Latest CVE Feed
-
5.0
MEDIUMCVE-2006-5138
Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message.... Read more
Affected Products : ubb.threads- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-4391
Buffer overflow in Apple ImageIO on Apple Mac OS X 10.4 through 10.4.7 allows remote attackers to execute arbitrary code via a malformed JPEG2000 image.... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2006-4393
Unspecified vulnerability in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, when Fast User Switching is enabled, allows local users to gain access to Kerberos tickets of other users.... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-4394
A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors.... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-4395
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image that is not properly handled by a cert... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4390
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trust... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-4397
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access t... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-4399
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not ac... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-4387
Apple Mac OS X 10.4 through 10.4.7, when the administrator clears the "Allow user to administer this computer" checkbox in System Preferences for a user, does not remove the user's account from the appserveradm or appserverusr groups, which still allows t... Read more
Affected Products : mac_os_x- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-4392
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to mo... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5098
lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image.... Read more
Affected Products : dokuwiki- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5099
lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invokin... Read more
Affected Products : dokuwiki- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5094
PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893... Read more
Affected Products : phpbb_xs- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5095
PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before bei... Read more
Affected Products : myphotos- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5096
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid param... Read more
Affected Products : virtuemart_joomla_ecommerrce_edition_cms- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5097
PHP remote file inclusion vulnerability in index.php in net2ftp, possibly 0.1 through 0.62, allows remote attackers to execute arbitrary PHP code via a URL in the application_rootdir parameter. NOTE: this issue has been disputed by a third party researche... Read more
Affected Products : net2ftp- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5093
PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.... Read more
Affected Products : tagmin_control_center- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5089
PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. NOTE: the provenance of this information is unknown; the details are obtained fro... Read more
Affected Products : my-bic- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5087
Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) track.php or (2) connect.php.... Read more
Affected Products : evobb- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5091
Unspecified vulnerability in HP-UX B.11.11 and B.11.23 CIFS Server (Samba) allows local users to gain privileges or obtain "unauthorized access" via unspecified vectors.... Read more
Affected Products : hp-ux- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025