| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| List of arbitrary files on Web host via nph-test-cgi script. |
| Buffer overflow in HP-UX newgrp program. |
| File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). |
| AnyForm CGI remote execution. |
| pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. |
| Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command. |
| getcwd() file descriptor leak in FTP. |
| Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0. |
| Buffer overflow in AIX rcp command allows local users to obtain root access. |
| The debug command in Sendmail is enabled, allowing attackers to execute commands as root. |
| Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm. |
| RIP v1 is susceptible to spoofing. |
| Buffer overflow in AIX lchangelv gives root access. |
| swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access. |
| Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. |
| The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |
| Sendmail WIZ command enabled, allowing root access. |
| The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access. |
| In older versions of Sendmail, an attacker could use a pipe character to execute root commands. |
| In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system. |