Latest CVE Feed
-
4.6
MEDIUMCVE-2006-5557
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details... Read more
Affected Products : hp-ux- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5559
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the ... Read more
- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5567
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.... Read more
Affected Products : winamp- Published: Oct. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5545
Premium Antispam in Symantec Mail Security for Domino Server 5.1.x before 5.1.2.28 does not filter certain SMTP address formats, which allows remote attackers to use the product as a spam relay.... Read more
Affected Products : mail_security- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5540
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimiza... Read more
Affected Products : postgresql- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5551
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command.... Read more
Affected Products : qk_smtp- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5530
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE... Read more
Affected Products : simpnews- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5548
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][directories][classes] parameter... Read more
Affected Products : otscms- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5527
PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the sys_path parameter.... Read more
Affected Products : intelieditor- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5528
Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : schoolalumni_portal- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5554
Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter in albumview.php to upload a text/... Read more
Affected Products : imageview- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5534
Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: so... Read more
Affected Products : online_shop- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5538
D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to list contents of the cgi-bin directory via unspecified vectors, probably a direct request.... Read more
Affected Products : dsl-g624t- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5531
PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.... Read more
Affected Products : ascended_guestbook- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5529
Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of th... Read more
Affected Products : schoolalumni_portal- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5547
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][includes] ... Read more
Affected Products : otscms- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5526
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b)... Read more
Affected Products : fully_modded_phpbb- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5539
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter.... Read more
Affected Products : ueberproject_management_system- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5535
Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to script... Read more
Affected Products : cpanel- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5541
backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via a coercion of an unknown element to ANYARRAY.... Read more
Affected Products : postgresql- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025