radar

ONE Sentinel

shield

CVE Tracker

96,407 total CVEs

Live vulnerability feed from the National Vulnerability Database

7.2

MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

10.0

The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.

5.0

netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.

7.2

Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

10.0

Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

7.5

Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.

7.5

A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

5.0

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

7.5

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

7.8

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

4.6

Denial of service in Linux 2.2.0 running the ldd command on a core file.

10.0

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

7.2

Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.

5.0

Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.

10.0

ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

7.2

ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.

5.0

Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

7.5

WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.

7.2

Buffer overflow in dtaction command gives root access.

2.1

Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

10.0

Windows NT 4.0 beta allows users to read and delete shares.

5.0

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

7.2

Linux ftpwatch program allows local users to gain root privileges.

2.1

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

10.0

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

Showing 95576-95600 of 96,407 CVEs