| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| NetBSD netstat command allows local users to access kernel memory. |
| The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. |
| IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. |
| The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. |
| A Windows NT domain user or administrator account has a default, null, blank, or missing password. |
| A DNS server allows inverse queries. |
| HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. |
| A system-critical Unix file or directory has inappropriate permissions. |
| The rwho/rwhod service is running, which exposes machine status and user information. |
| An application-critical Windows NT registry key has inappropriate permissions. |
| Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. |
| The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable. |
| NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network. |
| Buffer overflow in AIX ftpd in the libc library. |
| Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly. |
| sccw allows local users to read arbitrary files. |
| Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. |
| HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation. |
| PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. |
| The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. |