CVE Tracker
144,842 total CVEsLive vulnerability feed from the National Vulnerability Database
Denial of service in Qmail through long SMTP commands.
Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
NFS allows attackers to read and write any file on the system by specifying a false UID.
wu-ftpd FTP daemon allows any user and password combination.
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
The Perl fingerd program allows arbitrary command execution from remote users.
The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.
RIP v1 is susceptible to spoofing.
Buffer overflow in wu-ftp from PASV command causes a core dump.
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
MajorCool mj_key_cache program allows local users to modify files via a symlink attack.
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.
Command execution in Sun systems via buffer overflow in the at program.
getcwd() file descriptor leak in FTP.
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.
Denial of service in IIS using long URLs.
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.
Showing 144526-144550 of 144,842 CVEs