| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| FreeBSD mmap function allows users to modify append-only or immutable files. |
| Buffer overflow in the Linux mail program "deliver" allows local users to gain root access. |
| The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button. |
| Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. |
| MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag. |
| NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging. |
| NETBIOS share information may be published through SNMP registry keys in NT. |
| The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry. |
| UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target. |
| The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. |
| The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. |
| A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
| sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack. |
| Denial of service in Sendmail 8.8.6 in HPUX. |
| Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option. |
| Denial of service in AIX ptrace system call allows local users to crash the system. |
| The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack. |
| wwwboard allows a remote attacker to delete message board articles via a malformed argument. |