Searching null software vulnerabilities


A Unix account has a default, null, blank, or m


A Unix account has a default, null, blank, or missing password.


A Windows NT local user or administrator accoun


A Windows NT local user or administrator account has a default, null, blank, or missing password.


A Windows NT domain user or administrator accou


A Windows NT domain user or administrator account has a default, null, blank, or missing password.


An account on a router, firewall, or other netw


An account on a router, firewall, or other network device has a default, null, blank, or missing password.


An SNMP community name is the default (e.g. pub


An SNMP community name is the default (e.g. public), null, or missing.


dcshop.cgi in DCShop 1.002 Beta allows remote a


dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.


The Java Server Pages (JSP) engine in Tomcat al


The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).


The Java Server Pages (JSP) engine in JRun allo


The Java Server Pages (JSP) engine in JRun allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).


Solaris 2.5.1 through 9 allows local users to c


Solaris 2.5.1 through 9 allows local users to cause a denial of service (kernel panic) by setting the sd_struiowrq variable in the struioget function to null, which triggers a null dereference.


Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local u

Java | Sun |

Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception.


Midnight commander (mc) 4.5.55 and earlier allo


Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.


Mozilla allows remote attackers to cause a deni


Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.


profile.php in PunBB 1.2.1 allows remote attack


profile.php in PunBB 1.2.1 allows remote attackers to cause a denial of service (account lockout) by setting the user's password to NULL.


Carsten's 3D Engine (Ca3DE), March 2004 version


Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via text strings that are not null terminated, which triggers a null dereference.


XAMPP 1.4.x has multiple default or null passwo


XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.


oftpd 0.3.7 allows remote attackers to cause a


oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.


libungif library before 4.1.0 allows attackers


libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.


MySQL 5.0.18 and earlier allows local users to


MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.


NCH Swift Sound Web Dictate 1.02 allows remote


NCH Swift Sound Web Dictate 1.02 allows remote attackers to bypass authentication via a null password.


index.php in SoftBB 0.1, and possibly earlier,


index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter.


Software vulnerabilities results 1 to 20 of 423     
Page: 12345...22