Medium Severity Vulnerabilities
128.7K CVEs classified as medium severity
128.7K CVEs classified as medium severity
Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as "pfdisplay") for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.
Netscape Enterprise servers may list files through the PageServices query.
ICMP redirect messages may crash or lock up a host.
htmlscript CGI program allows remote read access to files.
Solaris SUNWadmap can be exploited to obtain root access.
Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.
cfingerd lists all users on a system via search.**@target.
Bonk variation of teardrop IP fragmentation denial of service.
Nestea variation of teardrop IP fragmentation denial of service.
Denial of service in talk program allows remote attackers to disrupt a user's display.
Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".
Bash treats any character with a value of 255 as a command separator.
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
Buffer overflow in Cisco 7xx routers through the telnet service.
Denial of service in Windows NT IIS server using ..\..
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.
Denial of service in Windows NT messenger service through a long username.
Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.
Denial of service of Ascend routers through port 150 (remote administration).
Livingston portmaster machines could be rebooted via a series of commands.
Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.
Denial of service of inetd on Linux through SYN and RST packets.