| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| WebTrends software stores account names and passwords in a file which does not have restricted access permissions. |
| CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. |
| Denial of service in BIND by improperly closing TCP sessions via so_linger. |
| UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file. |
| The Zeus web server administrative interface uses weak encryption for its passwords. |
| Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. |
| WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges. |
| CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. |
| Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine. |
| Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI. |
| Denial of service in BIND named via malformed SIG records. |
| Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library. |
| Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. |
| Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access. |
| Buffer overflow in BIND 8.2 via NXT records. |
| Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. |
| Falcon web server allows remote attackers to determine the absolute path of the web root via long file names. |
| Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. |
| Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname. |
| Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program. |