Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
5.1
Medium
Max CVSS
6.2
Highest
Min CVSS
5.0
Lowest

Browse by Severity

Medium Severity CVEs

Page 5350 of 5362
CVSS:5.0(Medium)

The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially sett...

CVSS:6.2(Medium)

Race condition in xterm allows local users to modify arbitrary files via the logging option.

CVSS:6.2(Medium)

HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.

CVSS:5.0(Medium)

Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.

CVSS:5.0(Medium)

classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.

CVSS:5.0(Medium)

TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS:5.0(Medium)

Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.

CVSS:5.0(Medium)

wwwboard allows a remote attacker to delete message board articles via a malformed argument.

CVSS:5.0(Medium)

Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.

CVSS:5.0(Medium)

Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.

CVSS:5.0(Medium)

NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS:5.0(Medium)

UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.

CVSS:5.0(Medium)

The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.

CVSS:5.0(Medium)

An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.

CVSS:5.0(Medium)

BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.

CVSS:5.1(Medium)

The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.

CVSS:5.0(Medium)

URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.

CVSS:5.0(Medium)

Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.

CVSS:5.0(Medium)

Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.

CVSS:5.0(Medium)

Denial of service in Axent Raptor firewall via malformed zero-length IP options.

CVSS:5.0(Medium)

Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.

CVSS:5.0(Medium)

iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.