Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
5.0
Medium
Max CVSS
5.1
Highest
Min CVSS
4.6
Lowest

Browse by Severity

Medium Severity CVEs

Page 5339 of 5362
CVSS:5.0(Medium)

Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.

CVSS:5.0(Medium)

Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.

CVSS:5.0(Medium)

Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.

CVSS:5.0(Medium)

DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.

CVSS:5.0(Medium)

Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.

CVSS:4.6(Medium)

CascadeView TFTP server allows local users to gain privileges via a symlink attack.

CVSS:5.0(Medium)

Denial of service in Savant web server via a null character in the requested URL.

CVSS:5.0(Medium)

Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.

CVSS:5.0(Medium)

ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.

CVSS:5.0(Medium)

RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.

CVSS:5.0(Medium)

Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large...

CVSS:5.0(Medium)

The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption...

CVSS:5.1(Medium)

Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.

CVSS:5.1(Medium)

Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.

CVSS:5.1(Medium)

The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.oc...

CVSS:5.0(Medium)

Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's...

CVSS:5.0(Medium)

Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending...

CVSS:5.0(Medium)

Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.

CVSS:4.6(Medium)

Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS:5.0(Medium)

Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.

CVSS:4.6(Medium)

gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.

CVSS:5.0(Medium)

Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a...

CVSS:5.0(Medium)

Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long ...

CVSS:5.0(Medium)

Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.