| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler. |
| mSQL v2.0.1 and below allows remote execution through a buffer overflow. |
| ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. |
| Denial of service through Solaris 2.5.1 telnet by sending ^D characters. |
| Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command. |
| Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. |
| Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files. |
| The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| A malicious Palace server can force a client to execute arbitrary programs. |
| ICMP redirect messages may crash or lock up a host. |
| Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. |
| cfingerd lists all users on a system via search.**@target. |
| SGI mediad program allows local users to gain root access. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| SGI syserr program allows local users to corrupt files. |
| IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |
| Buffer overflow in Solaris kcms_configure command allows local users to gain root access. |
| Buffer overflow in listserv allows arbitrary command execution. |
| arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c). |