| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. |
| KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. |
| KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables. |
| KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file. |
| The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. |
| A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. |
| The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. |
| Denial of service in WinGate proxy through a buffer overflow in POP3. |
| NT users can gain debug-level access on a system process using the Sechole exploit. |
| Linux PAM modules allow local users to gain root access using temporary files. |
| Buffer overflow in the Linux mail program "deliver" allows local users to gain root access. |
| HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack. |
| Buffer overflow in Internet Explorer 4.0(1). |
| SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files. |
| buffer overflow in HP xlock program. |
| The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections. |
| AAA authentication on Cisco systems allows attackers to execute commands without authorization. |
| The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost. |
| Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. |
| Progressive Networks Real Video server (pnserver) can be crashed remotely. |