CVE List

Id CVE No. Status Description Phase Votes Comments Actions
10185  CVE-2004-1757  Candidate  BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.  Assigned (20050310)  None (candidate not yet proposed)    View
10184  CVE-2004-1756  Candidate  BEA WebLogic Server and WebLogic Express 8.1 SP2 and earlier, and 7.0 SP4 and earlier, when using 2-way SSL with a custom trust manager, may accept a certificate chain even if the trust manager rejects it, which allows remote attackers to spoof other users or servers.  Assigned (20050310)  None (candidate not yet proposed)    View
10183  CVE-2004-1755  Candidate  The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.  Assigned (20050310)  None (candidate not yet proposed)    View
10182  CVE-2004-1754  Candidate  The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.  Assigned (20050309)  None (candidate not yet proposed)    View
10181  CVE-2004-1753  Candidate  The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.  Assigned (20050226)  None (candidate not yet proposed)    View

Page 18907 of 20943, showing 5 records out of 104715 total, starting on record 94531, ending on 94535

Actions