| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Local users can gain privileges using the debug utility in the MPE/iX operating system. |
| The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. |
| L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information. |
| Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. |
| Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. |
| Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames. |
| Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component. |
| Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client. |
| The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button. |
| The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred. |
| The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory. |
| A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail. |
| Buffer overflow in OpenBSD ping. |
| Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack. |
| Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD. |
| OpenBSD crash using nlink value in FFS and EXT2FS filesystems. |
| A Windows NT log file has an inappropriate maximum size or retention period. |
| A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire. |
| A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection. |
| A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers. |