CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7920  CVE-2003-1096  Candidate  The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.  Assigned (20050311)  None (candidate not yet proposed)    View
7919  CVE-2003-1095  Candidate  BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.  Assigned (20050311)  None (candidate not yet proposed)    View
7918  CVE-2003-1094  Candidate  BEA WebLogic Server and Express version 7.0 SP3 may follow certain code execution paths that result in an incorrect current user, such as in the frequent use of JNDI initial contexts, which could allow remote authenticated users to gain privileges.  Assigned (20050310)  None (candidate not yet proposed)    View
7917  CVE-2003-1093  Candidate  BEA WebLogic Server 6.1, 7.0 and 7.0.0.1, when routing messages to a JMS target domain that is inaccessible, may leak the user"s password when it throws a ResourceAllocationException.  Assigned (20050310)  None (candidate not yet proposed)    View
7916  CVE-2003-1092  Candidate  Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.41, related to "a memory allocation problem," has unknown impact.  Assigned (20050310)  None (candidate not yet proposed)    View

Page 19360 of 20943, showing 5 records out of 104715 total, starting on record 96796, ending on 96800

Actions