CWE-16 · 317 records
Configuration
CVEs in this class
317 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2004-2687Weaponized | distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute aapple · xcode · CWE-16 | Critical9.3 | — | 88.2% | Dec 31, 2004 |
54Plan | CVE-2006-3677Weaponized | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain propertimozilla · firefox · CWE-16 | High7.5 | — | 78.7% | Jul 27, 2006 |
54Plan | CVE-2024-46909No exploit | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-16 | Critical9.8 | — | 48.9% | Dec 2, 2024 |
50Plan | CVE-2017-6639No exploit | A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unautcisco · prime data center network manager · CWE-16 | Critical9.8 | — | 35.4% | Jun 8, 2017 |
49Plan | CVE-2007-2216Proof of concept | The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,microsoft · internet explorer · CWE-16 | Critical9.3 | — | 41.4% | Aug 14, 2007 |
46Plan | CVE-2009-2335Weaponized | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, wordpress · wordpress · CWE-16 | Medium5.0 | — | 85.0% | Jul 10, 2009 |
43Plan | CVE-2005-4837No exploit | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allownet-snmp · net-snmp · CWE-16 | Critical10.0 | — | 9.7% | Dec 31, 2005 |
43Plan | CVE-2013-4316No exploit | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.apache · struts · CWE-16 | Critical10.0 | — | 8.4% | Sep 30, 2013 |
42Plan | CVE-1999-0886Proof of concept | The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.microsoft · windows nt · CWE-16 | Critical9.0 | — | 21.6% | Sep 17, 1999 |
42Plan | CVE-2009-3956No exploit | The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhancadobe · acrobat · CWE-16 | Critical10.0 | — | 7.7% | Jan 13, 2010 |
42Plan | CVE-2007-4074No exploit | The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, andcentre for speech technology research · gentoo linux · CWE-16 | Critical10.0 | — | 5.4% | Jul 30, 2007 |
41Plan | CVE-2007-3898Proof of concept | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS smicrosoft · windows 2000 · CWE-16 | Medium6.4 | — | 52.3% | Nov 13, 2007 |
41Plan | CVE-2008-1662No exploit | Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allohp · hp-ux · CWE-16 | Critical10.0 | — | 4.4% | Aug 1, 2008 |
41Plan | CVE-2011-4501No exploit | The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fiedimax · br-6104k router firmware · CWE-16 | Critical10.0 | — | 4.2% | Nov 22, 2011 |
41Plan | CVE-2013-1221No exploit | The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcacisco · unified customer voice portal · CWE-16 | Critical10.0 | — | 3.4% | May 9, 2013 |
41Plan | CVE-2010-2276No exploit | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.xdojotoolkit · dojo · CWE-16 | Critical10.0 | — | 3.2% | Jun 15, 2010 |
41Plan | CVE-2008-1392No exploit | The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the consolevmware · ace · CWE-16 | Critical10.0 | — | 2.7% | Mar 19, 2008 |
41Plan | CVE-2008-4212No exploit | Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite whatapple · mac os x · CWE-16 | Critical10.0 | — | 2.6% | Oct 10, 2008 |
41Plan | CVE-2003-1357No exploit | ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.replicom · proxyview · CWE-16 | Critical10.0 | — | 2.2% | Dec 31, 2003 |
41Plan | CVE-2007-5419No exploit | The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I3com · 3crwe554g72t · CWE-16 | Critical10.0 | — | 2.2% | Oct 12, 2007 |
41Plan | CVE-2009-2357No exploit | The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote atyasinkaplan · tekradius · CWE-16 | Critical10.0 | — | 2.1% | Jul 7, 2009 |
41Plan | CVE-2010-4586No exploit | The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, poopera · opera browser · CWE-16 | Critical10.0 | — | 2.1% | Dec 21, 2010 |
41Plan | CVE-2009-0621No exploit | Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (bcisco · ace 4710 · CWE-16 | Critical10.0 | — | 1.8% | Feb 26, 2009 |
41Plan | CVE-2008-6820No exploit | The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impacibm · db2 · CWE-16 | Critical10.0 | — | 1.8% | Jun 3, 2009 |
40Plan | CVE-2009-0641Proof of concept | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onlfreebsd · freebsd · CWE-16 | Critical9.3 | — | 9.3% | Feb 20, 2009 |
- CVE-2004-268763This week
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute a
CriticalCVSS 9.3WeaponizedEPSS 88%apple · xcodeDec 31, 2004
- CVE-2006-367754Plan
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti
HighCVSS 7.5WeaponizedEPSS 79%mozilla · firefoxJul 27, 2006
- CVE-2024-4690954Plan
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 49%progress · whatsup goldDec 2, 2024
- CVE-2017-663950Plan
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unaut
CriticalCVSS 9.8No exploitEPSS 35%cisco · prime data center network managerJun 8, 2017
- CVE-2007-221649Plan
The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,
CriticalCVSS 9.3Proof of conceptEPSS 41%microsoft · internet explorerAug 14, 2007
- CVE-2009-233546Plan
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,
MediumCVSS 5.0WeaponizedEPSS 85%wordpress · wordpressJul 10, 2009
- CVE-2005-483743Plan
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allow
CriticalCVSS 10.0No exploitEPSS 10%net-snmp · net-snmpDec 31, 2005
- CVE-2013-431643Plan
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 8%apache · strutsSep 30, 2013
- CVE-1999-088642Plan
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CriticalCVSS 9.0Proof of conceptEPSS 22%microsoft · windows ntSep 17, 1999
- CVE-2009-395642Plan
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanc
CriticalCVSS 10.0No exploitEPSS 8%adobe · acrobatJan 13, 2010
- CVE-2007-407442Plan
The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and
CriticalCVSS 10.0No exploitEPSS 5%centre for speech technology research · gentoo linuxJul 30, 2007
- CVE-2007-389841Plan
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS s
MediumCVSS 6.4Proof of conceptEPSS 52%microsoft · windows 2000Nov 13, 2007
- CVE-2008-166241Plan
Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allo
CriticalCVSS 10.0No exploitEPSS 4%hp · hp-uxAug 1, 2008
- CVE-2011-450141Plan
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fi
CriticalCVSS 10.0No exploitEPSS 4%edimax · br-6104k router firmwareNov 22, 2011
- CVE-2013-122141Plan
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomca
CriticalCVSS 10.0No exploitEPSS 3%cisco · unified customer voice portalMay 9, 2013
- CVE-2010-227641Plan
The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x
CriticalCVSS 10.0No exploitEPSS 3%dojotoolkit · dojoJun 15, 2010
- CVE-2008-139241Plan
The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console
CriticalCVSS 10.0No exploitEPSS 3%vmware · aceMar 19, 2008
- CVE-2008-421241Plan
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what
CriticalCVSS 10.0No exploitEPSS 3%apple · mac os xOct 10, 2008
- CVE-2003-135741Plan
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
CriticalCVSS 10.0No exploitEPSS 2%replicom · proxyviewDec 31, 2003
- CVE-2007-541941Plan
The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I
CriticalCVSS 10.0No exploitEPSS 2%3com · 3crwe554g72tOct 12, 2007
- CVE-2009-235741Plan
The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote at
CriticalCVSS 10.0No exploitEPSS 2%yasinkaplan · tekradiusJul 7, 2009
- CVE-2010-458641Plan
The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, po
CriticalCVSS 10.0No exploitEPSS 2%opera · opera browserDec 21, 2010
- CVE-2009-062141Plan
Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b
CriticalCVSS 10.0No exploitEPSS 2%cisco · ace 4710Feb 26, 2009
- CVE-2008-682041Plan
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impac
CriticalCVSS 10.0No exploitEPSS 2%ibm · db2Jun 3, 2009
- CVE-2009-064140Plan
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onl
CriticalCVSS 9.3Proof of conceptEPSS 9%freebsd · freebsdFeb 20, 2009