Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitial
Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service
Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a di
Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and o
Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow
Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows r
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a
A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll all
A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to caus
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial
The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Jav
Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript th
Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that call
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in th
The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087
libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dep
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (inclu
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME emai
Unspecified vulnerability in the condor_ schedd daemon in Condor before 7.0.5 allows attackers to cause a denial of serv
Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control,
ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, wh
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows re
strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT mess
Unspecified vulnerability in the tape engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve
Unspecified vulnerability in the database engine service in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCse
Unspecified vulnerability in asdbapi.dll in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.4 allows
Unspecified vulnerability in the iSupplier Portal component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remot
Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial
The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attacker
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demons
The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-su
Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote at
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a
The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows
Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q931.c in the Q.931 dissector in Wireshark
core/string_api.php in Mantis before 1.1.3 does not check the privileges of the viewer before composing a link with issu
Unspecified vulnerability in the SQLNLS_UNPADDEDCHARLEN function in the New Compiler (aka Starburst derived compiler) co
The SORT/LIST SERVICES component in IBM DB2 9.1 before FP6 and 9.5 before FP2 writes sensitive information to the trace
Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directori
Directory traversal vulnerability in index.php in FAR-PHP 1.00, when magic_quotes_gpc is disabled, allows remote attacke
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local fil
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote
Scan for 2008 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started