| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp. |
| When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". |
| A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. |
| KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories. |
| The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. |
| Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL. |
| The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. |
| Denial of service in HP-UX SharedX recserv program. |
| The SSH authentication agent follows symlinks via a UNIX domain socket. |
| Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file. |
| Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. |
| The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. |
| Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. |
| UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. |
| HP Secure Web Console uses weak encryption. |
| Denial of service in Linux syslogd via a large number of connections. |
| Denial of service in BIND by improperly closing TCP sessions via so_linger. |
| Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled. |
| Denial of service in MDaemon WorldClient and WebConfig services via a long URL. |
| Denial of service in BIND named via consuming more than "fdmax" file descriptors. |