| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. |
| Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames. |
| Remote attackers can perform a denial of service using IRIX fcagent. |
| suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk. |
| Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. |
| Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. |
| Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. |
| The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly. |
| A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso. |
| A service or application has a backdoor password that was placed there by the developer. |
| Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port. |
| The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. |
| Local users can gain privileges using the debug utility in the MPE/iX operating system. |
| Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS. |
| L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information. |
| In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters. |
| Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. |
| Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password. |
| Solaris ff.core allows local users to modify files. |
| Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service. |