Vulnerabilities (CVE)

Filtered by CWE-669
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-5062 1 Aternity 1 Aternity 2024-02-04 9.3 HIGH 9.8 CRITICAL
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.
CVE-2002-0055 1 Microsoft 3 Exchange Server, Windows 2000, Windows Xp 2024-02-04 5.0 MEDIUM N/A
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
CVE-2004-0872 1 Opera 1 Opera Browser 2024-02-04 5.0 MEDIUM N/A
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."