| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php in /ecrire/tools/; (8) /ecrire/inc/connexion.php and (9) /inc/session.php; (10) class.blog.php, (11) class.blogcomment.php, (12) and class.blogpost.php in /inc/classes/; (13) append.php, (14) class.xblog.php, (15) class.xblogcomment.php, and (16) class.xblogpost.php in /layout/; (17) form.php, (18) list.php, (19) post.php, or (20) template.php in /themes/default/, which reveal the installation path in error messages. |
| The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session. |
| Race condition in signal handling routine in ftpd, allowing read/write arbitrary files. |
| fsdump command in IRIX allows local users to obtain root access by modifying sensitive files. |
| MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. |
| Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. |
| AIX routed allows remote users to modify sensitive files. |
| AIX nslookup command allows local users to obtain root access by not dropping privileges correctly. |
| Windows NT 4.0 beta allows users to read and delete shares. |
| Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon. |
| Denial of service in RAS/PPTP on NT systems. |
| The DG/UX finger daemon allows remote command execution through shell metacharacters. |
| FormMail CGI program allows remote execution of commands. |
| finger 0@host on some systems may print information on some user accounts. |
| Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag. |
| Buffer overflow in canuum program for Canna input system allows local users to gain root privileges. |
| Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. |
| IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections. |
| Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator. |
| AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters. |