CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9080 | CVE-2004-0652 | Candidate | BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods. | Assigned (20040709) | None (candidate not yet proposed) | View | |
9081 | CVE-2004-0653 | Candidate | Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user"s passwords by reading log files. | Assigned (20040709) | None (candidate not yet proposed) | View | |
9082 | CVE-2004-0654 | Candidate | Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic). | Assigned (20040709) | None (candidate not yet proposed) | View | |
9083 | CVE-2004-0655 | Candidate | eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file. | Assigned (20040709) | None (candidate not yet proposed) | View | |
9084 | CVE-2004-0656 | Candidate | The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections. | Assigned (20040709) | None (candidate not yet proposed) | View |
Page 905 of 20943, showing 5 records out of 104715 total, starting on record 4521, ending on 4525