GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to caus
Flash Messaging clients can ignore disconnecting commands such as "shutdown" from the Flash Messaging Server 5.2.0g (rev
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid poi
Info Touch Surfnet kiosk allows local users to access the underlying filesystem via a 'file://' URI.
Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbit
TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlin
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers t
Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-
Application Access Server (A-A-S) 1.0.37 and earlier allows remote authenticated users to cause a denial of service (app
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic)
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to ac
F-Secure Anti-Virus 5.41 and 5.42 on Windows, Client Security 5.50 and 5.52, 4.60 for Samba Servers, and 4.52 and earlie
Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multipl
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator pass
The /.inlook/.crypt file for inlook 0.7.3 and earlier is installed with world readable permissions, which allows local u
Memory leak in Microsoft Windows XP and Windows Server 2003 allows local users to cause a denial of service (memory exha
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of fa
Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local user
WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local us
Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of ser
Novell NetWare 6.5 SP 1.1, when installing or upgrading using the Overlay CDs and performing a custom installation with
Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on
Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndA
Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (
aMSN 0.90 for Microsoft Windows allows local users to obtain sensitive information such as hashed passwords from (1) hot
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table
DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
Admin Console in Secure Computing Corporation Sidewinder G2 6.1.0.01 exports private keys when exporting firewall certif
Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) t
ipmenu 0.0.3 before Debian GNU/Linux ipmenu_0.0.3-5 allows local users to overwrite arbitrary files via a symlink attack
The data-overwrite capability of ButtUglySoftware CleanCache 2.19 does not properly overwrite data in files, which allow
Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a den
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Ge
A numeric casting discrepancy in sdla_xfer in Linux kernel 2.6.x up to 2.6.5 and 2.4 up to 2.4.29-rc1 allows local users
The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive inf
resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login t
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arb
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files o
Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords.
NessusWX 1.4.4 stores account passwords in plaintext in .session files, which allows local users to obtain passwords.
Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0
Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local u
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, w
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain p
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started