| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cross-site scripting (XSS) vulnerability in password.asp in DUWare DUportal Pro 3.4.3 allows remote attackers to inject arbitrary web script or HTML via the result parameter. |
| SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. |
| IP traceroute is allowed from arbitrary hosts. |
| Multiple SQL injection vulnerabilities in eFiction 1.0, 1.1, and 2.0 allow remote attackers to execute arbitrary SQL commands via (1) the let parameter in a viewlist action to titles.php and (2) the username. |
| Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler. |
| mSQL v2.0.1 and below allows remote execution through a buffer overflow. |
| ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. |
| Denial of service through Solaris 2.5.1 telnet by sending ^D characters. |
| Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command. |
| Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. |
| Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files. |
| The jail_attach system call in FreeBSD 5.1 and 5.2 changes the directory of a calling process even if the process doesn't have permission to change directory, which allows local users to gain read/write privileges to files and directories within another jail. |
| MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. |
| A malicious Palace server can force a client to execute arbitrary programs. |
| ICMP redirect messages may crash or lock up a host. |
| Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access. |
| cfingerd lists all users on a system via search.**@target. |
| SGI mediad program allows local users to gain root access. |
| A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. |
| SGI syserr program allows local users to corrupt files. |