| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. |
| Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. |
| The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. |
| Routed allows attackers to append data to files. |
| Attackers can do a denial of service of IRC by crashing the server. |
| The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. |
| Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. |
| Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests. |
| IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| Buffer overflow in Solaris dtprintinfo program. |
| Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. |
| HP Remote Watch allows a remote user to gain root access. |
| TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password. |
| Windows NT RSHSVC program allows remote users to execute arbitrary commands. |
| Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed". |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| Buffer overflow in Samba smbd program via a malformed message command. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. |