| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death. |
| Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. |
| Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access. |
| Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. |
| fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access. |
| vold in Solaris 2.x allows local users to gain root access. |
| Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access. |
| The dip program on many Linux systems allows local users to gain root access via a buffer overflow. |
| The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. |
| admintool in Solaris allows a local user to write to arbitrary files and gain root access. |
| Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet. |
| The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |
| Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys. |
| Sendmail WIZ command enabled, allowing root access. |
| The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file. |
| The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands. |
| The handler CGI program in IRIX allows arbitrary command execution. |
| The DG/UX finger daemon allows remote command execution through shell metacharacters. |
| IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. |
| The ghostscript command with the -dSAFER option allows remote attackers to execute commands. |