High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.2
High
Max CVSS
10.0
Highest
Min CVSS
7.2
Lowest

Browse by Severity

High Severity CVEs

Page 4625 of 4645
CVSS:7.2(High)

FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.

CVSS:7.2(High)

Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.

CVSS:7.2(High)

IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.

CVSS:7.2(High)

IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.

CVSS:7.2(High)

sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.

CVSS:7.2(High)

The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.

CVSS:7.6(High)

Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command.

CVSS:10.0(Critical)

WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.

CVSS:7.2(High)

Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

CVSS:10.0(Critical)

Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.

CVSS:10.0(Critical)

Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.

CVSS:7.2(High)

Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.

CVSS:7.2(High)

Buffer overflow in uum program for Canna input system allows local users to gain root privileges.

CVSS:7.5(High)

AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.

CVSS:10.0(Critical)

IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.

CVSS:10.0(Critical)

Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.

CVSS:7.2(High)

UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.

CVSS:7.5(High)

Mutt mail client allows a remote attacker to execute commands via shell metacharacters.

CVSS:7.5(High)

Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.

CVSS:7.5(High)

MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Session Initiation Protocol (SIP) messages.

CVSS:10.0(Critical)

BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.

CVSS:10.0(Critical)

BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.

CVSS:10.0(Critical)

classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.