| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| sccw allows local users to read arbitrary files. |
| Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. |
| HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation. |
| PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. |
| The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. |
| In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access. |
| Buffer overflow in mstm in HP-UX allows local users to gain root access. |
| TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files. |
| NETBIOS share information may be published through SNMP registry keys in NT. |
| A Windows NT local user or administrator account has a guessable password. |
| A Windows NT local user or administrator account has a default, null, blank, or missing password. |
| A NETBIOS/SMB share password is guessable. |
| A NETBIOS/SMB share password is the default, null, or missing. |
| IP traceroute is allowed from arbitrary hosts. |
| A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input. |
| A version of finger is running that exposes valid user information to any entity on the network. |
| The rexd service is running, which uses weak authentication that can allow an attacker to execute commands. |
| The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service. |
| Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. |
| Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command. |