Latest CVE Feed
-
10.0
HIGHCVE-2021-24527
The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to reset the password of the admin of the blog, and gain unauthorised access, due to a bypass in the way the reset key is checked. Furthermore... Read more
Affected Products : profile_builder- Published: Aug. 16, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2003-0722
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.... Read more
Affected Products : solaris- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0690
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5... Read more
Affected Products : kde- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0648
Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.... Read more
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0201
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3700
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.... Read more
Affected Products : database_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0609
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.... Read more
Affected Products : cfingerd- Published: Aug. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0133
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET... Read more
Affected Products : interscan_viruswall- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0100
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more
Affected Products : bslist.cgi- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1077
Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.... Read more
Affected Products : iplanet_web_server- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0584
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.... Read more
- Published: Jul. 02, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-1420
NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.... Read more
- Published: Jul. 20, 1998
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0937
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.... Read more
Affected Products :- Published: Dec. 03, 1998
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0853
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.... Read more
- Published: Dec. 01, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0452
A service or application has a backdoor password that was placed there by the developer.... Read more
Affected Products :- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0204
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.... Read more
Affected Products : sendmail- Published: Jan. 01, 1997
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-0721
Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and p... Read more
Affected Products : qts- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0539
QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : qqq_systems- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0514
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : mp_form_mail_cgi- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0375
A vulnerability in the Cluster Manager of Cisco Policy Suite before 18.2.0 could allow an unauthenticated, remote attacker to log in to an affected system using the root account, which has default, static user credentials. The vulnerability is due to the ... Read more
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024