CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7920 | CVE-2003-1096 | Candidate | The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks. | Assigned (20050311) | None (candidate not yet proposed) | View | |
7919 | CVE-2003-1095 | Candidate | BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate. | Assigned (20050311) | None (candidate not yet proposed) | View | |
7918 | CVE-2003-1094 | Candidate | BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges. | Assigned (20050310) | None (candidate not yet proposed) | View | |
7917 | CVE-2003-1093 | Candidate | BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user"s password when it throws a ResourceAllocationException. | Assigned (20050310) | None (candidate not yet proposed) | View | |
7916 | CVE-2003-1092 | Candidate | Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact. | Assigned (20050310) | None (candidate not yet proposed) | View |
Page 19360 of 20943, showing 5 records out of 104715 total, starting on record 96796, ending on 96800