| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. |
| File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). |
| The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage. |
| Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. |
| Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command. |
| Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands. |
| wu-ftp allows files to be overwritten via the rnfr command. |
| getcwd() file descriptor leak in FTP. |
| CGI PHP mylog script allows an attacker to read any file on the target server. |
| Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. |
| Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail. |
| Buffer overflow in AIX libDtSvc library can allow local users to gain root access. |
| SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter. |
| Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line. |
| Finger redirection allows finger bombs. |
| RIP v1 is susceptible to spoofing. |
| Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys. |
| Open WebMail 2.30 and earlier, when use_syshomedir is disabled or create_syshomedir is enabled, creates new directories before authenticating, which allows remote attackers to create arbitrary directories. |
| Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood. |
| The handler CGI program in IRIX allows arbitrary command execution. |