netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment vari
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors,
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SM
Directory traversal vulnerability in Microsoft cabarc allows remote attackers to overwrite files via "../" sequences in
4D WebSTAR 5.3.2 and earlier allows local users to read and modify arbitrary files via a symlink attack.
Certain "programming errors" in the msync system call for FreeBSD 5.2.1 and earlier, and 4.10 and earlier, do not proper
MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permission
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or deter
IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log f
Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and
Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators
Microsoft Internet Explorer 5.5 and 6.0 allocates memory based on the memory size written in the BMP file instead of the
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web sc
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff fil
The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allo
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters that begin a hostname in a
Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascr
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a ta
Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitra
Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows
Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web pa
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multi
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Sec
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for t
zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted mu
Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU
Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of
Mozilla before 1.6 does not display the entire URL in the status bar when a link contains %00, which could allow remote
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remot
Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spac
The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of ser
Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR
msxml3.dll in Internet Explorer 6.0.2600.0 allows remote attackers to cause a denial of service (crash) via a single & (
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being do
Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar to facilitate phishing attacks via Javasc
Race condition in the sysfs_read_file and sysfs_write_file functions in Linux kernel before 2.6.10 allows local users to
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (infinite loop and crash) via an IF
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been l
Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files vi
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP request
Scan for 2004 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started