The Windows Internet Naming Service (WINS) in Windows NT Server 4.0 SP 6a, NT Terminal Server 4.0 SP 6, Windows 2000 Ser
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to o
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitr
The make_recovery command for the TFTP server in HP Ignite-UX before C.6.2.241 makes a copy of the password file in the
Microsoft Internet Explorer 6.0 SP2 allows remote attackers to spoof a legitimate URL in the status bar and conduct a ph
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for rem
Internet Explorer 5.01 through 6 allows remote attackers to spoof arbitrary web sites by injecting content from one wind
CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute
Internet Explorer 6 allows remote attackers to bypass the popup blocker via the document object model (DOM) methods in t
hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate an
Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a
Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attacke
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrar
TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execu
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unaut
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and b
PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arb
Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple fil
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, su
SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrar
The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which
Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth o
PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execut
ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it e
SQL injection vulnerability in the show_stats module in Arcade.php in IbProArcade allows remote attackers to execute arb
The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and
Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attacke
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1)
Multiple heap-based buffer overflows in the modpow function in PuTTY before 0.55 allow (1) remote attackers to execute a
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random
Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator
The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds
The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixati
Unknown vulnerability in the management station in HP StorageWorks Command View XP 1.8B and earlier allows remote attack
The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass a
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute ar
Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read
init.php in WebCalendar allows remote attackers to execute arbitrary local PHP scripts via the user_inc parameter.
WebCalendar allows remote attackers to gain privileges by modifying critical parameters to (1) view_entry.php or (2) upc
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute a
Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant mes
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands
Hired Team: Trial 2.0 and earlier and 2.200 does not limit how game players can kick other players off the server, inclu
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started