phpGroupWare before 0.9.16.002 transmits the (1) header admin and (2) setup passwords in plaintext via cookies, which al
Novell iChain 2.3 allows attackers to cause a denial of service via a URL with a "specific string."
Novell iChain 2.3 includes the build number in the VIA line of the proxy server's HTTP headers, which allows remote atta
Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remo
login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a
Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote a
Gaim before 0.82 allows remote servers to cause a denial of service (application crash) via a long HTTP Content-Length h
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (applica
Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows re
Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remo
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaust
Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rul
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped
SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insuffi
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the
The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to
TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.
Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files
Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cau
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (unca
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from t
The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cau
Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive i
Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) vi
John Lim ADOdb Library for PHP before 4.23 allows remote attackers to obtain sensitive information via direct requests t
Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_t
mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certai
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 1638
Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain att
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service
Gyach Enhanced (Gyach-E) before 1.0.0 stores passwords in plaintext, which allows attackers to obtain user passwords by
Buffer overflow in Gyach Enhanced (Gyach-E) before 1.0.0-SneakPeek-3 allows remote attackers to cause a denial of servic
HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which a
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cooki
Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a "s
Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary f
The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted E
Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by trigger
Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows local users to cause a denial of service (memory c
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04,
Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users wi
Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allo
Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which cou
Unknown "System Security Vulnerability" in Computer Associates (CA) Unicenter Remote Control (URC) 6.0 allows attackers
Unknown "potential system security vulnerability" in Computer Associates (CA) Unicenter Remote Control 5.0 through 5.2,
Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and con
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allow
Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started