| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments. |
| Sendmail WIZ command enabled, allowing root access. |
| The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |
| The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. |
| vold in Solaris 2.x allows local users to gain root access. |
| Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. |
| Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. |
| Listening TCP ports are sequentially allocated, allowing spoofing attacks. |
| Buffer overflow in AIX xdat gives root access to local users. |
| AnyForm CGI remote execution. |
| File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). |
| IRIX fam service allows an attacker to obtain a list of all files on the server. |
| Buffer overflow in HP-UX newgrp program. |
| List of arbitrary files on Web host via nph-test-cgi script. |
| Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. |
| Buffer overflow in University of Washington's implementation of IMAP and POP servers. |
| Cross-site scripting (XSS) vulnerability in search.htm in Cofax 2.0 RC3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchstring parameter. |
| Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field. |
| Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories. |
| Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access. |