High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.0
High
Max CVSS
10.0
Highest
Min CVSS
7.2
Lowest

Browse by Severity

High Severity CVEs

Page 4630 of 4645
CVSS:7.8(High)

Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

CWE-201999
CVSS:7.2(High)

The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.

CVSS:7.5(High)

The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other...

CVSS:7.2(High)

Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.

CVSS:7.5(High)

The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.

CVSS:7.5(High)

Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.

CVSS:9.3(Critical)

Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.

CVSS:10.0(Critical)

Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

CWE-941999
CVSS:7.2(High)

After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.

CWE-161999
CVSS:7.5(High)

The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.

CVSS:7.2(High)

Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.

CVSS:10.0(Critical)

The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.

CVSS:7.2(High)

Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.

CVSS:7.2(High)

The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.

CVSS:7.5(High)

The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.

CVSS:7.5(High)

Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.

CVSS:7.2(High)

The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

CVSS:10.0(Critical)

The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.