The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.
FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by ...
Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.
Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.
A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.
Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.
WS_FTP server remote denial of service through cwd command.
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
ACC Tigris allows public access without a login.
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX o...
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.
nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial...
Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash valu...
NetBSD netstat command allows local users to access kernel memory.
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identi...
rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
Lynx allows a local user to overwrite sensitive files through /tmp symlinks.
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file...
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
Vulnerability in Compaq Tru64 UNIX edauth command.
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ...
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cm...
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by conn...
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when sn...
A buffer overflow in lsof allows local users to obtain root privilege.
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.
Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords...
Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local use...
SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary ...
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt...
Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple co...
InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scriptin...
Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.
Buffer overflow in OpenBSD ping.
Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a ...
Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web...
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.
super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.