Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
5.1
Medium
Max CVSS
6.4
Highest
Min CVSS
4.6
Lowest

Browse by Severity

Medium Severity CVEs

Page 5358 of 5362
CVSS:6.4(Medium)

FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.

CVSS:6.2(Medium)

Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.

CVSS:5.0(Medium)

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

CVSS:5.0(Medium)

Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

CVSS:6.2(Medium)

Linux PAM modules allow local users to gain root access using temporary files.

CVSS:5.0(Medium)

The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the...

CVSS:5.0(Medium)

All records in a WINS database can be deleted through SNMP for a denial of service.

CVSS:5.0(Medium)

The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.

CVSS:5.0(Medium)

The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.

CVSS:5.0(Medium)

The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstr...

CVSS:5.0(Medium)

In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

CVSS:5.0(Medium)

Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.

CVSS:5.0(Medium)

Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.