ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which all
swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via
Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot)
Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which
wMCam server 2.1.348 allows remote attackers to cause a denial of service (no new connections) via multiple malformed HT
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of
The Javascript engine in Opera 7.23 allows remote attackers to cause a denial of service (crash) by creating a new Array
Directory traversal vulnerability in VocalTec VGW4/8 Gateway 8.0 allows remote attackers to read protected files via ..
Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote atta
Buffer overflow in Chrome 1.2.0.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet
Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (c
Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file siz
HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly
Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to caus
Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (c
Memory leak in the back-bdb backend for OpenLDAP 2.1.12 and earlier allows remote attackers to cause a denial of service
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t
Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (ha
The ftp_syslog function in ftpd in SGI IRIX 6.5.20 "doesn't work with anonymous FTP," which has an unknown impact, possi
Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb
Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fau
The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST
ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to cause a denial of service (crash) by calling the SetSit
Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in th
McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to
The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalen
Multiple directory traversal vulnerabilities in Nuked-KlaN 1.4b and 1.5b allow remote attackers to read or include arbit
sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN respon
xine 1.x alpha, 1.x beta, and 1.0rc through 1.0rc3a, and xine-ui 0.9.21 to 0.9.23 allows remote attackers to overwrite a
phProfession 2.5 allows remote attackers to gain sensitive information via a direct HTTP request to upload.php, which re
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files
The WebLinks module in Php-Nuke 6.x through 7.3 allows remote attackers to obtain sensitive information via an invalid s
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files
The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to
Unknown vulnerability in APC PowerChute Business Edition 6.0 through 7.0.1 allows remote attackers to cause a denial of
CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the
fetchnews in leafnode 1.9.47 and earlier allows remote attackers to cause a denial of service (process hang) via an empt
sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly si
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
Sophos Anti-Virus 3.78 allows remote attackers to cause a denial of service (infinite loop) via a MIME header that is no
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by
Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP ad
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauth
The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd paramete
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
The webacc servlet in Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to read arbitrary .htt fi
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started