| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Linux implementations of TFTP would allow access to files outside the restricted directory. |
| Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script. |
| In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution. |
| The passwd command in Solaris can be subjected to a denial of service. |
| Netmanager Chameleon SMTPd has several buffer overflows that cause a crash. |
| Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. |
| The info2www CGI script allows remote file access or remote command execution. |
| Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option. |
| Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution. |
| finger .@host on some systems may print information on some user accounts. |
| Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability. |
| Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. |
| Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made. |
| Denial of service in IIS using long URLs. |
| Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the "Invalid RDP Data" vulnerability. |
| Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error. |
| A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user. |
| Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a "WM_COPYDATA" message to an invisible window that is running with the privileges of the WINLOGON process. |
| The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. |
| Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command. |