Medium Severity Vulnerabilities

128.7K CVEs classified as medium severity

MEDIUM
Total CVEs
128.7K
Vulnerabilities
Avg CVSS
4.9
Medium
Max CVSS
5.0
Highest
Min CVSS
4.6
Lowest

Browse by Severity

Medium Severity CVEs

Page 5361 of 5362
CVSS:5.0(Medium)

IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

CVSS:5.0(Medium)

Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.

CVSS:4.6(Medium)

Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.

CVSS:4.6(Medium)

Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.

CVSS:5.0(Medium)

Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.

CVSS:5.0(Medium)

Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.

CVSS:4.6(Medium)

Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.

CVSS:5.0(Medium)

Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.

CVSS:5.0(Medium)

A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.

CVSS:5.0(Medium)

Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.

CVSS:5.0(Medium)

Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.

CVSS:5.0(Medium)

Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.

CVSS:5.0(Medium)

PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.