| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file. |
| Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail. |
| Denial of service in Debian IRC Epic/epic4 client via a long string. |
| genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767. |
| ypserv allows local administrators to modify password tables. |
| The Zeus web server administrative interface uses weak encryption for its passwords. |
| Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine. |
| Falcon web server allows remote attackers to determine the absolute path of the web root via long file names. |
| Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port. |
| Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. |
| Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file. |
| IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. |
| The default permissions for Endymion MailMan allow local users to read email or modify files. |
| Denial of service in Linux syslogd via a large number of connections. |
| HP Secure Web Console uses weak encryption. |
| By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. |
| The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail. |
| Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. |
| Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. |
| Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. |