| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user. |
| Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh). |
| Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list. |
| Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. |
| The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail. |
| HP Secure Web Console uses weak encryption. |
| The default permissions for Endymion MailMan allow local users to read email or modify files. |
| A NETBIOS/SMB share password is the default, null, or missing. |
| An NIS domain name is easily guessable. |
| IP traceroute is allowed from arbitrary hosts. |
| A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness. |
| A router's routing tables can be obtained from arbitrary hosts. |
| A version of finger is running that exposes valid user information to any entity on the network. |
| The rexd service is running, which uses weak authentication that can allow an attacker to execute commands. |
| The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service. |
| Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. |
| Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations. |
| Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command. |
| The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service. |
| NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade. |