Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
4.9
Medium
Max CVSS
6.2
Highest
Min CVSS
4.0
Lowest

Browse by Severity

Medium Severity CVEs

Page 5354 of 5362
CVSS:4.6(Medium)

The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.

CVSS:6.2(Medium)

Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

CVSS:5.0(Medium)

The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.

CVSS:5.0(Medium)

Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.

CVSS:5.1(Medium)

Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.

CVSS:5.0(Medium)

Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

CVSS:5.0(Medium)

Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.

CVSS:5.0(Medium)

Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

CVSS:5.0(Medium)

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

CVSS:4.6(Medium)

sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.

CVSS:5.0(Medium)

Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.

CVSS:4.0(Medium)

Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.

CVSS:4.0(Medium)

The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

CVSS:5.1(Medium)

The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

CVSS:5.0(Medium)

The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.

CWE-161999
CVSS:5.0(Medium)

The netstat service is running, which provides sensitive information to remote attackers.

CVSS:5.0(Medium)

The rwho/rwhod service is running, which exposes machine status and user information.

CVSS:5.0(Medium)

An incorrect configuration of the Webcart CGI program could disclose private information.