CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
7230 | CVE-2003-0403 | Candidate | Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template. | Assigned (20030610) | None (candidate not yet proposed) | View | |
7229 | CVE-2003-0402 | Candidate | The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks. | Assigned (20030610) | None (candidate not yet proposed) | View | |
7228 | CVE-2003-0401 | Candidate | Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template. | Assigned (20030610) | None (candidate not yet proposed) | View | |
7227 | CVE-2003-0400 | Candidate | Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports. | Assigned (20030610) | None (candidate not yet proposed) | View | |
7226 | CVE-2003-0399 | Candidate | Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template. | Assigned (20030610) | None (candidate not yet proposed) | View |
Page 19498 of 20943, showing 5 records out of 104715 total, starting on record 97486, ending on 97490