| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The Windows NT guest account is enabled. |
| An SSH server allows authentication through the .rhosts file. |
| A router's routing tables can be obtained from arbitrary hosts. |
| HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests. |
| The registry in Windows NT can be accessed remotely by users who are not administrators. |
| Windows NT automatically logs in an administrator upon rebooting. |
| NFS exports system-critical data to the world, e.g. / or a password file. |
| A Unix account with a name other than "root" has UID 0, i.e. root privileges. |
| Two or more Unix accounts have the same UID. |
| A system-critical Unix file or directory has inappropriate permissions. |
| A system-critical Windows NT file or directory has inappropriate permissions. |
| IIS has the #exec function enabled for Server Side Include (SSI) files. |
| An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities. |
| .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. |
| A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. |
| A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories. |
| A Sendmail alias allows input to be piped to a program. |
| rpc.admind in Solaris is not running in a secure mode. |
| A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. |
| Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. |