| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. |
| A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| A Windows NT administrator account has the default name of Administrator. |
| A filter in a router or firewall allows unusual fragmented packets. |
| The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |
| A system-critical Windows NT registry key has inappropriate permissions. |
| A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. |
| The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. |
| Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file. |
| A Windows NT log file has an inappropriate maximum size or retention period. |
| Buffer overflow in ToxSoft NextFTP client through CWD command. |
| An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information. |
| The rpc.sprayd service is running. |
| Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics. |
| The rstat/rstatd service is running. |
| The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. |
| The ident/identd service is running. |
| Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host. |
| The systat service is running. |
| Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL. |