High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.6
High
Max CVSS
10.0
Highest
Min CVSS
7.2
Lowest

Browse by Severity

High Severity CVEs

Page 4628 of 4645
CVSS:10.0(Critical)

Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.

CVSS:7.2(High)

Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.

CVSS:10.0(Critical)

Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.

CVSS:10.0(Critical)

The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.

CVSS:10.0(Critical)

Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

CVSS:7.2(High)

Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

CVSS:7.6(High)

Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.

CVSS:7.5(High)

Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.

CVSS:7.2(High)

The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.

CVSS:7.6(High)

Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.

CVSS:10.0(Critical)

BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.

CVSS:10.0(Critical)

Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

CVSS:7.5(High)

The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.

CVSS:10.0(Critical)

Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.

CVSS:7.2(High)

The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file.

CVSS:7.2(High)

KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.

CVSS:7.2(High)

Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.

CVSS:7.5(High)

IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.

CVSS:10.0(Critical)

Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.