CVE Tracker
159,379 total CVEsLive vulnerability feed from the National Vulnerability Database
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
Buffer overflow in ALMail32 POP3 client via From: or To: headers.
FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
The WebRamp web administration utility has a default password.
Buffer overflow in ToxSoft NextFTP client through CWD command.
FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.
Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
Denial of service in Gauntlet Firewall via a malformed ICMP packet.
WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.
Showing 158251-158275 of 159,379 CVEs