Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol
Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption
WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hija
Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoo
Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL t
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict th
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the len
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict t
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly rest
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly rest
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restr
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Se
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data d
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a lon
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell meta
crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is own
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or
Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call in
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option ena
PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to g
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a scr
Trend Micro InterScan VirusWall creates an "Intscan" share to the "InterScan" directory with permissions that grant Full
in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request
cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY,
Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a direc
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of th
Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows re
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gai
Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with
Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remot
Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and p
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/."
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a l
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a lo
Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via
Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
Scan for 2001 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started