profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without prov
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arb
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbi
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitra
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1
Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the
Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote a
Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands
Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP co
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arb
Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct
file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to by
Multiple PHP remote file inclusion vulnerabilities in Guestbook Script 1.9 allow remote attackers to execute arbitrary P
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
PHP remote file inclusion vulnerability in lib/classes/offl_nflteam.php in Online Fantasy Football League (OFFL) 0.2.6 a
PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to exe
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-2
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to b
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allow
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allo
Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows r
Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with
OpenBase 10.0.5 and earlier allows remote authenticated users to trigger a free of an arbitrary memory location via long
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspe
The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to ex
IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak per
The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port w
Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execut
oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV comma
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and applicati
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote att
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (sta
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote att
Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malf
JWIG might allow context-dependent attackers to cause a denial of service (service degradation) via loops of references
The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attacke
Multiple off-by-one errors in fsplib.c in fsplib before 0.8 allow attackers to cause a denial of service via unspecified
Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to
The IAX2 channel driver (chan_iax2) in Asterisk Open 1.2.x before 1.2.23, 1.4.x before 1.4.9, and Asterisk Appliance Dev
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transm
The login_to_simulator method in Linden Lab Second Life, as used by the secondlife:// protocol handler and possibly othe
Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credenti
The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, whic
Microsoft Internet Explorer 6.0.2900 SP2 and earlier allows remote attackers to cause a denial of service (crash) via a
Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on
Scan for 2007 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started