CVE Tracker
168,849 total CVEsLive vulnerability feed from the National Vulnerability Database
An SSH server allows authentication through the .rhosts file.
A trust relationship exists between two Unix hosts.
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.
ICMP echo (ping) is allowed from arbitrary hosts.
A system-critical NETBIOS/SMB share has inappropriate access control.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
Anonymous FTP is enabled.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
A service or application has a backdoor password that was placed there by the developer.
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
Showing 168126-168150 of 168,849 CVEs