| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| SGI mediad program allows local users to gain root access. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| SGI syserr program allows local users to corrupt files. |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| Buffer overflow in Solaris kcms_configure command allows local users to gain root access. |
| Buffer overflow in listserv allows arbitrary command execution. |
| arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c). |
| The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107. |
| Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable. |
| Windows NT RSHSVC program allows remote users to execute arbitrary commands. |
| Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command. |
| Some configurations of NIS+ in Linux allowed attackers to log in as the user "+". |
| Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |
| HP-UX gwind program allows users to modify arbitrary files. |
| Remote execution of arbitrary commands through Guestbook CGI program. |
| Bash treats any character with a value of 255 as a command separator. |
| Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges. |
| Buffer overflow in Cisco 7xx routers through the telnet service. |
| Denial of service in Windows NT messenger service through a long username. |
| In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters. |