tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other w
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JS
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify n
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are pro
WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin boar
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remo
IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split
Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies
ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control
Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (cr
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database f
The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote a
Apple Personal Web Sharing (PWS) 1.1, 1.5, and 1.5.5, when Web Sharing authentication is enabled, allows remote attacker
The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, w
Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to r
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoo
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict th
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict t
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly rest
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly rest
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restr
Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full
cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY,
Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a direc
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gai
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a l
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the searc
fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrit
GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.
Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/me
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to
The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory,
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a
Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier f
CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could al
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possi
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove softwa
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privil
Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow lo
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started