| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A remote attacker can read information from a Netscape user's cache via JavaScript. |
| Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. |
| The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches. |
| index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "admin". |
| NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries. |
| The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. |
| MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. |
| Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. |
| The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. |
| Routed allows attackers to append data to files. |
| Attackers can do a denial of service of IRC by crashing the server. |
| The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. |
| Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. |
| Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests. |
| IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| Buffer overflow in Solaris dtprintinfo program. |
| Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords. |
| HP Remote Watch allows a remote user to gain root access. |
| TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain the database username and password. |