The administration function in Cisco Secure Access Control Server (ACS) for Windows, 2.6.x and earlier and 3.x through 3
The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute a
ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows rem
PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a w
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled,
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi f
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV c
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascri
Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and cras
Block_render_url.class in PHPSlash 0.6.1 allows remote attackers with PHPSlash administrator privileges to read arbitrar
Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" chara
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arb
Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physi
ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of conne
Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary fil
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexi
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitra
Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possi
ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET request
gnujsp 1.0.0 and 1.0.1 allows remote attackers to list directories, read source code of certain scripts, and bypass acce
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling l
The Notify daemon for Symantec Enterprise Firewall (SEF) 6.5.x drops large alerts when SNMP is used as the transport, wh
Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.
Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which
SMTP proxy in Symantec Enterprise Firewall (SEF) 6.5.x includes the firewall's physical interface name and address in an
The Store Service in Microsoft Exchange 2000 allows remote attackers to cause a denial of service (CPU consumption) via
ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that
DNS dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (CPU consumption) via a malf
Vulnerability in GIOP dissector in Ethereal before 0.9.3 allows remote attackers to cause a denial of service (memory co
ColdFusion 5.0 and earlier on Windows systems allows remote attackers to determine the absolute pathname of .cfm or .dbm
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory,
WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in
WorkforceROI Xpede 4.1 allows remote attackers to read user timesheets by modifying the TSN ID parameter to the ts_app_p
Scan for 2002 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started