Latest CVE Feed
-
10.0
HIGHCVE-2001-1240
The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.... Read more
Affected Products : secure_linux- Published: Jul. 11, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3016
Multiple unspecified vulnerabilities in the WYSIWYG editor in PHP-Nuke before 7.9 Final have unknown impact and attack vectors.... Read more
Affected Products : php-nuke- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1162
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.... Read more
- Published: Jun. 23, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1113
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more
Affected Products : trollftpd- Published: Aug. 13, 2001
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2019-5128
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in... Read more
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-1080
diagrpt in AIX 4.3.x and 5.1 uses the DIAGDATADIR environment variable to find and execute certain programs, which allows local users to gain privileges by modifying the variable to point to a Trojan horse program.... Read more
Affected Products : aix- Published: Jun. 19, 2001
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2019-5151
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could poten... Read more
Affected Products : youphptube- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-0981
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.... Read more
Affected Products : cifs-9000_server- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-5081
An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC 200 Firmware version 03.01.07(13) and 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets c... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-5074
An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12) and WAGO PFC100 Firmware version 03.00.39(12). A speciall... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-0961
Buffer overflow in tab expansion capability of the most program allows local or remote attackers to execute arbitrary code via a malformed file that is viewed with most.... Read more
Affected Products : most- Published: Sep. 18, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0969
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.... Read more
Affected Products : freebsd- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0966
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.... Read more
Affected Products : nudester- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2016-0854
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vector... Read more
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2001-0817
Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.... Read more
Affected Products : hp-ux- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0797
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.... Read more
- Published: Dec. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2007-3828
Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbitrary code via unspecified vectors, a related issue to CVE-2007-2386.... Read more
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2001-0850
A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow.... Read more
Affected Products : openlinux- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0803
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.... Read more
Affected Products : cde_common_desktop_environment- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-5029
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor proce... Read more
Affected Products : exhibitor- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024