CVE List

Id CVE No. Status Description Phase Votes Comments Actions
15206  CVE-2005-4002  Candidate  WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation.  Assigned (20051204)  None (candidate not yet proposed)    View
13487  CVE-2005-2281  Candidate  WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.  Assigned (20050717)  None (candidate not yet proposed)    View
13491  CVE-2005-2285  Candidate  WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system configuration.  Assigned (20050717)  None (candidate not yet proposed)    View
13489  CVE-2005-2283  Candidate  WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.  Assigned (20050717)  None (candidate not yet proposed)    View
13492  CVE-2005-2286  Candidate  WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.  Assigned (20050717)  None (candidate not yet proposed)    View

Page 383 of 20943, showing 5 records out of 104715 total, starting on record 1911, ending on 1915

Actions