CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9080  CVE-2004-0652  Candidate  BEA WebLogic Server and WebLogic Express 7.0 through 7.0 Service Pack 4, and 8.1 through 8.1 Service Pack 2, allows attackers to obtain the username and password for booting the server by directly accessing certain internal methods.  Assigned (20040709)  None (candidate not yet proposed)    View
9081  CVE-2004-0653  Candidate  Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user"s passwords by reading log files.  Assigned (20040709)  None (candidate not yet proposed)    View
9082  CVE-2004-0654  Candidate  Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).  Assigned (20040709)  None (candidate not yet proposed)    View
9083  CVE-2004-0655  Candidate  eupdatedb in esearch 0.6.1 and earlier allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.  Assigned (20040709)  None (candidate not yet proposed)    View
9084  CVE-2004-0656  Candidate  The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.  Assigned (20040709)  None (candidate not yet proposed)    View

Page 905 of 20943, showing 5 records out of 104715 total, starting on record 4521, ending on 4525

Actions