BSCW groupware system 3.3 through 4.0.2 beta allows remote attackers to read or modify arbitrary files by uploading and
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could
POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to appe
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existe
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Co
Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and rea
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, a
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an al
PHP 4.0.4pl1 and 4.0.5 in safe mode allows remote attackers to read and write files owned by the web server UID by uploa
The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote
Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must
Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directorie
CMG WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate author
Openwave WAP gateway does not verify the fully qualified domain name URL with X.509 certificates from root certificate a
Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arb
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privile
Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages.
Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, make
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produce
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink attack.
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir
Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack
initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to condu
Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denia
Format string vulnerability in auto nice daemon (AND) 1.0.4 and earlier allows a local user to possibly execute arbitrar
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwr
Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows
Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.
ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a Zon
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for
script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardl
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mo
Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call in
Multiple cross-site scripting (XSS) vulnerabilities in the log messages in certain Alpha versions of AOL Instant Messeng
Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applet
The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the use
Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosi
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web si
vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary
Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL)
Vulnerabilities in CGI scripts in susehelp in SuSE 7.2 and 7.3 allow remote attackers to execute arbitrary commands by n
Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does
A cross-site scripting vulnerability in Caucho Technology Resin before 1.2.4 allows a malicious webmaster to embed Javas
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a reques
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive informatio
Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started