mntd_mount.c in mntd before 0.4.2 might allow local users to gain privileges via shell metacharacters in a remount optio
The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophst
BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functional
Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer
Buffer overflow in MyWeb 3.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary
The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manual
The file server in ActivePost Standard 3.1 and earlier allows remote authenticated users to obtain sensitive information
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary we
ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment con
The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers
Nortel Contivity VPN Client 2.1.7, 3.00, 3.01, 4.91, and 5.01, when opening a VPN tunnel, does not check the gateway cer
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server
Unknown vulnerability in Rippy the Aggregator before 0.10, when register_globals is enabled, has unknown attack vectors
Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary we
Cross-site scripting (XSS) vulnerability in Outblaze Email allows remote attackers to inject arbitrary web script or HTM
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SM
Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Vi
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (wh
The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows
Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote at
phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to My
Unspecified vulnerability in Sesamie 1.0 allows remote anonymous attackers to gain access to repositories of other users
The (1) bos.rte.serv_aid or (2) bos.rte.console filesets in IBM AIX 5.1 and 5.2 allow local users to overwrite arbitrary
An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows r
TinyWeb 1.9 allows remote attackers to read source code of scripts via "/./" in the URL.
The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound con
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" director
Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown
Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files
Unspecified vulnerability in Sun Fire 3800/4800/4810/6800, Sun Fire V1280, and Netra 1280 allows remote attackers to cau
Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of
Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in
Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "
Unspecified vulnerability in ASN.1 Compiler (asn1c) before 0.9.7 has unknown impact and attack vectors when processing "
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (unca
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from t
FreezeX 1.00.100.0666 allows local users with administrator privileges to cause a denial of service (FreezeX application
Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of char
Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by trigger
Multiple cross-site scripting (XSS) vulnerabilities in YaCy before 0.32 allow remote attackers to inject arbitrary web s
The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbo
Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors in
The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cau
rdesktop 1.3.1 with xscreensaver 4.14, and possibly other versions, when running on Fedora and possibly other platforms,
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashc
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, w
resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login t
Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started