CWE-16 · 317 записей
Configuration
CVE этого класса
317 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2004-2687Готовый эксплойт | distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute aapple · xcode · CWE-16 | Критическая9,3 | — | 88,2 % | 31 дек. 2004 г. |
54В плане | CVE-2006-3677Готовый эксплойт | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain propertimozilla · firefox · CWE-16 | Высокая7,5 | — | 78,7 % | 27 июл. 2006 г. |
54В плане | CVE-2024-46909Эксплойта нет | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-16 | Критическая9,8 | — | 48,9 % | 2 дек. 2024 г. |
50В плане | CVE-2017-6639Эксплойта нет | A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unautcisco · prime data center network manager · CWE-16 | Критическая9,8 | — | 35,4 % | 8 июн. 2017 г. |
49В плане | CVE-2007-2216Proof of concept | The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,microsoft · internet explorer · CWE-16 | Критическая9,3 | — | 41,4 % | 14 авг. 2007 г. |
46В плане | CVE-2009-2335Готовый эксплойт | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, wordpress · wordpress · CWE-16 | Средняя5,0 | — | 85,0 % | 10 июл. 2009 г. |
43В плане | CVE-2005-4837Эксплойта нет | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allownet-snmp · net-snmp · CWE-16 | Критическая10,0 | — | 9,7 % | 31 дек. 2005 г. |
43В плане | CVE-2013-4316Эксплойта нет | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.apache · struts · CWE-16 | Критическая10,0 | — | 8,4 % | 30 сент. 2013 г. |
42В плане | CVE-1999-0886Proof of concept | The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.microsoft · windows nt · CWE-16 | Критическая9,0 | — | 21,6 % | 17 сент. 1999 г. |
42В плане | CVE-2009-3956Эксплойта нет | The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhancadobe · acrobat · CWE-16 | Критическая10,0 | — | 7,7 % | 13 янв. 2010 г. |
42В плане | CVE-2007-4074Эксплойта нет | The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, andcentre for speech technology research · gentoo linux · CWE-16 | Критическая10,0 | — | 5,4 % | 30 июл. 2007 г. |
41В плане | CVE-2007-3898Proof of concept | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS smicrosoft · windows 2000 · CWE-16 | Средняя6,4 | — | 52,3 % | 13 нояб. 2007 г. |
41В плане | CVE-2008-1662Эксплойта нет | Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allohp · hp-ux · CWE-16 | Критическая10,0 | — | 4,4 % | 1 авг. 2008 г. |
41В плане | CVE-2011-4501Эксплойта нет | The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fiedimax · br-6104k router firmware · CWE-16 | Критическая10,0 | — | 4,2 % | 22 нояб. 2011 г. |
41В плане | CVE-2013-1221Эксплойта нет | The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcacisco · unified customer voice portal · CWE-16 | Критическая10,0 | — | 3,4 % | 9 мая 2013 г. |
41В плане | CVE-2010-2276Эксплойта нет | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.xdojotoolkit · dojo · CWE-16 | Критическая10,0 | — | 3,2 % | 15 июн. 2010 г. |
41В плане | CVE-2008-1392Эксплойта нет | The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the consolevmware · ace · CWE-16 | Критическая10,0 | — | 2,7 % | 19 мар. 2008 г. |
41В плане | CVE-2008-4212Эксплойта нет | Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite whatapple · mac os x · CWE-16 | Критическая10,0 | — | 2,6 % | 10 окт. 2008 г. |
41В плане | CVE-2007-5419Эксплойта нет | The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I3com · 3crwe554g72t · CWE-16 | Критическая10,0 | — | 2,2 % | 12 окт. 2007 г. |
41В плане | CVE-2003-1357Эксплойта нет | ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.replicom · proxyview · CWE-16 | Критическая10,0 | — | 2,2 % | 31 дек. 2003 г. |
41В плане | CVE-2009-2357Эксплойта нет | The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote atyasinkaplan · tekradius · CWE-16 | Критическая10,0 | — | 2,1 % | 7 июл. 2009 г. |
41В плане | CVE-2010-4586Эксплойта нет | The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, poopera · opera browser · CWE-16 | Критическая10,0 | — | 2,1 % | 21 дек. 2010 г. |
41В плане | CVE-2009-0621Эксплойта нет | Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (bcisco · ace 4710 · CWE-16 | Критическая10,0 | — | 1,8 % | 26 февр. 2009 г. |
41В плане | CVE-2008-6820Эксплойта нет | The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impacibm · db2 · CWE-16 | Критическая10,0 | — | 1,8 % | 3 июн. 2009 г. |
40В плане | CVE-2009-0641Proof of concept | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onlfreebsd · freebsd · CWE-16 | Критическая9,3 | — | 9,3 % | 20 февр. 2009 г. |
- CVE-2004-268763На этой неделе
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute a
КритическаяCVSS 9,3Готовый эксплойтEPSS 88 %apple · xcode31 дек. 2004 г.
- CVE-2006-367754В плане
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %mozilla · firefox27 июл. 2006 г.
- CVE-2024-4690954В плане
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 49 %progress · whatsup gold2 дек. 2024 г.
- CVE-2017-663950В плане
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unaut
КритическаяCVSS 9,8Эксплойта нетEPSS 35 %cisco · prime data center network manager8 июн. 2017 г.
- CVE-2007-221649В плане
The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,
КритическаяCVSS 9,3Proof of conceptEPSS 41 %microsoft · internet explorer14 авг. 2007 г.
- CVE-2009-233546В плане
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,
СредняяCVSS 5,0Готовый эксплойтEPSS 85 %wordpress · wordpress10 июл. 2009 г.
- CVE-2005-483743В плане
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allow
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %net-snmp · net-snmp31 дек. 2005 г.
- CVE-2013-431643В плане
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %apache · struts30 сент. 2013 г.
- CVE-1999-088642В плане
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
КритическаяCVSS 9,0Proof of conceptEPSS 22 %microsoft · windows nt17 сент. 1999 г.
- CVE-2009-395642В плане
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanc
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %adobe · acrobat13 янв. 2010 г.
- CVE-2007-407442В плане
The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %centre for speech technology research · gentoo linux30 июл. 2007 г.
- CVE-2007-389841В плане
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS s
СредняяCVSS 6,4Proof of conceptEPSS 52 %microsoft · windows 200013 нояб. 2007 г.
- CVE-2008-166241В плане
Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allo
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %hp · hp-ux1 авг. 2008 г.
- CVE-2011-450141В плане
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fi
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %edimax · br-6104k router firmware22 нояб. 2011 г.
- CVE-2013-122141В плане
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomca
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %cisco · unified customer voice portal9 мая 2013 г.
- CVE-2010-227641В плане
The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %dojotoolkit · dojo15 июн. 2010 г.
- CVE-2008-139241В плане
The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %vmware · ace19 мар. 2008 г.
- CVE-2008-421241В плане
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %apple · mac os x10 окт. 2008 г.
- CVE-2007-541941В плане
The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %3com · 3crwe554g72t12 окт. 2007 г.
- CVE-2003-135741В плане
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %replicom · proxyview31 дек. 2003 г.
- CVE-2009-235741В плане
The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote at
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %yasinkaplan · tekradius7 июл. 2009 г.
- CVE-2010-458641В плане
The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, po
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %opera · opera browser21 дек. 2010 г.
- CVE-2009-062141В плане
Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %cisco · ace 471026 февр. 2009 г.
- CVE-2008-682041В плане
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impac
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %ibm · db23 июн. 2009 г.
- CVE-2009-064140В плане
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onl
КритическаяCVSS 9,3Proof of conceptEPSS 9 %freebsd · freebsd20 февр. 2009 г.