CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8050  CVE-2003-1226  Candidate  BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.  Assigned (20050816)  None (candidate not yet proposed)    View
8051  CVE-2003-1227  Candidate  PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable only during installation, or if the administrator has not run a security script after installation.  Assigned (20050816)  None (candidate not yet proposed)    View
8052  CVE-2003-1228  Candidate  Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.  Assigned (20050816)  None (candidate not yet proposed)    View
13761  CVE-2005-2555  Candidate  Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.  Assigned (20050816)  None (candidate not yet proposed)    View
13762  CVE-2005-2556  Candidate  core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.  Assigned (20050816)  None (candidate not yet proposed)    View

Page 1942 of 20943, showing 5 records out of 104715 total, starting on record 9706, ending on 9710

Actions