Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect c
IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Editio
Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote a
The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-depen
The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properl
NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language l
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC)
M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_ver
plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does n
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functio
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cau
Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote au
vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.
ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows r
VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows r
Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules,
front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a fi
Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remot
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows rem
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows rem
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote att
Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allow
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allow
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration fi
Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitra
k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a l
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently
hyBook Guestbook Script stores sensitive information under the web root with insufficient access control, which allows r
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files
Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 might allow re
Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to byp
Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cooki
MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which all
PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allo
PreProjects Pre Courier and Cargo Business stores dbcourior.mdb under the web root with insufficient access control, whi
PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-C
Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products,
Scan for 2009 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started