Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
4.9
Medium
Max CVSS
6.4
Highest
Min CVSS
4.6
Lowest

Browse by Severity

Medium Severity CVEs

Page 5355 of 5362
CVSS:5.0(Medium)

An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.

CVSS:5.0(Medium)

An incorrect configuration of the PDG Shopping Cart CGI program "shopper.cgi" could disclose private information.

CVSS:5.0(Medium)

quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password...

CVSS:5.0(Medium)

An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information.

CVSS:5.0(Medium)

An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.

CVSS:5.0(Medium)

An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information.

CVSS:4.9(Medium)

The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.

CVSS:5.0(Medium)

A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.

CVSS:4.6(Medium)

A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

CVSS:5.0(Medium)

An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.

CVSS:4.6(Medium)

HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.

CVSS:4.6(Medium)

A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate ...

CVSS:5.0(Medium)

UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.

CVSS:5.0(Medium)

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

CVSS:4.6(Medium)

An account on a router, firewall, or other network device has a default, null, blank, or missing password.

CVSS:4.6(Medium)

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

CWE-941999
CVSS:5.0(Medium)

Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.

CVSS:5.0(Medium)

Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.