Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-5081

    PHP remote file inclusion vulnerability in acc.php in QuickBlogger (QB) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.... Read more

    Affected Products : quickblogger
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5084

    Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally re... Read more

    Affected Products : skype skype
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.8

    HIGH
    CVE-2006-5075

    The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client.... Read more

    Affected Products : solaris
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5078

    PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.... Read more

    Affected Products : polaring
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5076

    Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.... Read more

    Affected Products : back-end_cms
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 5.0

    MEDIUM
    CVE-2006-4925

    packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.... Read more

    Affected Products : openssh
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5085

    Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected into include/variables.php.... Read more

    Affected Products : pixel_motion_blog
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5077

    PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more

    Affected Products : minerva
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 6.4

    MEDIUM
    CVE-2006-5086

    Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the origin... Read more

    Affected Products : pixel_motion_blog
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5079

    PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.... Read more

    Affected Products : pabugs
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5074

    Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert parameter.... Read more

    Affected Products : php_invoice
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 4.3

    MEDIUM
    CVE-2006-5080

    Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : movable_type movable_type
    • Published: Sep. 29, 2006
    • Modified: Apr. 09, 2025
  • 7.8

    HIGH
    CVE-2006-2937

    OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.... Read more

    Affected Products : openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.8

    HIGH
    CVE-2006-2940

    OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that req... Read more

    Affected Products : openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 4.3

    MEDIUM
    CVE-2006-4343

    The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.... Read more

    Affected Products : ubuntu_linux debian_linux openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-3738

    Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.... Read more

    Affected Products : openssl
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 2.6

    LOW
    CVE-2006-5069

    Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more

    Affected Products : typo3
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5058

    Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute arbitrary code via a long map argument to the "callvote map" command.... Read more

    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 5.1

    MEDIUM
    CVE-2006-5065

    PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.... Read more

    Affected Products : zoomstats
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
  • 7.5

    HIGH
    CVE-2006-5062

    PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.... Read more

    Affected Products : pblang
    • Published: Sep. 28, 2006
    • Modified: Apr. 09, 2025
Showing 20 of 294733 Results