Searching strnlen user software vulnerabilities


wu-ftpd FTP daemon allows any user and password


wu-ftpd FTP daemon allows any user and password combination.


finger .@host on some systems may print informa


finger .@host on some systems may print information on some user accounts.


HP Remote Watch allows a remote user to gain ro


HP Remote Watch allows a remote user to gain root access.


A Windows NT local user or administrator accoun


A Windows NT local user or administrator account has a guessable password.


A Windows NT domain user or administrator accou


A Windows NT domain user or administrator account has a guessable password.


A system does not present an appropriate legal


A system does not present an appropriate legal message or warning to a user who is accessing it.


Netscape Navigator uses weak encryption for sto


Netscape Navigator uses weak encryption for storing a user's Netscape mail password.


glFtpD includes a default glftpd user account w


glFtpD includes a default glftpd user account with a default password and a UID of 0.


NetZero 3.0 and earlier uses weak encryption fo


NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password.


EFTP 2.0.7.337 stores user passwords in plainte

EFTP |

EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.


One-Time Passwords In Everything (a.k.a OPIE) 2


One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.


Windows XP with fast user switching and account


Windows XP with fast user switching and account lockout enabled allows local users to deny user account access by setting the fast user switch to the same user (self) multiple times, which causes other accounts to be locked out.


user_profile.asp in PortalApp 2.2 allows local


user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.


tcpdump does not properly drop privileges to th


tcpdump does not properly drop privileges to the pcap user when starting up.


The key validation code in GnuPG before 1.2.2 d


The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.


CiscoWorks Common Management Foundation (CMF) 2


CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.


The strnlen_user function in Linux kernel befor


The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.


DeluxeBB 1.07 and earlier does not properly han


DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.


wp-admin/user-edit.php in WordPress before 2.0.


wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.


Mail in Apple iPhone 1.1.1 allows remote user-a


Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the user before dialing the number.


Software vulnerabilities results 1 to 20 of 1883     
Page: 12345...95