Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers
The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allo
Unspecified versions of the Linux kernel allow local users to cause a denial of service (unrecoverable zombie process) v
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has
The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to
The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which
Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to wa
The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including env
Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) fun
The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with phy
The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persis
The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local u
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection s
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schem
The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers
Fujitsu FENCE-Pro before V5L01, and Systemwalker Desktop Encryption V12.0L10, V12.0L10A, V12.0L10B, V12.0L20 and V13.0.0
TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem u
Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a de
The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-depend
QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file per
The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp
The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of s
libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that ar
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4,
usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening A
usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (wor
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to cha
wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, al
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-B
The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory pag
vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' c
The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allow
The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global va
The process scheduler in the Linux kernel 2.6.16 gives preference to "interactive" processes that perform voluntary slee
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sa
The ULE process scheduler in the FreeBSD kernel gives preference to "interactive" processes that perform voluntary sleep
The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process
The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and perfo
The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel,
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inje
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership o
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plainte
Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users,
Scan for 2007 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started