| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |
| Buffer overflow in Solaris dtprintinfo program. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. |
| TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password. |
| HP Remote Watch allows a remote user to gain root access. |
| Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed". |
| Windows NT RSHSVC program allows remote users to execute arbitrary commands. |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| Buffer overflow in Samba smbd program via a malformed message command. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server. |
| Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file. |
| A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service. |
| In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. |
| Denial of service in Linux 2.2.0 running the ldd command on a core file. |
| wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself. |
| Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. |
| Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine. |
| Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set. |