| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems. |
| Buffer overflow in OpenBSD ping. |
| Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors. |
| The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute. |
| The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. |
| Denial of service in WinGate proxy through a buffer overflow in POP3. |
| A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares. |
| A Windows NT domain user or administrator account has a guessable password. |
| Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands. |
| A NETBIOS/SMB share password is the default, null, or missing. |
| An NIS domain name is easily guessable. |
| ICMP echo (ping) is allowed from arbitrary hosts. |
| An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. |
| The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. |
| A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. |
| A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. |
| The Windows NT guest account is enabled. |
| An SSH server allows authentication through the .rhosts file. |
| A superfluous NFS server is running, but it is not importing or exporting any file systems. |
| HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. |