Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite file
SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allo
IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local
inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on th
VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirec
Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a lo
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to c
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has
The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to
Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.
The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local us
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processe
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.
A remote attacker can read information from a Netscape user's cache via JavaScript.
Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of serv
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that int
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitiv
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows rem
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that
Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" ru
Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session
The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame secur
Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user cl
CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the fi
The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HT
A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, whic
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Med
NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sha
The recover program in Solstice Backup allows local users to restore sensitive files.
AIX techlibss allows local users to overwrite files via a symlink attack.
CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be r
surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users
The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporar
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of servi
snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers t
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which a
Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a m
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a lo
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with acces
BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.
The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.
Scan for 2000 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started