| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. |
| A Sendmail alias allows input to be piped to a program. |
| A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. |
| There is a one-way or two-way trust relationship between Windows NT domains. |
| Buffer overflow in AIX ftpd in the libc library. |
| A system-critical Windows NT registry key has an inappropriate value. |
| Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. |
| The rwho/rwhod service is running, which exposes machine status and user information. |
| Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field. |
| Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly. |
| sccw allows local users to read arbitrary files. |
| Apache allows remote attackers to conduct a denial of service via a large number of MIME headers. |
| HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation. |
| PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands. |
| Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe. |
| Unknown vulnerability in filestat.c for Apache running on OS2, versions 2.0 through 2.0.45, allows unknown attackers to cause a denial of service via requests related to device names. |
| SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. |
| Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Homepage field (aka the Website field) in an "image-related comment" and (2) the img_size field in view.php. NOTE: due to lack of details from the researcher, it is not clear whether the comment vector overlaps CVE-2005-1886. |
| Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use. |
| Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code. |