radar

ONE Sentinel

shield

CVE Tracker

96,703 total CVEs

Live vulnerability feed from the National Vulnerability Database

5.0

ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.

7.2

The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.

10.0

Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.

5.0

AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.

7.2

The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.

5.0

Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.

5.0

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

4.6

Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.

4.6

resend command in Majordomo allows local users to gain privileges via shell metacharacters.

5.0

Denial of service in Savant web server via a null character in the requested URL.

10.0

Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.

5.0

Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.

5.0

InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.

4.6

UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.

6.2

IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.

10.0

Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.

10.0

WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.

2.1

FTPPro allows local users to read sensitive information, which is stored in plain text.

2.6

strace allows local users to read arbitrary files via memory mapped file names.

7.5

The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

7.5

The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

4.6

Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

10.0

glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.

7.5

glFtpD includes a default glftpd user account with a default password and a UID of 0.

2.6

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

Showing 95226-95250 of 96,703 CVEs