Latest CVE Feed
-
3.6
LOWCVE-2006-5213
Sun Solaris 10 before 20061006 uses "incorrect and insufficient permission checks" that allow local users to intercept or spoof packets by creating a raw socket on a link aggregation (network device aggregation).... Read more
Affected Products : solaris- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2006-5176
Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the signature field of NTLM Type 1 messages".... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.4
MEDIUMCVE-2006-5179
Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra ti... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5191
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : phpbb- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5187
PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : bulletin_board_ace- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.8
HIGHCVE-2006-5196
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.... Read more
Affected Products : surfboard- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5208
Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php.... Read more
Affected Products : php_classifieds- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5182
PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.... Read more
Affected Products : travelsized_cms- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.1
MEDIUMCVE-2006-5207
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter.... Read more
Affected Products : phpmyteam- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5216
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.... Read more
Affected Products : simple_httpd- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5142
Stack-based buffer overflow in CA BrightStor ARCserve Backup R11.5 client and server allows remote attackers to execute arbitrary code via long messages to the CheyenneDS Mailslot.... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-5201
Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) St... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5202
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout paramet... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5183
Multiple PHP remote file inclusion vulnerabilities in Dayfox Designs Dayfox Blog 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the slogin parameter in the (1) adminlog.php, (2) postblog.php, (3) index.php, or (4) index2.php script ... Read more
Affected Products : dayfox_blog- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5143
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote att... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
6.2
MEDIUMCVE-2006-5072
The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-5170
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
7.5
HIGHCVE-2006-4997
The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed ... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
5.0
MEDIUMCVE-2006-5212
Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6.5.0.1418, 7.0 before 7.0.0.1257, and 7.3 before 7.3.0.1053 allow remote attackers to delete files via a m... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-4812
Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ... Read more
Affected Products : php- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025