Show filters
338 Total Results
Displaying 331-338 of 338
Sort by:
Attacker Value
Unknown

CVE-2007-1273

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.
0
Attacker Value
Unknown

CVE-2007-1249

Disclosure Date: March 03, 2007 (last updated October 04, 2023)
MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.
0
Attacker Value
Unknown

CVE-2006-3667

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2006-2719

Disclosure Date: June 01, 2006 (last updated October 04, 2023)
JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.
0
Attacker Value
Unknown

CVE-2006-2718

Disclosure Date: June 01, 2006 (last updated October 04, 2023)
JIWA Financials 6.4.14 passes a Microsoft SQL Server account's username and password, and the name of a data source, to a Crystal Reports .rpt file, which allows remote authenticated users to execute certain standard stored procedures by referencing them in a user-written .rpt file, as demonstrated by using a stored procedure that provides the username and cleartext password of every account.
0
Attacker Value
Unknown

CVE-2002-2301

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.
0
Attacker Value
Unknown

CVE-2001-0392

Disclosure Date: June 18, 2001 (last updated February 22, 2025)
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.
0
Attacker Value
Unknown

CVE-2001-0393

Disclosure Date: June 18, 2001 (last updated February 22, 2025)
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.
0