to gain privileges.  Assigned (20060201)  None (candidate not yet proposed)    View
16531  CVE-2006-0427  Candidate  Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.  Assigned (20060125)  None (candidate not yet proposed)    View

Page 18846 of 20943, showing 5 records out of 104715 total, starting on record 94226, ending on 94230

Actions