| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program. |
| Denial of service by sending forged ICMP unreachable packets. |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| HP Remote Watch allows a remote user to gain root access. |
| Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. |
| Denial of service in IIS using long URLs. |
| Denial of service through Winpopup using large user names. |
| Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. |
| Buffer overflow in FreeBSD lpd through long DNS hostnames. |
| fpkg2swpk in HP-UX allows local users to gain root access. |
| Vulnerability in HP-UX mediainit program. |
| In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access. |
| TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files. |
| NETBIOS share information may be published through SNMP registry keys in NT. |
| A Windows NT local user or administrator account has a guessable password. |
| A NETBIOS/SMB share password is guessable. |
| A NETBIOS/SMB share password is the default, null, or missing. |
| IP traceroute is allowed from arbitrary hosts. |
| A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input. |
| A router's routing tables can be obtained from arbitrary hosts. |