Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messa
OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows
Distributed Checksum Clearinghouse (DCC) 1.3.65 allows remote attackers to cause a denial of service (crash) via a "SOCK
Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot do
The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect audit entries in th
StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain so
Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involvi
xscreensaver 5.03 and earlier, when running without xscreensaver-gl-extras (GL extras) installed, crashes when /usr/bin/
Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the exist
Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00
The safe_path function in shttp before 0.0.5 allows remote attackers to conduct directory traversal attacks and read fil
Double free vulnerability in the ftpprchild function in ftppr in 3proxy 0.5 through 0.5.3i allows remote attackers to ca
Massive Entertainment World in Conflict 1.001 and earlier allows remote attackers to cause a denial of service (failed a
SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request
Heap-based buffer overflow in the samp_send function in nuauth/sasl.c in NuFW before 2.2.7 allows remote attackers to ca
Directory traversal vulnerability in downloadfile.php in eLouai's Force Download of media files script, as available on
eFileMan 7.1.0.87-88 stores sensitive information under the web root with insufficient access control, which allows remo
Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard a
The Globe7 soft phone client 7.3 sends username and password information in cleartext, which allows remote attackers to
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to re
Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control,
Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (
Micro Login System 1.0 stores sensitive information under the web root with insufficient access control, which allows re
The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 p
Unspecified vulnerability in the Groupmax Collaboration - Schedule component in Hitachi Groupmax Collaboration Portal 07
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client
Directory traversal vulnerability in PageTraiteDownload.php in phpMyConferences 8.0.2 and earlier allows remote attacker
Directory traversal vulnerability in modules/Builder/DownloadModule.php in ModuleBuilder 1.0 allows remote attackers to
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary
dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to obtain sensitive author credentials by maki
Directory traversal vulnerability in fileSystem.do in SSL-Explorer before 0.2.14 allows remote attackers to access arbit
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or
Perl-Compatible Regular Expression (PCRE) library before 7.3 reads past the end of the string when searching for unmatch
Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \p sequence,
HTTPSocket.cpp in the C++ Sockets Library before 2.2.5 allows remote attackers to cause a denial of service (crash) via
MyWebFTP, possibly 5.3.2, stores sensitive information under the web root with insufficient access control, which allows
The modules/mdop.m in the Cypress 1.0k script for BitchX, as downloaded from a distribution site in November 2007, conta
The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges
The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections)
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6
Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced sear
USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors.
Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive inform
The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a ho
KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie param
The Belkin F5D7230-4 Wireless G Router allows remote attackers to cause a denial of service (degraded networking and log
frame.html in Aida-Web (Aida Web) allows remote attackers to bypass a protection mechanism and obtain comment and task d
Javamail does not properly handle a series of invalid login attempts in which the same e-mail address is entered as user
Scan for 2007 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started