| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |
| Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections. |
| The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| Remote command execution in Microsoft Internet Explorer using .lnk and .url files. |
| SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin. |
| Denial of service through Winpopup using large user names. |
| Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. |
| Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable. |
| HP-UX gwind program allows users to modify arbitrary files. |
| Vulnerability in HP-UX mediainit program. |
| Buffer overflow in mstm in HP-UX allows local users to gain root access. |
| NETBIOS share information may be published through SNMP registry keys in NT. |
| A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input. |
| A Windows NT local user or administrator account has a default, null, blank, or missing password. |
| A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. |
| A router's routing tables can be obtained from arbitrary hosts. |
| MajorCool mj_key_cache program allows local users to modify files via a symlink attack. |
| A version of finger is running that exposes valid user information to any entity on the network. |
| Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request. |