Latest CVE Feed
-
4.6
MEDIUMCVE-2006-4127
Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cm... Read more
Affected Products : dconnect_daemon- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4132
ArcSoft MMS Composer 1.5.5.6 and possibly earlier, and 2.0.0.13 and possibly earlier, allow remote attackers to cause a denial of service (resource exhaustion and application crash) via WAPPush messages to UDP port UDP 2948.... Read more
Affected Products : mms_composer- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4114
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.... Read more
Affected Products : phpmyring- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4111
Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.... Read more
- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-4117
The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a large number of TCP connections ("heavy TCP/IP loads"). NOT... Read more
Affected Products : solaris- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4112
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (... Read more
Affected Products : rails- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4113
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.... Read more
Affected Products : hitweb- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4115
PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter.... Read more
Affected Products : pgmarket- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4116
Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, w... Read more
- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4110
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on c... Read more
Affected Products : http_server- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4102
PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.... Read more
Affected Products : sqlitewebadmin- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4105
Cross-site scripting (XSS) vulnerability in Fill Threads Database (FTD) 3.7.3 allows remote attackers to inject arbitrary web script or HTML via the (1) search field or (2) an e-mail message.... Read more
Affected Products : fill_threads_database- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4106
Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title.... Read more
Affected Products : blur6ex- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1168
The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.... Read more
Affected Products : ncompress- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4109
Cross-site scripting (XSS) vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : bibliography_module- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4108
SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : bibliography_module- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4107
SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search.... Read more
Affected Products : job_search- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4104
Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via "password input."... Read more
Affected Products : mojogallery- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4103
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.... Read more
Affected Products : phnntp- Published: Aug. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3813
A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.... Read more
Affected Products : enterprise_linux- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025