| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. |
| HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack. |
| A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. |
| Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. |
| A system is operating in "promiscuous" mode which allows it to perform packet sniffing. |
| Linux PAM modules allow local users to gain root access using temporary files. |
| Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. |
| An SSH server allows authentication through the .rhosts file. |
| Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash. |
| A superfluous NFS server is running, but it is not importing or exporting any file systems. |
| Denial of service in WinGate proxy through a buffer overflow in POP3. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares. |
| A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. |
| A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. |
| A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. |
| The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. |
| SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int. |
| Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups. |