CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8048  CVE-2003-1224  Candidate  Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user"s password by physically observing ("shoulder surfing") the screen.  Assigned (20050816)  None (candidate not yet proposed)    View
34332  CVE-2008-4215  Candidate  Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that has multiple short names, which might allow attackers to bypass intended access restrictions.  Assigned (20080924)  None (candidate not yet proposed)    View
9650  CVE-2004-1222  Candidate  weblibs.pl in WebLibs 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the TextFile parameter.  Assigned (20041214)  None (candidate not yet proposed)    View
88518  CVE-2016-1699  Candidate  WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL.  Assigned (20160112)  None (candidate not yet proposed)    View
88530  CVE-2016-1711  Candidate  WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.  Assigned (20160112)  None (candidate not yet proposed)    View

Page 246 of 20943, showing 5 records out of 104715 total, starting on record 1226, ending on 1230

Actions