finger 0@host on some systems may print information on some user accounts.
finger .@host on some systems may print information on some user accounts.
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP se
Denial of service in Sendmail 8.6.11 and 8.6.12.
Attackers can do a denial of service of IRC by crashing the server.
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of s
Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.
Linux cfingerd could be exploited to gain root access.
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credent
Buffer overflow in ircd allows arbitrary command execution.
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
mSQL v2.0.1 and below allows remote execution through a buffer overflow.
The Java Web Server would allow remote users to obtain the source code for CGI programs.
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logg
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's c
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute command
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of he
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attack
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL
A service or application has a backdoor password that was placed there by the developer.
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packet
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
Anonymous FTP is enabled.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
A system-critical NETBIOS/SMB share has inappropriate access control.
ICMP echo (ping) is allowed from arbitrary hosts.
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A trust relationship exists between two Unix hosts.
An SSH server allows authentication through the .rhosts file.
A superfluous NFS server is running, but it is not importing or exporting any file systems.
Windows NT automatically logs in an administrator upon rebooting.
NFS exports system-critical data to the world, e.g. / or a password file.
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
Two or more Unix accounts have the same UID.
Scan for 1999 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started