radar

ONE Sentinel

shield

CVE Tracker

143,144 total CVEs

Live vulnerability feed from the National Vulnerability Database

5.0

Denial of service in Savant web server via a null character in the requested URL.

10.0

Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.

5.0

Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.

5.0

InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.

4.6

UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.

6.2

IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.

10.0

Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.

10.0

WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.

2.1

FTPPro allows local users to read sensitive information, which is stored in plain text.

2.6

strace allows local users to read arbitrary files via memory mapped file names.

7.5

The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

7.5

The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

4.6

Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

10.0

glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.

7.5

glFtpD includes a default glftpd user account with a default password and a UID of 0.

2.6

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

5.0

RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.

7.2

The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.

5.0

Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.

5.0

Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."

10.0

Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.

5.0

Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.

7.2

wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.

10.0

Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.

5.0

Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.

Showing 141676-141700 of 143,144 CVEs