htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for th
htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attacke
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.c
send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk
ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's I
Directory traversal vulnerability in imlist.php for Php Imglist allows remote attackers to read arbitrary code via a ..
article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of th
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary d
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obta
IBM UniVerse with UV/ODBC allows attackers to cause a denial of service (client crash or server CPU consumption) via a q
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .
Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail 1.0.36
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr pa
mIRC DCC server protocol allows remote attackers to gain sensitive information such as alternate IRC nicknames via a "10
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumpti
IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vul
Eudora 5.1 and earlier versions stores attachments in a directory with a fixed name, which could make it easier for atta
Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the we
Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathnam
MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between client
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file cont
The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attack
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the data
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) vi
Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG t
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp pag
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbi
Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.
Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, whi
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to deter
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to caus
ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-in
Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO
Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrar
phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt t
PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corru
Scan for 2002 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started