M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialba
psyced before 20120821 does not verify that a request was made for an XMPP Server Dialback response, which allows remote
Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMP
Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EG
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attacke
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random nu
The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 a
Open redirect vulnerability in index.php in ocPortal before 7.1.6 allows remote attackers to redirect users to arbitrary
IBM Tivoli Federated Identity Manager (TFIM) and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1, 6.2.
Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x befo
Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows re
tiki-featured_link.php in TikiWiki CMS/Groupware 8.3 allows remote attackers to load arbitrary web site pages into frame
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assert
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Up
(1) services/twitter/twitter-contact-view.c and (2) services/twitter/twitter-item-view.c in libsocialweb before 0.25.20
services/flickr/flickr.c in libsocialweb before 0.25.21 automatically connects to Flickr when no Flickr account is set,
librdmacm 1.0.16, when ibacm.port is not specified, connects to port 6125, which allows remote attackers to specify the
Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.
The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access module
Open redirect vulnerability in Pebble before 2.6.4 allows remote attackers to redirect users to arbitrary web sites and
The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN)
Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's
Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, d
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the
Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Comm
The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF befor
The PayPal merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN)
The PayPal IPN utility does not verify that the server hostname matches a domain name in the subject's Common Name (CN)
PayPal Payments Standard PHP Library before 20120427 does not verify that the server hostname matches a domain name in t
PayPal Payments Standard PHP Library 20120427 does not verify that the server hostname matches a domain name in the subj
PayPal Invoicing does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or sub
The Sage Pay Direct module in osCommerce does not verify that the server hostname matches a domain name in the subject's
The Authorize.Net module in osCommerce does not verify that the server hostname matches a domain name in the subject's C
The MoneyBookers module in osCommerce does not verify that the server hostname matches a domain name in the subject's Co
The PayPal Express module in osCommerce does not verify that the server hostname matches a domain name in the subject's
The PayPal Pro module in osCommerce does not verify that the server hostname matches a domain name in the subject's Comm
The PayPal Pro PayFlow module in osCommerce does not verify that the server hostname matches a domain name in the subjec
The PayPal Pro PayFlow EC module in osCommerce does not verify that the server hostname matches a domain name in the sub
The Canada Post (aka CanadaPost) module in PrestaShop does not verify that the server hostname matches a domain name in
The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Nam
The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common N
The PayPal module in Ubercart does not verify that the server hostname matches a domain name in the subject's Common Nam
The Authorize.Net module in Ubercart does not verify that the server hostname matches a domain name in the subject's Com
The CyberSource module in Ubercart does not verify that the server hostname matches a domain name in the subject's Commo
The PayPal IPN functionality in Zen Cart does not verify that the server hostname matches a domain name in the subject's
The PayPal Payments Pro module in Zen Cart does not verify that the server hostname matches a domain name in the subject
Scan for 2012 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started