CVE Tracker
74,858 total CVEsLive vulnerability feed from the National Vulnerability Database
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.
Denial of service in AIX ptrace system call allows local users to crash the system.
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
Buffer overflow in ALMail32 POP3 client via From: or To: headers.
FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
The WebRamp web administration utility has a default password.
Buffer overflow in ToxSoft NextFTP client through CWD command.
FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.
Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
Denial of service in Gauntlet Firewall via a malformed ICMP packet.
Showing 73726-73750 of 74,858 CVEs