Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
Direct static code injection vulnerability in the PCG simple application generation in phpCodeGenie before 3.0.2 allows
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensi
The remove method in a stateful Enterprise JavaBean (EJB) in BEA WebLogic Server and WebLogic Express version 8.1 throug
Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write c
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input typ
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null charact
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perfor
slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP r
Directory traversal vulnerability in the sanitize_path function in util.c for rsync 2.6.2 and earlier, when chroot is di
Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain informat
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary S
Linksys WAP55AG 1.07 allows remote attackers with access to an SNMP read only community string to gain access to read/wr
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote
HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to se
MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a
Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write
Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a d
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write ar
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by
Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execu
Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to c
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of t
Novell Internet Messaging System (NIMS) 2.6 and 3.0, and NetMail 3.1 and 3.5, is installed with a default NMAP authentic
The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, w
Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect direct
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote
Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote att
Multiple memory leaks in Samba before 3.0.6 allow attackers to cause a denial of service (memory consumption).
PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files an
The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound con
Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of
upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unsp
The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers
Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reus
Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (bu
Unknown vulnerability in the Veritas NetBackup Administrative Assistant interface for NetBackup BusinesServer 3.4, 3.4.1
The Ignition Project ignitionServer 0.1.2 through 0.1.2-R2 allows remote authenticated users with local IRC operator pri
Unspecified vulnerability in Window Maker 0.80.2 and earlier allows attackers to perform unknown actions via format stri
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) conn
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and databas
Cross-site scripting (XSS) vulnerability in Novell iChain 2.3 allows remote attackers to obtain login credentials via un
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of char
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the ser
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrar
Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrar
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started