| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. |
| By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. |
| HP Secure Web Console uses weak encryption. |
| Denial of service in Linux syslogd via a large number of connections. |
| The default permissions for Endymion MailMan allow local users to read email or modify files. |
| Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port. |
| Falcon web server allows remote attackers to determine the absolute path of the web root via long file names. |
| Firewall-1 does not properly restrict access to LDAP attributes. |
| ypserv allows a local user to modify the GECOS and login shells of other users. |
| ypserv allows local administrators to modify password tables. |
| Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests. |
| Denial of service in Debian IRC Epic/epic4 client via a long string. |
| The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file. |
| Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system. |
| Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords. |
| War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections. |
| The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system. |
| Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. |
| Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session. |
| Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock. |