| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| ICMP echo (ping) is allowed from arbitrary hosts. |
| IP traceroute is allowed from arbitrary hosts. |
| A DNS server allows inverse queries. |
| A trust relationship exists between two Unix hosts. |
| A password for accessing a WWW URL is guessable. |
| Two or more Unix accounts have the same UID. |
| A system-critical Unix file or directory has inappropriate permissions. |
| A system-critical Windows NT file or directory has inappropriate permissions. |
| IIS has the #exec function enabled for Server Side Include (SSI) files. |
| A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. |
| A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. |
| .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |
| A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. |
| A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
| A Sendmail alias allows input to be piped to a program. |
| rpc.admind in Solaris is not running in a secure mode. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |
| A Windows NT file system is not NTFS. |
| A network service is running on a nonstandard port. |
| A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data. |