| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. |
| Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases. |
| Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. |
| Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable. |
| Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names. |
| In older versions of Sendmail, an attacker could use a pipe character to execute root commands. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. |
| The info2www CGI script allows remote file access or remote command execution. |
| Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter. |
| Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. |
| Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php. |
| Netscape Enterprise servers may list files through the PageServices query. |
| Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. |
| mSQL v2.0.1 and below allows remote execution through a buffer overflow. |
| The Java Web Server would allow remote users to obtain the source code for CGI programs. |
| Denial of service in BIND named via maxdname. |
| IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. |