| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php and (2) id parameter in stats.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information. |
| Unspecified vulnerability in the sapdba command in SAP with Informix before 700, and 700 up to patch 100, allows local users to execute arbitrary commands via unknown vectors related to "insecure environment variable" handling. |
| Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag. |
| Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. |
| The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file. |
| NFS allows attackers to read and write any file on the system by specifying a false UID. |
| FormMail CGI program can be used by web servers other than the host server that the program resides on. |
| The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. |
| The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost. |
| Buffer overflow in Linux su command gives root access to local users. |
| NetBSD netstat command allows local users to access kernel memory. |
| Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. |
| A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. |
| A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. |
| The Windows NT guest account is enabled. |
| HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. |
| The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates. |
| The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch. |