High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.3
High
Max CVSS
10.0
Highest
Min CVSS
7.1
Lowest

Browse by Severity

High Severity CVEs

Page 4629 of 4645
CVSS:7.2(High)

Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.

CVSS:7.2(High)

Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.

CVSS:7.5(High)

Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.

CVSS:7.2(High)

Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.

CVSS:9.3(Critical)

The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.

CWE-161999
CVSS:10.0(Critical)

SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.

CVSS:7.2(High)

Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.

CVSS:10.0(Critical)

Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.

CVSS:10.0(Critical)

The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.

CVSS:7.5(High)

The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

CVSS:10.0(Critical)

Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.

CVSS:7.5(High)

Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.

CVSS:10.0(Critical)

QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.

CVSS:7.5(High)

A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.

CVSS:10.0(Critical)

The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.

CVSS:7.8(High)

A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.

CVSS:7.8(High)

An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.

CWE-201999
CVSS:7.1(High)

When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

CWE-161999
CVSS:7.1(High)

The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.

CVSS:10.0(Critical)

The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.