prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid lang
sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe,
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by
FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that gen
ArGoSoft FTP Server 1.2.2.2 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) f
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension,
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received from non-delegated name se
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conv
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data t
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV"
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers
Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify
Autogalaxy stores usernames and passwords in cleartext in cookies, which makes it easier for remote attackers to obtain
The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and pa
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attacker
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allo
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started