Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %
jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp ext
The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent"
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitr
Directory traversal vulnerability in index.php in iBoutique.MALL and possibly iBoutique allows remote attackers to read
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featur
Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive information under the web root with insufficient acc
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
index.php in GANTTy 1.0.3 allows remote attackers to obtain the full path of the web server via an invalid lang paramete
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form fie
The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obta
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME
Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via "..
Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php
Ingate Firewall in the SIP module before 4.4.1 and SIParator before 4.4.1, when TLS is enabled or when SSL/TLS is enable
Unspecified vulnerability in CGI-RESCUE FORM2MAIL 1.21 and earlier allows remote attackers to inject email headers, whic
Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attacker
Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php
A-CART 2.0 stores the acart2_0.mdb file under the web document root with insufficient access control, which allows remot
Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct r
Directory traversal vulnerability in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to read a
videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain sensitive information via a certain id parameter,
Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daem
Mafia Moblog 0.6M1 and earlier allows remote attackers to obtain the installation path in an error message via a direct
The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow
MyScrapbook 3.1 allows remote attackers to obtain sensitive information via a direct request to files in the txt-db-api
Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of servic
Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allows remote attackers
Multiple unspecified vulnerabilities in IBM DB2 Universal Database (UDB) before 8.1 FixPak 12 allow remote attackers to
IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application
write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with mod_mime, allows remote attackers to bypass restriction
klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Worksta
parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of servi
PhpMyFactures 1.0, and possibly 1.2 and earlier, allows remote attackers to obtain the installation path via a direct re
users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parame
CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via
Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays
Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows remote attackers to cause a denial of service (crash)
The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a den
Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified m
CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly inv
CRLF injection vulnerability in CS-Forum before 0.82 allows remote attackers to inject arbitrary email headers via a new
Directory traversal vulnerability in extract_chmLib example program in CHM Lib (chmlib) before 0.38 allows remote attack
index.php in singapore 0.10.0 and earlier allows remote attackers to obtain the installation path via an invalid templat
Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL cont
Unspecified versions of Internet Explorer allow remote attackers to cause a denial of service (crash) via an IFRAME with
The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of
Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space,
Scan for 2006 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started