Skip to content
Noroxi

CWE-16 · 317 records

Configuration

CVEs in this class

317 records

  • CVE-2004-2687
    63This week

    distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute a

    CriticalCVSS 9.3WeaponizedEPSS 88%

    apple · xcodeDec 31, 2004

  • Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti

    HighCVSS 7.5WeaponizedEPSS 79%

    mozilla · firefoxJul 27, 2006

  • WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 49%

    progress · whatsup goldDec 2, 2024

  • A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unaut

    CriticalCVSS 9.8No exploitEPSS 35%

    cisco · prime data center network managerJun 8, 2017

  • The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,

    CriticalCVSS 9.3Proof of conceptEPSS 41%

    microsoft · internet explorerAug 14, 2007

  • WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,

    MediumCVSS 5.0WeaponizedEPSS 85%

    wordpress · wordpressJul 10, 2009

  • snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allow

    CriticalCVSS 10.0No exploitEPSS 10%

    net-snmp · net-snmpDec 31, 2005

  • Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 8%

    apache · strutsSep 30, 2013

  • The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

    CriticalCVSS 9.0Proof of conceptEPSS 22%

    microsoft · windows ntSep 17, 1999

  • The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanc

    CriticalCVSS 10.0No exploitEPSS 8%

    adobe · acrobatJan 13, 2010

  • The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and

    CriticalCVSS 10.0No exploitEPSS 5%

    centre for speech technology research · gentoo linuxJul 30, 2007

  • The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS s

    MediumCVSS 6.4Proof of conceptEPSS 52%

    microsoft · windows 2000Nov 13, 2007

  • Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allo

    CriticalCVSS 10.0No exploitEPSS 4%

    hp · hp-uxAug 1, 2008

  • The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fi

    CriticalCVSS 10.0No exploitEPSS 4%

    edimax · br-6104k router firmwareNov 22, 2011

  • The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomca

    CriticalCVSS 10.0No exploitEPSS 3%

    cisco · unified customer voice portalMay 9, 2013

  • The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x

    CriticalCVSS 10.0No exploitEPSS 3%

    dojotoolkit · dojoJun 15, 2010

  • The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console

    CriticalCVSS 10.0No exploitEPSS 3%

    vmware · aceMar 19, 2008

  • Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what

    CriticalCVSS 10.0No exploitEPSS 3%

    apple · mac os xOct 10, 2008

  • ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.

    CriticalCVSS 10.0No exploitEPSS 2%

    replicom · proxyviewDec 31, 2003

  • The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I

    CriticalCVSS 10.0No exploitEPSS 2%

    3com · 3crwe554g72tOct 12, 2007

  • The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote at

    CriticalCVSS 10.0No exploitEPSS 2%

    yasinkaplan · tekradiusJul 7, 2009

  • The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, po

    CriticalCVSS 10.0No exploitEPSS 2%

    opera · opera browserDec 21, 2010

  • Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b

    CriticalCVSS 10.0No exploitEPSS 2%

    cisco · ace 4710Feb 26, 2009

  • The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impac

    CriticalCVSS 10.0No exploitEPSS 2%

    ibm · db2Jun 3, 2009

  • sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onl

    CriticalCVSS 9.3Proof of conceptEPSS 9%

    freebsd · freebsdFeb 20, 2009

All vulnerability classes