Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6,
Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET re
Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a G
Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the
Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to e
Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary fil
Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of cer
Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a la
The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS per
Entrust Authority Security Manager (EASM) 6.0 does not properly require multiple master users to change the password of
The secldapclntd daemon in AIX 4.3, 5.1 and 5.2 uses an Internet socket when communicating with the loadmodule, which al
SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWAT
Nokia Gateway GPRS support node (GGSN) allows remote attackers to cause a denial of service (kernel panic) via a malform
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by settin
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1)
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an
Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click acti
Unknown vulnerability in minimalist mailing list manager 2.4, 2.2, and possibly other versions, allows remote attackers
xsok 1.02 does not properly drop privileges before finding and executing the "gunzip" program, which allows local users
The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Interne
jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attac
vbox3 0.1.8 and earlier does not properly drop privileges before executing a user-provided TCL script, which allows loca
The calendar module for phpgroupware 0.9.14 does not enforce the "save extension" feature for holiday files, which allow
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote
jitterbug 1.6.2 does not properly sanitize inputs, which allows remote authenticated users to execute arbitrary commands
The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, whic
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (
Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is
Buffer overflow in the ARTpost function in art.c in the control message handling code for INN 2.4.0 may allow remote att
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script o
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response
Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the us
Cross-site scripting (XSS) vulnerability in search.php in JShop E-Commerce Server allows remote attackers to inject arbi
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via
Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service
Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user.
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss o
Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to
Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single
eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started