| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| AIX infod allows local users to gain root access through an X display. |
| Windows NT 4.0 beta allows users to read and delete shares. |
| Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root. |
| The Perl fingerd program allows arbitrary command execution from remote users. |
| Buffer overflow in AIX lchangelv gives root access. |
| Race condition in Linux mailx command allows local users to read user files. |
| The DG/UX finger daemon allows remote command execution through shell metacharacters. |
| Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request. |
| Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon. |
| Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. |
| Local users can start Sendmail in daemon mode and gain root privileges. |
| Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. |
| The dip program on many Linux systems allows local users to gain root access via a buffer overflow. |
| Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. |
| Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access. |
| Denial of service in RAS/PPTP on NT systems. |
| In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering. |
| Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. |
| Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature. |
| Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter. |