Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
Directory traversal vulnerability in index.php in SolarPay allows remote attackers to read certain files via a .. (dot d
sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters,
P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attacker
Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and
Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution
Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed f
Mutt 1.5.13 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Mutt from vis
GNUMail 1.1.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents GNUMail fro
Iono allows remote attackers to obtain the full server path via certain requests to (1) templates/iono/admin/denied.tpl.
SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denia
include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to caus
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-
Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a ..
WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php,
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbit
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partia
The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to ca
The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which al
The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement s
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the fil
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using c
nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented pack
IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other s
product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with
Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arb
The LLTD Mapper in Microsoft Windows Vista does not verify that an IP address in a TLV type 0x07 field in a HELLO packet
The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships,
The LLTD Mapper in Microsoft Windows Vista does not properly gather responses to EMIT packets, which allows remote attac
Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to
The Teredo implementation in Microsoft Windows Vista uses the same nonce for communication with different UDP ports with
Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers t
Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) before 1.8a
The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attack
Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service
admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of
The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cau
w-agora 4.2.1 allows remote attackers to obtain sensitive information by via the (1) bn[] array parameter to index.php,
CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to ph
Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary lo
The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlie
Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which all
Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbi
w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1)
search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) va
Scan for 2007 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started