The log files in Apache web server contain information directly supplied by clients and does not filter or quote control
Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (cr
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database f
The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote a
Apple Personal Web Sharing (PWS) 1.1, 1.5, and 1.5.5, when Web Sharing authentication is enabled, allows remote attacker
The timed program (in.timed) in UnixWare 7 and OpenUnix 8.0.0 does not properly terminate certain strings with a null, w
Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to r
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoo
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict th
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict t
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly rest
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly rest
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restr
Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full
cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY,
Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a direc
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gai
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a l
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the searc
fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.
elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrit
GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.
Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/me
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to
The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory,
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a
Dallas Semiconductor iButton DS1991 returns predictable values when given an incorrect password, which makes it easier f
CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could al
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possi
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove softwa
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privil
Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.
Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow lo
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument t
pmake before 2.1.35 in Turbolinux 6.05 and earlier is installed with setuid root privileges, which could allow local use
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoi
Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm devi
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with inse
Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain pr
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
bctool in Jetico BestCrypt 0.7 and earlier trusts the user-supplied PATH to find and execute an fsck utility program, wh
Multiple buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allow local use
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name
Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain h
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started