publish_xp_docs.php in Gallery 1.3.2 allows remote attackers to execute arbitrary PHP code by modifying the GALLERY_BASE
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one s
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server a
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers
Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders v
cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long
Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0
Format string vulnerability in the error handling of IRC invite responses for Trillian 0.725 and 0.73 allows remote IRC
Buffer overflow in Trillian 0.73 allows remote IRC servers to execute arbitrary code via a long PING response.
SQL injection vulnerability in Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to execute arbitrary SQL q
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP
Buffer overflow in the IRC module of Trillian 0.725 and 0.73 allowing remote attackers to execute arbitrary code via a l
phpShare.php in phpShare before 0.6 beta 3 allows remote attackers to include and execute arbitrary PHP scripts from rem
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attac
Samba before 2.2.5 does not properly terminate the enum_csc_policy data structure, which may allow remote attackers to e
Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP f
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing w
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote a
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow f
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands
SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary S
Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' func
SQL injection vulnerability in mod_search/index.php in PortailPHP 0.99 allows remote attackers to execute arbitrary SQL
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows re
Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (c
Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to exec
SQL injection vulnerability in agentadmin.php in Immobilier allows remote attackers to execute arbitrary SQL commands vi
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code an
Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use sy
Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remo
The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a
Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and
SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via f
Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly
SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitra
Gordano Messaging Server (GMS) Mail 8 (a.k.a. NTMail) only filters email messages for the first recipient, which allows
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters
Buffer overflow in (1) grpck and (2) pwck, if installed setuid on a system as recommended in some AIX documentation, may
Buffer overflow in passwd for HP UX B.10.20 allows local users to execute arbitrary commands with root privileges via a
Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user t
sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow lo
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to g
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privi
Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a lo
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media instal
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (
Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long
Scan for 2002 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started