| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. |
| Buffer overflow in ircd allows arbitrary command execution. |
| Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page. |
| cfingerd lists all users on a system via search.**@target. |
| ICMP redirect messages may crash or lock up a host. |
| HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack. |
| rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory. |
| ftp on HP-UX 11.00 allows local users to gain privileges. |
| Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS. |
| gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files. |
| A NETBIOS/SMB share password is the default, null, or missing. |
| The "screen dump" feature in Eterm 0.9.1 and earlier allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to a user's terminal, e.g. when the user views a file containing the malicious sequence. |
| A superfluous NFS server is running, but it is not importing or exporting any file systems. |
| The rpc.sprayd service is running. |
| The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service. |
| Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option. |
| The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. |
| Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser. |
| FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument. |
| Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers. |