Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
5.0
Medium
Max CVSS
6.4
Highest
Min CVSS
4.6
Lowest

Browse by Severity

Medium Severity CVEs

Page 5356 of 5362
CVSS:5.0(Medium)

The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.

CVSS:5.0(Medium)

The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.

CVSS:5.0(Medium)

The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button.

CVSS:5.0(Medium)

A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.

CVSS:5.0(Medium)

Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.

CVSS:5.0(Medium)

The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.

CVSS:4.6(Medium)

Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.

CVSS:5.0(Medium)

An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).

CVSS:5.0(Medium)

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

CVSS:4.6(Medium)

Local users can gain privileges using the debug utility in the MPE/iX operating system.

CVSS:5.0(Medium)

In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.

CVSS:5.0(Medium)

Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.

CVSS:5.0(Medium)

Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.

CVSS:5.0(Medium)

Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.

CVSS:5.0(Medium)

Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.

CVSS:4.6(Medium)

Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.

CVSS:4.6(Medium)

XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

CVSS:5.0(Medium)

Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.

CVSS:5.0(Medium)

Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.

CVSS:6.4(Medium)

talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.

CVSS:4.6(Medium)

Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.