vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' c
The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allow
The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global va
The process scheduler in the Linux kernel 2.6.16 gives preference to "interactive" processes that perform voluntary slee
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sa
The ULE process scheduler in the FreeBSD kernel gives preference to "interactive" processes that perform voluntary sleep
The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process
The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and perfo
The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel,
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.2.1 allow remote authenticated administrators to inje
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create
The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a
xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership o
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plainte
Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users,
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x86_64 platform allows local users t
The display driver allocattr functions in NetBSD 3.0 through 4.0_BETA2, and NetBSD-current before 20070728, allow local
HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Contr
EMC VMware Server before 1.0.4 Build 56528 writes passwords in cleartext to unspecified log files, which allows local us
Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT)
Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT)
The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux ker
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Ser
ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow l
Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to
Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sens
Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users
Liferea before 1.4.6 uses weak permissions (0644) for the feedlist.opml backup file, which allows local users to obtain
The Globe7 soft phone client 7.3 uses weak cryptography (reversed sequence of binary values) for the password, which mig
IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central A
iSCSI Enterprise Target (iscsitarget) 0.4.15 uses weak permissions for /etc/ietd.conf, which allows local users to obtai
WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF f
PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long str
buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) sc
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 al
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, doe
Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a
zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gai
Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often r
IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, al
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which
The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard content
The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argume
Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protecti
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of ser
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across m
The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allow
Scan for 2007 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started