CVE Database

Search and browse vulnerability records from NVD

Showing 23 of 21473 CVEs

CVE ID Severity Description EPSS Published
7.5 HIGH

IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

0.7% 2000-06-08
7.5 HIGH

Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

1.6% 2000-06-08
7.5 HIGH

The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.

1.4% 2000-06-08
7.5 HIGH

Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Stealth Attachment."

2.5% 2000-04-28
7.5 HIGH

IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.

20.3% 2000-04-12
7.5 HIGH

Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.

30.0% 1999-12-31
7.8 HIGH

Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.

0.2% 1999-11-16
8.2 HIGH

Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.

1.9% 1999-04-09
7.5 HIGH

Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

1.4% 1999-01-01
7.5 HIGH

IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.

1.1% 1998-11-04
7.5 HIGH

Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.

0.7% 1998-06-03
8.4 HIGH

Solaris ufsrestore buffer overflow.

0.7% 1998-04-29
7.0 HIGH

Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.

0.7% 1998-02-06
8.4 HIGH

Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.

0.5% 1998-01-22
7.5 HIGH

Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.

4.1% 1998-01-01
8.4 HIGH

root privileges via buffer overflow in ordist command on SGI IRIX systems.

0.4% 1997-07-16
7.3 HIGH

IRIX fam service allows an attacker to obtain a list of all files on the server.

0.7% 1997-07-14
8.4 HIGH

IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.

0.8% 1997-05-26
7.3 HIGH

webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.

20.7% 1997-05-06
8.4 HIGH

Buffer overflow in xlock program allows local users to execute commands as root.

0.1% 1997-04-26
7.5 HIGH

ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.

17.6% 1997-01-01
7.8 HIGH

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

0.2% 1996-07-03
8.4 HIGH

Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.

0.1% 1990-05-01