| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The DG/UX finger daemon allows remote command execution through shell metacharacters. |
| The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. |
| NFS allows users to use a "cd .." command to access other directories besides the exported file system. |
| Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers. |
| FormMail CGI program allows remote execution of commands. |
| In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters. |
| The passwd command in Solaris can be subjected to a denial of service. |
| Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. |
| IIS newdsn.exe CGI script allows remote users to overwrite files. |
| finger 0@host on some systems may print information on some user accounts. |
| finger .@host on some systems may print information on some user accounts. |
| A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user. |
| Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. |
| Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server. |
| libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind. |
| rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. |
| The SunView (SunTools) selection_svc facility allows remote users to read files. |
| Attackers can do a denial of service of IRC by crashing the server. |
| Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. |
| Progressive Networks Real Video server (pnserver) can be crashed remotely. |