| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. |
| Open Projects Network Internet Relay Chat (IRC) daemon u2.10.05.18 does not perform a double-reverse DNS lookup, which allows remote attackers to spoof any valid hostname on the Internet. NOTE: a followup post suggests that this is not an issue in the daemon. |
| Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, allows remote attackers to display restricted products and components via a direct HTTP request to queryhelp.cgi. |
| The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost. |
| The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication. |
| Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. |
| run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands. |
| Buffer overflow in the Linux mail program "deliver" allows local users to gain root access. |
| Linux PAM modules allow local users to gain root access using temporary files. |
| A malicious Palace server can force a client to execute arbitrary programs. |
| WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin board messages posted by users, which could allow remote attackers to hijack user sessions. |
| Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems. |
| CGI PHP mlog script allows an attacker to read any file on the target server. |
| Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character. |
| Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. |
| Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE |
| ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. |
| Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack. |
| rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory. |
| The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access. |