CWE-16 · 317 kayıt
Configuration
Bu sınıftaki CVE’ler
317 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
63Bu hafta | CVE-2004-2687Silahlaştırılmış | distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute aapple · xcode · CWE-16 | Kritik9,3 | — | %88,2 | 31 Ara 2004 |
54Planlayın | CVE-2006-3677Silahlaştırılmış | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain propertimozilla · firefox · CWE-16 | Yüksek7,5 | — | %78,7 | 27 Tem 2006 |
54Planlayın | CVE-2024-46909İstismar yok | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-16 | Kritik9,8 | — | %48,9 | 2 Ara 2024 |
50Planlayın | CVE-2017-6639İstismar yok | A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unautcisco · prime data center network manager · CWE-16 | Kritik9,8 | — | %35,4 | 8 Haz 2017 |
49Planlayın | CVE-2007-2216Kavram kanıtı | The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,microsoft · internet explorer · CWE-16 | Kritik9,3 | — | %41,4 | 14 Ağu 2007 |
46Planlayın | CVE-2009-2335Silahlaştırılmış | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, wordpress · wordpress · CWE-16 | Orta5,0 | — | %85,0 | 10 Tem 2009 |
43Planlayın | CVE-2005-4837İstismar yok | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allownet-snmp · net-snmp · CWE-16 | Kritik10,0 | — | %9,7 | 31 Ara 2005 |
43Planlayın | CVE-2013-4316İstismar yok | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.apache · struts · CWE-16 | Kritik10,0 | — | %8,4 | 30 Eyl 2013 |
42Planlayın | CVE-1999-0886Kavram kanıtı | The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.microsoft · windows nt · CWE-16 | Kritik9,0 | — | %21,6 | 17 Eyl 1999 |
42Planlayın | CVE-2009-3956İstismar yok | The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhancadobe · acrobat · CWE-16 | Kritik10,0 | — | %7,7 | 13 Oca 2010 |
42Planlayın | CVE-2007-4074İstismar yok | The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, andcentre for speech technology research · gentoo linux · CWE-16 | Kritik10,0 | — | %5,4 | 30 Tem 2007 |
41Planlayın | CVE-2007-3898Kavram kanıtı | The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS smicrosoft · windows 2000 · CWE-16 | Orta6,4 | — | %52,3 | 13 Kas 2007 |
41Planlayın | CVE-2008-1662İstismar yok | Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allohp · hp-ux · CWE-16 | Kritik10,0 | — | %4,4 | 1 Ağu 2008 |
41Planlayın | CVE-2011-4501İstismar yok | The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fiedimax · br-6104k router firmware · CWE-16 | Kritik10,0 | — | %4,2 | 22 Kas 2011 |
41Planlayın | CVE-2013-1221İstismar yok | The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcacisco · unified customer voice portal · CWE-16 | Kritik10,0 | — | %3,4 | 9 May 2013 |
41Planlayın | CVE-2010-2276İstismar yok | The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.xdojotoolkit · dojo · CWE-16 | Kritik10,0 | — | %3,2 | 15 Haz 2010 |
41Planlayın | CVE-2008-1392İstismar yok | The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the consolevmware · ace · CWE-16 | Kritik10,0 | — | %2,7 | 19 Mar 2008 |
41Planlayın | CVE-2008-4212İstismar yok | Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite whatapple · mac os x · CWE-16 | Kritik10,0 | — | %2,6 | 10 Eki 2008 |
41Planlayın | CVE-2003-1357İstismar yok | ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.replicom · proxyview · CWE-16 | Kritik10,0 | — | %2,2 | 31 Ara 2003 |
41Planlayın | CVE-2007-5419İstismar yok | The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I3com · 3crwe554g72t · CWE-16 | Kritik10,0 | — | %2,2 | 12 Eki 2007 |
41Planlayın | CVE-2009-2357İstismar yok | The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote atyasinkaplan · tekradius · CWE-16 | Kritik10,0 | — | %2,1 | 7 Tem 2009 |
41Planlayın | CVE-2010-4586İstismar yok | The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, poopera · opera browser · CWE-16 | Kritik10,0 | — | %2,1 | 21 Ara 2010 |
41Planlayın | CVE-2009-0621İstismar yok | Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (bcisco · ace 4710 · CWE-16 | Kritik10,0 | — | %1,8 | 26 Şub 2009 |
41Planlayın | CVE-2008-6820İstismar yok | The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impacibm · db2 · CWE-16 | Kritik10,0 | — | %1,8 | 3 Haz 2009 |
40Planlayın | CVE-2009-0641Kavram kanıtı | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onlfreebsd · freebsd · CWE-16 | Kritik9,3 | — | %9,3 | 20 Şub 2009 |
- CVE-2004-268763Bu hafta
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute a
KritikCVSS 9,3SilahlaştırılmışEPSS %88apple · xcode31 Ara 2004
- CVE-2006-367754Planlayın
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti
YüksekCVSS 7,5SilahlaştırılmışEPSS %79mozilla · firefox27 Tem 2006
- CVE-2024-4690954Planlayın
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
KritikCVSS 9,8İstismar yokEPSS %49progress · whatsup gold2 Ara 2024
- CVE-2017-663950Planlayın
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unaut
KritikCVSS 9,8İstismar yokEPSS %35cisco · prime data center network manager8 Haz 2017
- CVE-2007-221649Planlayın
The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation,
KritikCVSS 9,3Kavram kanıtıEPSS %41microsoft · internet explorer14 Ağu 2007
- CVE-2009-233546Planlayın
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists,
OrtaCVSS 5,0SilahlaştırılmışEPSS %85wordpress · wordpress10 Tem 2009
- CVE-2005-483743Planlayın
snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allow
KritikCVSS 10,0İstismar yokEPSS %10net-snmp · net-snmp31 Ara 2005
- CVE-2013-431643Planlayın
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %8apache · struts30 Eyl 2013
- CVE-1999-088642Planlayın
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
KritikCVSS 9,0Kavram kanıtıEPSS %22microsoft · windows nt17 Eyl 1999
- CVE-2009-395642Planlayın
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanc
KritikCVSS 10,0İstismar yokEPSS %8adobe · acrobat13 Oca 2010
- CVE-2007-407442Planlayın
The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and
KritikCVSS 10,0İstismar yokEPSS %5centre for speech technology research · gentoo linux30 Tem 2007
- CVE-2007-389841Planlayın
The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS s
OrtaCVSS 6,4Kavram kanıtıEPSS %52microsoft · windows 200013 Kas 2007
- CVE-2008-166241Planlayın
Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allo
KritikCVSS 10,0İstismar yokEPSS %4hp · hp-ux1 Ağu 2008
- CVE-2011-450141Planlayın
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with fi
KritikCVSS 10,0İstismar yokEPSS %4edimax · br-6104k router firmware22 Kas 2011
- CVE-2013-122141Planlayın
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomca
KritikCVSS 10,0İstismar yokEPSS %3cisco · unified customer voice portal9 May 2013
- CVE-2010-227641Planlayın
The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x
KritikCVSS 10,0İstismar yokEPSS %3dojotoolkit · dojo15 Haz 2010
- CVE-2008-139241Planlayın
The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console
KritikCVSS 10,0İstismar yokEPSS %3vmware · ace19 Mar 2008
- CVE-2008-421241Planlayın
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what
KritikCVSS 10,0İstismar yokEPSS %3apple · mac os x10 Eki 2008
- CVE-2003-135741Planlayın
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
KritikCVSS 10,0İstismar yokEPSS %2replicom · proxyview31 Ara 2003
- CVE-2007-541941Planlayın
The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source I
KritikCVSS 10,0İstismar yokEPSS %23com · 3crwe554g72t12 Eki 2007
- CVE-2009-235741Planlayın
The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it easier for remote at
KritikCVSS 10,0İstismar yokEPSS %2yasinkaplan · tekradius7 Tem 2009
- CVE-2010-458641Planlayın
The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, po
KritikCVSS 10,0İstismar yokEPSS %2opera · opera browser21 Ara 2010
- CVE-2009-062141Planlayın
Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b
KritikCVSS 10,0İstismar yokEPSS %2cisco · ace 471026 Şub 2009
- CVE-2008-682041Planlayın
The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impac
KritikCVSS 10,0İstismar yokEPSS %2ibm · db23 Haz 2009
- CVE-2009-064140Planlayın
sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid onl
KritikCVSS 9,3Kavram kanıtıEPSS %9freebsd · freebsd20 Şub 2009