CVE Tracker
167,614 total CVEsLive vulnerability feed from the National Vulnerability Database
Buffer overflow in dtaction command gives root access.
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
Windows NT 4.0 beta allows users to read and delete shares.
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.
Linux ftpwatch program allows local users to gain root privileges.
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
Buffer overflow in Thomas Boutell's cgic library version up to 1.05.
Solaris ff.core allows local users to modify files.
Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.
L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.
Buffer overflow in Dosemu Slang library in Linux.
search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
Buffer overflow in the bootp server in the Debian Linux netstd package.
HP-UX aserver program allows local users to gain privileges via a symlink attack.
The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.
Showing 166801-166825 of 167,614 CVEs