![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-1352
https://notcve.org/view.php?id=CVE-2006-1352
22 Mar 2006 — BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via crafted non-canonicalized XML documents. • http://dev2dev.bea.com/pub/advisory/183 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-0421
https://notcve.org/view.php?id=CVE-2006-0421
25 Jan 2006 — By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic instance on the same machine, allows administrators of any created domain to access other created domains, which could allow administrators to gain privileges that were not intended. • http://dev2dev.bea.com/pub/advisory/165 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-0422
https://notcve.org/view.php?id=CVE-2006-0422
25 Jan 2006 — Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allow remote attackers to access MBean attributes or cause an unspecified denial of service via unknown attack vectors. • http://dev2dev.bea.com/pub/advisory/166 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2006-0424
https://notcve.org/view.php?id=CVE-2006-0424
25 Jan 2006 — BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information. • http://dev2dev.bea.com/pub/advisory/168 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-4749
https://notcve.org/view.php?id=CVE-2005-4749
31 Dec 2005 — HTTP request smuggling vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allows remote attackers to inject arbitrary HTTP headers via unspecified attack vectors. • http://dev2dev.bea.com/pub/advisory/159 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-4751
https://notcve.org/view.php?id=CVE-2005-4751
31 Dec 2005 — Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and WebLogic Express 9.0, 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier allow remote attackers to inject arbitrary web script or HTML and gain administrative privileges via unknown attack vectors. • http://dev2dev.bea.com/pub/advisory/139 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-4763
https://notcve.org/view.php?id=CVE-2005-4763
31 Dec 2005 — BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and 6.1 SP7 and earlier, when Internet Inter-ORB Protocol (IIOP) is used, sometimes include a password in an exception message that is sent to a client or stored in a log file, which might allow remote attackers to perform unauthorized actions. • http://dev2dev.bea.com/pub/advisory/154 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-4705
https://notcve.org/view.php?id=CVE-2005-4705
31 Dec 2005 — BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, which allows remote attackers to sniff the connection. • http://dev2dev.bea.com/pub/advisory/141 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-4750
https://notcve.org/view.php?id=CVE-2005-4750
31 Dec 2005 — BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier allow remote attackers to cause a denial of service (server thread hang) via unknown attack vectors. • http://dev2dev.bea.com/pub/advisory/138 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2005-4704
https://notcve.org/view.php?id=CVE-2005-4704
31 Dec 2005 — Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user credentials to be sent across the network in cleartext and allows remote attackers to gain privileges. • http://dev2dev.bea.com/pub/advisory/140 •