Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary comman
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the origi
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the searc
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII ch
Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters
DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a mal
Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protec
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when
fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrit
GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.
Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, wh
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allo
Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they
Recourse ManTrap 1.6 modifies the kernel so that ".." does not appear in the /proc listing, which allows attackers to de
Recourse ManTrap 1.6 generates an error when an attacker cd's to /proc/self/cwd and executes the pwd command, which allo
Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that
Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resu
Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/me
Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to
The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the
Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary comman
Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that co
Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that c
Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that
PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that cont
RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service vi
RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via
StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a l
Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community nam
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decryp
NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication pac
NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login reques
The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which a
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory,
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody gr
Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message t
Twig webmail system does not properly set the "vhosts" variable if it is not configured on the site, which allows remote
ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" comma
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitr
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH ser
Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a l
Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files
Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of servi
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the rema
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started