| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Linux cfingerd could be exploited to gain root access. |
| Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| Remote command execution in Microsoft Internet Explorer using .lnk and .url files. |
| Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. |
| In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). |
| Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. |
| The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button. |
| Denial of service in HP-UX sendmail 8.8.6 related to accepting connections. |
| The Logon box of a Windows NT system displays the name of the last user who logged in. |
| A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. |
| The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. |
| QMS CrownNet Unix Utilities for 2060 allows root to log on without a password. |
| A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. |
| IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option. |
| The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows. |
| quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request. |
| Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back. |
| Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to "boogieman". |
| violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a "spam proxy" by setting the Mod and ForumName parameters. |