Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running o
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code vi
3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying th
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requ
HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct r
NetDSL ADSL Modem 800 with Microsoft Network firmware 5.5.11 allows remote attackers to gain access to configuration men
Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbit
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files
Sendmail 8.12.0 through 8.12.6 truncates log messages longer than 100 characters, which allows remote attackers to preve
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary director
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable tempor
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.a
setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does no
OSSP mm library (libmm) before 1.2.0 allows the local Apache user to gain privileges via temporary files, possibly via a
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite ar
The installation of OpenOffice 1.0.1 allows local users to overwrite files and possibly gain privileges via a symlink at
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privile
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaSc
W3Mail 1.0.2 through 1.0.5 with server side scripting (SSI) enabled in the attachments directory does not properly restr
The NBActiveX.ocx ActiveX control in NeoBook 4 allows remote attackers to install and execute arbitrary programs.
The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers
An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS),
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk wh
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows loca
dump 0.4 b10 through b29 allows local users to cause a denial of service (execution prevention) by using flock() to lock
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by us
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores
Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Securi
RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.
Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3,
The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, wh
Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other por
Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients b
Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security se
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privil
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as oth
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attachi
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creatin
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while mod
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arb
isakmpd/message.c in isakmpd in FreeBSD before isakmpd-20020403_1, and in OpenBSD 3.1, allows remote attackers to cause
Scan for 2002 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started