CVE Tracker
211,763 total CVEsLive vulnerability feed from the National Vulnerability Database
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
rpc.admind in Solaris is not running in a secure mode.
A Sendmail alias allows input to be piped to a program.
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
IIS has the #exec function enabled for Server Side Include (SSI) files.
A system-critical Windows NT file or directory has inappropriate permissions.
A system-critical Unix file or directory has inappropriate permissions.
Two or more Unix accounts have the same UID.
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
NFS exports system-critical data to the world, e.g. / or a password file.
Windows NT automatically logs in an administrator upon rebooting.
A superfluous NFS server is running, but it is not importing or exporting any file systems.
An SSH server allows authentication through the .rhosts file.
A trust relationship exists between two Unix hosts.
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.
ICMP echo (ping) is allowed from arbitrary hosts.
A system-critical NETBIOS/SMB share has inappropriate access control.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
Anonymous FTP is enabled.
Showing 211026-211050 of 211,763 CVEs