Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 393 454

Количество 393 454

nvd логотип

CVE-2007-0430

больше 19 лет назад

The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2007-0429

больше 19 лет назад

DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0428

больше 19 лет назад

Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0427

больше 19 лет назад

Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2007-0426

больше 19 лет назад

BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-0425

больше 19 лет назад

Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-0424

больше 19 лет назад

Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0423

больше 19 лет назад

BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2007-0422

больше 19 лет назад

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0421

больше 19 лет назад

BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2007-0420

больше 19 лет назад

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0419

больше 19 лет назад

The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0418

больше 19 лет назад

BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-0417

больше 19 лет назад

BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2007-0416

больше 19 лет назад

The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-0415

больше 19 лет назад

BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0414

больше 19 лет назад

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0413

больше 19 лет назад

BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2007-0412

больше 19 лет назад

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-0411

больше 19 лет назад

BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-0430

The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.

CVSS2: 4.9
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0429

DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.

CVSS2: 5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0428

Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.

CVSS2: 5
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0427

Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.

CVSS2: 9.3
31%
Средний
больше 19 лет назад
nvd логотип
CVE-2007-0426

BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the changes are made on a managed server while the Administrative Server is unavailable, which might allow attackers to bypass intended restrictions.

CVSS2: 6.8
3%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0425

Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.

CVSS2: 7.5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0424

Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to cause a denial of service via certain requests that trigger errors that lead to a server being marked as unavailable, hosting web server failure, or CPU consumption.

CVSS2: 5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0423

BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which has an unknown impact.

CVSS2: 4.4
0%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0422

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.

CVSS2: 5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0421

BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.

CVSS2: 6.4
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0420

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0419

The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).

CVSS2: 5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0418

BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.

CVSS2: 7.5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0417

BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.

CVSS2: 10
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0416

The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.

CVSS2: 7.5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0415

BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through exploded jars, which allows attackers to bypass intended access restrictions.

CVSS2: 5
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0414

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests that cause muxer threads to block when processing error pages.

CVSS2: 5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0413

BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.

CVSS2: 4.4
0%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0412

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.

CVSS2: 5
2%
Низкий
больше 19 лет назад
nvd логотип
CVE-2007-0411

BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.

CVSS2: 6.8
1%
Низкий
больше 19 лет назад

Уязвимостей на страницу