radar

ONE Sentinel

shield

CVE Tracker

74,831 total CVEs

Live vulnerability feed from the National Vulnerability Database

5.0

Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.

10.0

ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

7.2

install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.

4.6

Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.

7.2

SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.

4.6

Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.

5.0

Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.

4.6

Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.

2.6

Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.

2.1

Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.

7.5

In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.

7.2

Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.

7.2

Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.

2.1

xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

7.2

A buffer overflow in lsof allows local users to obtain root privilege.

10.0

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

5.0

Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.

2.6

A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.

5.0

O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.

7.5

Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.

2.1

Debian GNU/Linux cfengine package is susceptible to a symlink attack.

7.5

mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.

2.1

Vulnerability in Compaq Tru64 UNIX edauth command.

7.5

Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.

5.0

Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.

Showing 73951-73975 of 74,831 CVEs