| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network. |
| NetBSD allows ARP packets to overwrite static ARP entries. |
| The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. |
| Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301. |
| Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. |
| Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. |
| Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. |
| The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail. |
| By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. |
| HP Secure Web Console uses weak encryption. |
| Denial of service in Linux syslogd via a large number of connections. |
| The default permissions for Endymion MailMan allow local users to read email or modify files. |
| IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. |
| Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. |
| Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. |
| Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
| Firewall-1 does not properly restrict access to LDAP attributes. |
| Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests. |
| Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail. |
| Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. |