Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arb
Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifie
Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailin
Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.
SQL injection vulnerability in bb_memberlist.php for phpBB 1.4.2 allows remote attackers to execute arbitrary SQL querie
Alcatel ADSL modems allow remote attackers to access the Trivial File Transfer Protocol (TFTP) to modify firmware and co
network_query.php in Network Query Tool 1.0 allows remote attackers to execute arbitrary commands via shell metacharacte
ProFTPD 1.2.2rc2, and possibly other versions, does not properly verify reverse-resolved hostnames by performing forward
webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell meta
Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as o
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string
Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitr
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and pa
SpeedXess HA-120 DSL router has a default administrative password of "speedxess", which allows remote attackers to gain
NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allo
Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remot
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, do
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources
Format string vulnerability in libvanessa_logger 0.0.1 in Perdition 0.1.8 allows remote attackers to execute arbitrary c
The MAC module in Netfilter in Linux kernel 2.4.1 through 2.4.11, when configured to filter based on MAC addresses, allo
Unknown vulnerability in CDE in Caldera OpenUnix 7.1.0, 7.1.1, and 8.0 allows an xterm session to gain privileges when t
The File Blocker feature in Clearswift MAILsweeper for SMTP 4.2 allows remote attackers to bypass e-mail attachment filt
CardBoard 2.4 greeting card CGI by Michael Barretto allows remote attackers to execute arbitrary commands via shell meta
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attacker
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell meta
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to g
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a lo
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via
Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when
Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.
Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.
Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administra
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Servic
procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl file
procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a ja
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could all
Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of serv
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental v
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started