Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging sel
Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by s
Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for
Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via ".." (
Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with th
code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.
upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method
violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 a
The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote
Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive
Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user crede
KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.
The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.
Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative p
The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which a
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.
Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a docume
Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.
HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a deni
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows
Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password.
The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to g
Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed inp
The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive info
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows loca
Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the "Desk
Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that i
gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uuc
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via l
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via l
Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.
The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain pri
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow loc
Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a tempo
Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) p
NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decryp
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path n
Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Re
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (c
Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat L
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows lo
Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with consol
OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user i
Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.
Scan for 2000 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started