Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows r
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mail
PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php,
Linksys WRT54G router uses the same private key and certificate for every router, which allows remote attackers to sniff
browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not e
Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to u
Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Jav
Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote
Multiple "endianness errors" in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invali
libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header wit
Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in th
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to us
The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses
Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash
ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.
shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_
Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption)
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, wh
The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attacke
Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial
Unknown vulnerability in the (1) AgentX dissector, (2) PER dissector, (3) DOCSIS dissector, (4) SCTP graphs, (5) HTTP di
Unknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a denial of
Unknown vulnerability in the (1) SMPP dissector, (2) 802.3 dissector, (3) DHCP, (4) MEGACO dissector, or (5) H1 dissecto
Unknown vulnerability in the (1) GIOP dissector, (2) WBXML, or (3) CAMEL dissector in Ethereal 0.8.20 through 0.10.11 al
Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer o
Unknown vulnerability in the BER dissector in Ethereal 0.10.11 allows remote attackers to cause a denial of service (abo
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct reques
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrar
Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which
Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitr
PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitra
Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which r
vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops fro
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attack
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a f
Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files vi
EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directo
Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to d
FunkBoard 0.66CF, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct re
The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-be
xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrar
CaLogic 1.22, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct reques
Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device cr
Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cau
Mentor ADSL-FR4II router running firmware 2.00.0111 allows remote attackers to cause a denial of service (active TCP con
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local use
Parlano MindAlign 5.0 and later versions allows remote attackers to list valid users via unknown vectors, aka the "User
Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javasc
Scan for 2005 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started