| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| AnyForm CGI remote execution. |
| CGI PHP mylog script allows an attacker to read any file on the target server. |
| Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. |
| Buffer overflow in AIX xdat gives root access to local users. |
| Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access. |
| Listening TCP ports are sequentially allocated, allowing spoofing attacks. |
| PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password. |
| Buffer overflow in wu-ftp from PASV command causes a core dump. |
| Predictable TCP sequence numbers allow spoofing. |
| Buffer overflow in AIX libDtSvc library can allow local users to gain root access. |
| Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports. |
| Buffer overflow in AIX rcp command allows local users to obtain root access. |
| Sendmail decode alias can be used to overwrite sensitive files. |
| The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character). |
| Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities. |
| Remote access in AIX innd 1.5.1, using control messages. |
| Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line. |
| Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm. |
| A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2. |
| finger allows recursive searches by using a long string of @ symbols. |