Latest CVE Feed
-
9.3
HIGHCVE-2006-5176
Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the signature field of NTLM Type 1 messages".... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5185
Eval injection vulnerability in Template.php in HAMweather 3.9.8.4 and earlier allows remote attackers to execute arbitrary code via a modified query string, which is supplied to an eval function call within the do_parse_code function.... Read more
Affected Products : hamweather- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5168
Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.... Read more
Affected Products : pebble- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5186
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.... Read more
Affected Products : phpmyprofiler- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5201
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) St... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-5174
The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a b... Read more
Affected Products : linux_kernel- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-5204
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be le... Read more
Affected Products : invision_power_board- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5193
PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir parameter.... Read more
Affected Products : wikyblog- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-5194
Cross-site scripting (XSS) vulnerability in index.php in net2ftp 0.93 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : net2ftp- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5183
Multiple PHP remote file inclusion vulnerabilities in Dayfox Designs Dayfox Blog 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the slogin parameter in the (1) adminlog.php, (2) postblog.php, (3) index.php, or (4) index2.php script ... Read more
Affected Products : dayfox_blog- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.9
MEDIUMCVE-2006-3741
The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descrip... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5156
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.... Read more
- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.5
MEDIUMCVE-2006-5150
SQL injection vulnerability in the reports system in OpenBiblio before 0.5.2 allows remote attackers with report privileges to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : openbiblio- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5151
Unspecified vulnerability in HP Ignite-UX server before C.6.9.150 for HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to "gain root access" via unspecified vectors.... Read more
Affected Products : hp-ux- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5154
PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.... Read more
Affected Products : deluxebb- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5155
PHP remote file inclusion vulnerability in core/pdf.php in VideoDB 2.2.1 and earlier allows remote attackers to execute arbitrary PHP code via the config[pdf_module] parameter.... Read more
Affected Products : videodb- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5167
Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c) com... Read more
Affected Products : basilix_webmail- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.4
MEDIUMCVE-2006-5161
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.... Read more
Affected Products : client_security_password_manager- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5162
wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.... Read more
Affected Products : internet_explorer- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
6.8
MEDIUMCVE-2006-5164
Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.... Read more
Affected Products : digishop- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025