Show filters
338 Total Results
Displaying 331-338 of 338
Sort by:
Attacker Value
Unknown
CVE-2007-1273
Disclosure Date: March 10, 2007 (last updated October 04, 2023)
Integer overflow in the ktruser function in NetBSD-current before 20061022, NetBSD 3 and 3-0 before 20061024, and NetBSD 2 before 20070209, when the kernel is built with the COMPAT_FREEBSD or COMPAT_DARWIN option, allows local users to cause a denial of service and possibly gain privileges.
0
Attacker Value
Unknown
CVE-2007-1249
Disclosure Date: March 03, 2007 (last updated October 04, 2023)
MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.
0
Attacker Value
Unknown
CVE-2006-3667
Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2006-2719
Disclosure Date: June 01, 2006 (last updated October 04, 2023)
JIWA Financials 6.4.14 stores usernames and passwords for all accounts in cleartext in the HR_Staff table in Microsoft SQL Server, and sends the usernames and passwords in cleartext to the application's SQL Server ODBC driver, which might allow context-dependent attackers to obtain the passwords.
0
Attacker Value
Unknown
CVE-2006-2718
Disclosure Date: June 01, 2006 (last updated October 04, 2023)
JIWA Financials 6.4.14 passes a Microsoft SQL Server account's username and password, and the name of a data source, to a Crystal Reports .rpt file, which allows remote authenticated users to execute certain standard stored procedures by referencing them in a user-written .rpt file, as demonstrated by using a stored procedure that provides the username and cleartext password of every account.
0
Attacker Value
Unknown
CVE-2002-2301
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Lawson Financials 8.0, when configured to use a third party relational database, stores usernames and passwords in a world-readable file, which allows local users to read the passwords and log onto the database.
0
Attacker Value
Unknown
CVE-2001-0392
Disclosure Date: June 18, 2001 (last updated February 22, 2025)
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.
0
Attacker Value
Unknown
CVE-2001-0393
Disclosure Date: June 18, 2001 (last updated February 22, 2025)
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.
0