radar

ONE Sentinel

shield

CVE Tracker

121,335 total CVEs

Live vulnerability feed from the National Vulnerability Database

10.0

Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

10.0

Attackers can do a denial of service of IRC by crashing the server.

5.0

Denial of service in Sendmail 8.6.11 and 8.6.12.

10.0

Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.

10.0

finger .@host on some systems may print information on some user accounts.

10.0

finger 0@host on some systems may print information on some user accounts.

4.6

SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.

2.1

Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.

4.6

mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.

5.0

Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.

7.5

Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.

7.5

nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.

4.6

BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.

2.1

Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.

7.2

The passwd command in Solaris can be subjected to a denial of service.

7.2

Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.

4.6

RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.

7.2

fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.

7.5

Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.

10.0

Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

7.5

Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.

10.0

BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.

10.0

BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.

10.0

UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.

2.6

Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.

Showing 120651-120675 of 121,335 CVEs