270001
|
- |
|
bea
|
weblogic_server
|
The URL pattern matching feature in BEA WebLogic Server 6.x matches illegal patterns ending in "*" as wildcards as if they were the legal "/*" pattern, which could cause WebLogic 7.x to allow remote …
|
NVD-CWE-Other
|
CVE-2004-0711
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270002
|
- |
|
bea
|
weblogic_server
|
The configuration tools (1) config.sh in Unix or (2) config.cmd in Windows for BEA WebLogic Server 8.1 through SP2 create a log file that contains the administrative username and password in cleartex…
|
NVD-CWE-Other
|
CVE-2004-0712
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270003
|
- |
|
bea
|
weblogic_server
|
The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 through SP2, 7.0 through SP4, and 6.1 through SP6, does not properly check EJB permis…
|
NVD-CWE-Other
|
CVE-2004-0713
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270004
|
- |
|
bea
|
weblogic_server
|
The WebLogic Authentication provider for BEA WebLogic Server and WebLogic Express 8.1 through SP2 and 7.0 through SP4 does not properly clear member relationships when a group is deleted, which can c…
|
NVD-CWE-Other
|
CVE-2004-0715
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270005
|
- |
|
apple
|
safari
|
Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame i…
|
NVD-CWE-Other
|
CVE-2004-0720
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270006
|
- |
|
microsoft
|
java_virtual_machine
|
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/K…
|
NVD-CWE-Other
|
CVE-2004-0723
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270007
|
- |
|
valve_software
|
half-life half-life_dedicated_server
|
The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.
|
NVD-CWE-Other
|
CVE-2004-0724
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270008
|
- |
|
microsoft
|
systems_management_server
|
The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to cause a denial of service (crash) via a data packet to TCP port 2702 that cause…
|
NVD-CWE-Other
|
CVE-2004-0728
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270009
|
- |
|
phpbb_group
|
phpbb
|
PhpBB 2.0.8 allows remote attackers to gain sensitive information via an invalid (1) category_rows parameter to index.php, (2) faq parameter to faq.php, or (3) ranksrow parameter to profile.php, whic…
|
NVD-CWE-Other
|
CVE-2004-0729
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270010
|
- |
|
phpbb_group
|
phpbb
|
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cat_title parameter in index.php, (2) the faq[0][0] parame…
|
NVD-CWE-Other
|
CVE-2004-0730
|
2017-07-11 10:30 |
2004-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|