Latest CVE Feed
-
5.0
MEDIUMCVE-2006-5028
Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5034
Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.... Read more
Affected Products : vcap- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5039
Unspecified vulnerability in Events 1.3 beta module (com_events) for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5048
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php,... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5045
Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php.... Read more
Affected Products : com_pollxt- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5051
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5052
Unspecified vulnerability in portable OpenSSH before 4.4, when running on some platforms, allows remote attackers to determine the validity of usernames via unknown vectors involving a GSSAPI "authentication abort."... Read more
Affected Products : openssh- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5047
Unspecified vulnerability in rsgallery2.html.php in RS Gallery2 component (com_rsgallery2) before 1.11.3 for Joomla! allows attackers to execute arbitrary code.... Read more
Affected Products : rs_gallery2- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5017
SQL injection vulnerability in admin/all_users.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to execute arbitrary SQL commands via the from parameter.... Read more
Affected Products : e-vision_cms- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5036
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) att... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5026
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.3 have unknown impact and attack vectors.... Read more
Affected Products : simple_http_scanner- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5040
Unspecified vulnerability in SEF404x (com_sef) for Joomla! has unspecified impact and attack vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-4694
Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Wi... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5009
Unspecified vulnerability in xlock in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary commands and overwrite arbitrary files via unspecified vectors, possibly involving a buffer overflow.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
6.6
MEDIUMCVE-2006-5012
Unspecified vulnerability in Sun Solaris 8, 9, and 10 before 20060925 allows local users to cause a denial of service (disable syslog) and prevent security messages from being logged via unspecified vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5002
Unspecified vulnerability in IBM Inventory Scout for AIX 2.2.0.0 through 2.2.0.9 (invscoutClient_VPD_Survey) allows attackers to overwrite arbitrary files via unspecified vectors.... Read more
- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
4.6
MEDIUMCVE-2006-5007
Untrusted search path vulnerability in uucp in IBM AIX 5.2.0 and 5.3.0 allows local users to local users to gain privileges via a Trojan horse program involving uux.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5008
Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attackers to execute arbitrary commands and overwrite arbitrary files via unspecified vectors.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-4924
sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detect... Read more
Affected Products : openssh- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025
-
7.2
HIGHCVE-2006-5010
Untrusted search path vulnerability in acctctl in IBM AIX 5.3.0 allows local users to execute arbitrary commands by modifying the path to point to a malicious mkdir program.... Read more
Affected Products : aix- Published: Sep. 27, 2006
- Modified: Apr. 09, 2025