ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementatio
The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, w
The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number g
CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of
The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allow
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow
The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent us
The Data Access component in Apple iOS before 5 does not properly handle the existence of multiple user accounts on the
The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, w
The Home screen component in Apple iOS before 5 does not properly support a certain application-switching gesture, which
Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via
Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows remote authenticated users to affect availability,
Unspecified vulnerability in the Oracle Communications Unified component in Oracle Sun Products Suite 7.0 allows local u
Unspecified vulnerability in SysFW 8.0 on certain SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade based servers allows
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to DTrace Software Lib
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, whi
The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure
Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows l
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.0 allows local u
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not
The Radeon GPU drivers in the Linux kernel before 2.6.38-rc5 do not properly validate data related to the AA resolve reg
crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files
crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-lin
The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x b
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text typ
Race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, create
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.2.0 and 8.3.5.0
The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which a
IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTS
Tembria Server Monitor before 6.0.5 Build 2252 uses a substitution cipher to encrypt application credentials, which allo
NetSaro Enterprise Messenger Server 2.0 stores cleartext console credentials in configuration.xml, which allows local us
NetSaro Enterprise Messenger Server 2.0 allows local users to discover cleartext server credentials by reading the NetSa
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allo
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality via unknown vectors re
Unspecified vulnerability in the Applications Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009),
Unspecified vulnerability in the Oracle Universal Installer component in Oracle Database Server 10.1.0.5 allows local us
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality via unknown vectors related
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to ZFS, a different vu
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, related to ZFS.
Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vect
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow
Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for s
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.0, 10.0.2.0, 10.3.3.
Scan for 2011 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started