DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attem
The LDAP name service (nsd) in IRIX 6.5.19 and earlier does not properly verify if the USERPASSWORD attribute has been p
Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service a
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote at
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly exe
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to by
cci_dir in IBM U2 UniVerse 10.0.0.9 and earlier creates hard links and unlinks files as root, which allows local users t
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which mak
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source code via a request that
Off-by-one error in certain versions of xfstt allows remote attackers to read potentially sensitive memory via a malform
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain chara
mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log,
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-depende
faxrunqd.in in mgetty 1.1.28 and earlier allows local users to overwrite files via a symlink attack on JOB files.
Multiple buffer overflows in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allow remote attackers to execute arbitrary code v
OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads t
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to exe
Buffer overflow in traceroute-nanog (aka traceroute-ng) may allow local users to execute arbitrary code via a long hostn
The spray mode in traceroute-nanog (aka traceroute-ng) may allow local users to overwrite arbitrary memory locations via
Cross-site scripting (XSS) vulnerability in MHonArc before 2.5.14 allows remote attackers to inject arbitrary HTML into
Buffer overflow in typespeed 0.4.2 and earlier allows local users to gain privileges via long input.
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users
The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via
The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via
The Telnet service for Polycom ViewStation before 7.2.4 allows remote attackers to cause a denial of service (crash) via
gsinterf.c in bmv 1.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary file
The daemon for GeneWeb before 4.09 does not properly handle requested paths, which allows remote attackers to read arbit
Buffer overflow in cnd-program for mgetty before 1.1.29 allows remote attackers to cause a denial of service and possibl
faxspool in mgetty before 1.1.29 uses a world-writable spool directory for outgoing faxes, which allows local users to m
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a she
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to
Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obta
Heap-based buffer overflow in the wordwrap function in PHP after 4.1.2 and before 4.3.0 may allow attackers to cause a d
Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of servic
Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibl
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versi
Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary co
Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for Pos
Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local
dhcpcd DHCP client daemon 1.3.22 and earlier allows local users to execute arbitrary code via shell metacharacters that
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not i
Multiple SQL injection vulnerabilities in IMP 2.2.8 and earlier allow remote attackers to perform unauthorized database
Multiple stack-based buffer overflows in the error handling routines of the minires library, as used in the NSUPDATE cap
Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash).
Scan for 2003 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started