High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.3
High
Max CVSS
10.0
Highest
Min CVSS
7.2
Lowest

Browse by Severity

High Severity CVEs

Page 4626 of 4645
CVSS:7.2(High)

Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.

CVSS:10.0(Critical)

Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

CVSS:7.5(High)

Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.

CVSS:10.0(Critical)

Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.

CVSS:10.0(Critical)

A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.

CVSS:7.8(High)

Denial of service in various Windows systems via malformed, fragmented IGMP packets.

CWE-201999
CVSS:10.0(Critical)

dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

CVSS:10.0(Critical)

Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.

CVSS:7.5(High)

Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.

CVSS:7.2(High)

Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.

CVSS:7.5(High)

genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.

CVSS:7.2(High)

Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.

CVSS:7.2(High)

The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.

CVSS:7.2(High)

Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.

CVSS:10.0(Critical)

Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.

CVSS:10.0(Critical)

Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.

CVSS:7.5(High)

iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.

CVSS:7.5(High)

Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.

CVSS:9.0(Critical)

The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

CWE-161999
CVSS:10.0(Critical)

Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.