NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59164 | CVE-2006-0426 | BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change occurs, stores the old and new passwords in cleartext in the DefaultAuditRecorder.log file, which could allow attackers to gain privileges. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
834 | CVE-2008-0863 | BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service"s WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
59167 | CVE-2006-0429 | BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions. | 2 | 2.1 | Low | 2016-12-20 | 2011-03-07 | View | |
59157 | CVE-2006-0419 | BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedded LDAP server, which allows remote attackers to read user entries or cause a denial of service (unspecified) via a large number of connections. | 2 | 6.4 | Medium | 2016-12-20 | 2008-09-05 | View | |
70353 | CVE-2005-4764 | BEA WebLogic Server and WebLogic Express 9.0, 8.1, and 7.0 lock out the admin user account after multiple incorrect password guesses, which allows remote attackers who know or guess the admin account name to cause a denial of service (blocked admin logins). | 2 | 7.8 | High | 2017-01-03 | 2008-09-05 | View |
Page 1522 of 17672, showing 5 records out of 88360 total, starting on record 7606, ending on 7610