Latest CVE Feed
-
5.0
MEDIUMCVE-2006-5568
FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command.... Read more
Affected Products : ftpxq- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5565
CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2) file, (3) module, and (4) func parameters in (a) index.php; and the (5) file parameter in (b) modules.ph... Read more
Affected Products : md-pro- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5561
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.... Read more
Affected Products : discuz_gbk- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5558
Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details ... Read more
Affected Products : hp-ux- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-5556
Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.... Read more
Affected Products : hp-ux- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5564
Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third par... Read more
Affected Products : md-pro- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5562
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter.... Read more
Affected Products : sourceforge- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5560
Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE:... Read more
Affected Products : progsys- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-5557
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details... Read more
Affected Products : hp-ux- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5559
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the ... Read more
- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5567
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.... Read more
Affected Products : winamp- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5545
Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.... Read more
Affected Products : mail_security- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
6.4
MEDIUMCVE-2006-5544
Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which causes the address bar to omit some cha... Read more
- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-5553
Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with ... Read more
- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5537
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote attackers to inject arbitrary web script or HTML via the (1) upnp:settings/state or (2) upnp:settings/connection parame... Read more
Affected Products : dsl-g624t- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5540
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimiza... Read more
Affected Products : postgresql- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5533
Multiple PHP remote file inclusion vulnerabilities in AROUNDMe 0.6.9, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter in template/barnraiser_01/pol_view.t... Read more
Affected Products : aroundme- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5532
Cross-site scripting (XSS) vulnerability in rmgs/images.php in RMSOFT Gallery System 2.0 allows remote attackers to inject arbitrary web script or HTML via the kw parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : xoops_rmsoft_gallery_system- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5546
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3.0 through 1.4.1 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][classes] p... Read more
Affected Products : otscms- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5536
Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.... Read more
Affected Products : dsl-g624t- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025