CVE List

Id CVE No. Status Description Phase Votes Comments Actions
9140  CVE-2004-0712  Candidate  The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartext, which could allow local users to gain privileges.  Assigned (20040720)  None (candidate not yet proposed)    View
9141  CVE-2004-0713  Candidate  The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permissions before unexporting a bean, which allows remote authenticated users to remove EJB objects from remote views before the security exception is thrown.  Assigned (20040720)  None (candidate not yet proposed)    View
9142  CVE-2004-0714  Candidate  Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory corruption).  Assigned (20040720)  None (candidate not yet proposed)    View
9143  CVE-2004-0715  Candidate  The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can cause a new group with the same name to have the members of the old group, which allows group members to gain privileges.  Assigned (20040720)  None (candidate not yet proposed)    View
7872  CVE-2003-1048  Candidate  Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.  Assigned (20040720)  None (candidate not yet proposed)    View

Page 917 of 20943, showing 5 records out of 104715 total, starting on record 4581, ending on 4585

Actions