| FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23. CVE-2025-66039 · NVD, Metasploit exploit modules | vulnerability 1 exploit 2 | — | 9.8 | 2025-12-09 |
| Sangoma FreePBX Authentication Bypass Vulnerability CVE-2025-57819 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB | vulnerability 2 exploit 2 | — | 9.8 | 2025-08-28 |
| GNU InetUtils Argument Injection Vulnerability CVE-2026-24061 · CISA Known Exploited Vulnerabilities, NVD, Exploit-DB, Metasploit exploit modules | vulnerability 2 exploit 2 | — | 9.8 | 2026-01-21 |
| runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container process (from runc exec) to have a working directory in the host filesystem namespace, allowing for a container escape by giving access to the host filesystem ("attack 2"). The same attack could be used by a malicious image to allow a container process to gain access to the host filesystem through runc run ("attack 1"). Variants of attacks 1 and 2 could be also be used to overwrite semi-arbitrary host binaries, allowing for complete container escapes ("attack 3a" and "attack 3b"). runc 1.1.12 includes patches for this issue. CVE-2024-21626 · NVD, Metasploit exploit modules | vulnerability 1 exploit 1 | — | 8.6 | 2024-01-31 |
| RARLAB UnRAR Directory Traversal Vulnerability CVE-2022-30333 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules | vulnerability 2 exploit 2 | — | 7.5 | 2022-05-09 |
| Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability CVE-2022-41352 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules | vulnerability 2 exploit 1 | — | 9.8 | 2022-06-28 |
| Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability CVE-2022-27925 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules | vulnerability 2 exploit 1 | — | 7.2 | 2022-04-21 |
| VMware Server Side Request Forgery in vRealize Operations Manager API CVE-2021-21975 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules | vulnerability 2 exploit 1 | — | 7.5 | 2021-03-30 |
| Red Hat Libuser Race Condition Vulnerability CVE-2015-3246 · CISA Known Exploited Vulnerabilities, NVD, Metasploit exploit modules, Exploit-DB | vulnerability 2 exploit 3 | — | 7.4 | 2015-07-24 |
| Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. CVE-2000-0917 · NVD, Metasploit exploit modules, Exploit-DB | vulnerability 1 exploit 5 | — | — | 2000-09-25 |
| The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions. CVE-2006-2451 · NVD, Exploit-DB | vulnerability 1 exploit 5 | — | — | 2006-07-07 |
| Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE. CVE-2006-2656 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2006-05-26 |
| Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function. CVE-2000-0998 · NVD, Exploit-DB | vulnerability 1 exploit 2 | — | — | 2000-11-01 |
| Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "." CVE-2000-0920 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2000-12-19 |
| PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. CVE-2000-0967 · NVD, Exploit-DB | vulnerability 1 exploit 2 | — | — | 2000-10-12 |
| Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter. CVE-2000-0987 · NVD, Exploit-DB | vulnerability 1 exploit 2 | — | — | 2000-10-18 |
| Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option. CVE-2000-0949 · NVD, Exploit-DB | vulnerability 1 exploit 4 | — | — | 2000-09-28 |
| Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file. CVE-2000-0935 · NVD, Exploit-DB | vulnerability 1 exploit 2 | — | — | 2000-11-01 |
| Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords. CVE-2000-0936 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2000-11-01 |
| named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug." CVE-2000-0887 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2000-11-01 |
| Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated. CVE-2000-0973 · NVD, Exploit-DB | vulnerability 1 exploit 2 | — | — | 2000-10-13 |
| Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack. CVE-2000-0992 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2000-09-30 |
| Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header. CVE-2000-0909 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2000-09-23 |
| The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL. CVE-2000-1016 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 2000-09-21 |
| FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections. CVE-2000-0916 · NVD, Exploit-DB | vulnerability 1 exploit 1 | — | — | 1999-09-27 |