| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| FormMail CGI program can be used by web servers other than the host server that the program resides on. |
| The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. |
| The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost. |
| Buffer overflow in Linux su command gives root access to local users. |
| NetBSD netstat command allows local users to access kernel memory. |
| Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. |
| A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. |
| A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. |
| The Windows NT guest account is enabled. |
| HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. |
| A system-critical Unix file or directory has inappropriate permissions. |
| A Sendmail alias allows input to be piped to a program. |
| A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. |
| Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. |
| The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. |
| The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch. |
| The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. |
| Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. |