| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A malicious Palace server can force a client to execute arbitrary programs. |
| Denial of service in WinGate proxy through a buffer overflow in POP3. |
| The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. |
| A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. |
| A system is operating in "promiscuous" mode which allows it to perform packet sniffing. |
| A trust relationship exists between two Unix hosts. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. |
| The jj CGI program allows command execution via shell metacharacters. |
| Nestea variation of teardrop IP fragmentation denial of service. |
| Buffer overflow in War FTP allows remote execution of commands. |
| The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder. |
| The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command. |
| abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access. |
| Buffer overflow in NCSA WebServer (version 1.5c) gives remote access. |
| Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. |
| Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. |
| Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL. |