CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12960 | CVE-2005-1754 | Candidate | ** DISPUTED ** JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned products." | Assigned (20050526) | None (candidate not yet proposed) | View | |
12961 | CVE-2005-1755 | Candidate | PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter. | Assigned (20050526) | None (candidate not yet proposed) | View | |
12948 | CVE-2005-1742 | Candidate | BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools." | Assigned (20050525) | None (candidate not yet proposed) | View | |
12949 | CVE-2005-1743 | Candidate | BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions. | Assigned (20050525) | None (candidate not yet proposed) | View | |
12950 | CVE-2005-1744 | Candidate | BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings. | Assigned (20050525) | None (candidate not yet proposed) | View |
Page 19334 of 20943, showing 5 records out of 104715 total, starting on record 96666, ending on 96670