| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables. |
| FormMail CGI program can be used by web servers other than the host server that the program resides on. |
| The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server. |
| KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. |
| Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. |
| When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records. |
| In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution. |
| Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTML pages and cause a denial of service. |
| Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. |
| Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. |
| A remote attacker can read information from a Netscape user's cache via JavaScript. |
| Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. |
| The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches. |
| index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin". |
| NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries. |
| The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. |
| MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. |
| Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. |
| The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. |
| Routed allows attackers to append data to files. |