| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. |
| Routed allows attackers to append data to files. |
| Livingston portmaster machines could be rebooted via a series of commands. |
| Denial of service in talk program allows remote attackers to disrupt a user's display. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| All records in a WINS database can be deleted through SNMP for a denial of service. |
| NetBSD netstat command allows local users to access kernel memory. |
| The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. |
| Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. |
| A DNS server allows inverse queries. |
| HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. |
| Two or more Unix accounts have the same UID. |
| The rwho/rwhod service is running, which exposes machine status and user information. |
| The error handling in the (1) inflate and (2) inflateBack functions in ZLib compression library 1.2.x allows local users to cause a denial of service (application crash). |
| Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. |
| inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced. |
| The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable. |
| The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. |
| upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code. |
| Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag. |