9 results (0.006 seconds)

CVSS: 5.9EPSS: 0%CPEs: 6EXPL: 0

02 Feb 2011 — MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation. MyProxy v5.0 hasta v5.2, tal como se utiliza en Globus Toolkit v5.0.0 hasta v5.0.2, no comprueba correctamente (1) el nombre de host o (2) la identi... • http://grid.ncsa.illinois.edu/myproxy/security/myproxy-adv-2011-01.txt • CWE-20: Improper Input Validation •

CVSS: 9.8EPSS: 52%CPEs: 1EXPL: 1

28 Mar 2005 — Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated. • https://www.exploit-db.com/exploits/25303 •

CVSS: 9.8EPSS: 47%CPEs: 1EXPL: 0

28 Mar 2005 — Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands. • ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:01.telnet.asc •

CVSS: 9.8EPSS: 6%CPEs: 1EXPL: 2

23 Sep 1997 — Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution. • https://www.exploit-db.com/exploits/21050 •

CVSS: 9.8EPSS: 5%CPEs: 2EXPL: 1

15 Jul 1997 — The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file. • https://www.exploit-db.com/exploits/20423 •

CVSS: 10.0EPSS: 91%CPEs: 2EXPL: 0

20 Mar 1996 — phf CGI program allows remote command execution through shell metacharacters. • http://www.cert.org/advisories/CA-1996-06.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 10.0EPSS: 4%CPEs: 3EXPL: 2

17 Feb 1995 — Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access. • https://www.exploit-db.com/exploits/21050 •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

01 Feb 1995 — Buffer overflow in NCSA WebServer (version 1.5c) gives remote access. • https://www.cve.org/CVERecord?id=CVE-1999-0232 •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

10 Sep 1991 — The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files. • http://www.cert.org/advisories/CA-1991-15.html •