| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message. |
| Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. |
| In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection. |
| The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. |
| Buffer overflow in Samba smbd program via a malformed message command. |
| The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration. |
| The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device. |
| Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. |
| Denial of service in RAS/PPTP on NT systems. |
| The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users. |
| Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port. |
| Buffer overflow in freesweep in Debian GNU/Linux 3.0 allows local users to gain "games" group privileges when processing environment variables. |
| IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. |
| Buffer overflow in marbles 1.0.2 and earlier allows local users to gain privileges via a long HOME environment variable. |
| finger 0@host on some systems may print information on some user accounts. |
| finger .@host on some systems may print information on some user accounts. |
| Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. |
| Denial of service in Sendmail 8.6.11 and 8.6.12. |
| Attackers can do a denial of service of IRC by crashing the server. |
| 64 bit Solaris 7 procfs allows local users to perform a denial of service. |