NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
72137 | CVE-2004-1758 | BEA WebLogic Server and WebLogic Express version 8.1 up to SP2, 7.0 up to SP4, and 6.1 up to SP6 may store the database username and password for an untargeted JDBC connection pool in plaintext in config.xml, which allows local users to gain privileges. | 2 | 4.6 | Medium | 2017-07-18 | 2017-07-10 | View | |
61156 | CVE-2006-2461 | BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
74290 | CVE-2003-1220 | BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL. | 2 | 5 | Medium | 2017-01-03 | 2008-09-10 | View | |
45053 | CVE-2012-3458 | Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2012-09-17 | View | |
18723 | CVE-2016-2510 | BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-02 | View |
Page 1523 of 17672, showing 5 records out of 88360 total, starting on record 7611, ending on 7615