| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error. |
| A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user. |
| Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. |
| The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. |
| Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. |
| rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. |
| NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access. |
| Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters. |
| Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone. |
| Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server. |
| Solaris volrmmount program allows attackers to read any file. |
| Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the "Malformed PPTP Packet Stream" vulnerability. |
| Buffer overflow in mana in OpenServer 5.0.6a and earlier allows local users to execute arbitrary code. |
| Denial of service of Ascend routers through port 150 (remote administration). |
| Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry. |
| Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable. |
| Denial of service in Windows NT IIS server using ..\.. |
| Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. |
| Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack. |
| HP ypbind allows attackers with root privileges to modify NIS data. |