Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an
tinc 1.0pre3 and 1.0pre4 allows remote attackers to inject data into user sessions by sniffing and replaying packets.
Unknown vulnerability in the file system protection subsystem in HP Secure OS Software for Linux 1.0 allows additional u
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to
Buffer overflow in lpstat in SCO OpenServer 5.0 through 5.0.6a allows local users to execute arbitrary code as group bin
geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which
Allaire JRun 2.3.3, 3.0 and 3.1 running on IIS 4.0 and 5.0, iPlanet, Apache, JRun web server (JWS), and possibly other w
JRun 3.0 and 3.1 running on JRun Web Server (JWS) and IIS allows remote attackers to read arbitrary JavaServer Pages (JS
Unknown vulnerability in Allaire JRun 3.1 allows remote attackers to directly access the WEB-INF and META-INF directorie
Macromedia JRun 3.0 and 3.1 allows remote attackers to obtain duplicate active user session IDs and perform actions as o
ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does no
Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary
RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to
RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denia
RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then ca
Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal d
Cross-site scripting (XSS) vulnerability in user.php in PostNuke 0.64 allows remote attackers to inject arbitrary web sc
Cross-site scripting (XSS) vulnerability in im.php in IMessenger for PHP-Nuke allows remote attackers to inject arbitrar
Cross-site scripting (XSS) vulnerability in the DMOZGateway module for PHP-Nuke allows remote attackers to inject arbitr
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify n
Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote a
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtai
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are pro
Buffer overflow in rpc.yppasswdd (yppasswd server) in AIX allows attackers to gain unauthorized access via a long string
run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to exe
Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitr
WebX stores authentication information in the HTTP_REFERER variable, which is included in URL links within bulletin boar
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP add
Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session
SpeedXess HA-120 DSL router has a default administrative password of "speedxess", which allows remote attackers to gain
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remo
IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split
Buffer overflow in Unix-to-Unix Copy Protocol (UUCP) in BSDI BSD/OS 3.0 through 4.2 allows local users to execute arbitr
NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allo
Axis network camera 2120, 2110, 2100, 200+ and 200 contains a default administration password "pass", which allows remot
Directory traversal vulnerability in Macromedia JRun Web Server (JWS) 2.3.3, 3.0 and 3.1 allows remote attackers to read
Macromedia JRun 3.0 and 3.1 appends the jsessionid to URL requests (a.k.a. rewriting) when client browsers have cookies
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, do
ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP pack
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which al
Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restric
ssdpsrv.exe in Windows ME allows remote attackers to cause a denial of service by sending multiple newlines in a Simple
Buffer overflow in setiathome for SETI@home 3.03, if installed setuid, could allow local users to execute arbitrary code
IBM AIX 430 does not properly unlock IPPMTU_LOCK, which allows remote attackers to cause a denial of service (hang) via
pt_chmod in Solaris 8 does not call fdetach to reset terminal privileges when users log out of terminals, which allows l
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control
Buffer overflow in ftpd in IBM AIX 4.3 and 5.1 allows attackers to gain privileges.
Unknown vulnerability in IP defragmenter (frag2) in Snort before 1.8.3 allows attackers to cause a denial of service (cr
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started