CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7230  CVE-2003-0403  Candidate  Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) by directly accessing the /vgn/license template.  Assigned (20030610)  None (candidate not yet proposed)    View
7229  CVE-2003-0402  Candidate  The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks.  Assigned (20030610)  None (candidate not yet proposed)    View
7228  CVE-2003-0401  Candidate  Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.  Assigned (20030610)  None (candidate not yet proposed)    View
7227  CVE-2003-0400  Candidate  Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions of memory, as demonstrated using the "-->" string in a CookieName argument to the login template, referred to as a "memory leak" in some reports.  Assigned (20030610)  None (candidate not yet proposed)    View
7226  CVE-2003-0399  Candidate  Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the vgn_creds cookie to an arbitrary value and directly accessing the save template.  Assigned (20030610)  None (candidate not yet proposed)    View

Page 19498 of 20943, showing 5 records out of 104715 total, starting on record 97486, ending on 97490

Actions