Latest CVE Feed
-
7.5
HIGHCVE-2006-4799
Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.... Read more
Affected Products : xine-lib- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4790
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by ... Read more
Affected Products : gnutls- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4789
Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or execute arbitrary code via a long project name in an open_movie_editor_project XML tag.... Read more
Affected Products : open_movie_editor- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4788
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code... Read more
Affected Products : signkorn_guestbook- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4778
SQL injection vulnerability in Creative Commons Tools ccHost before 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URL, which is used to populate the file ID. NOTE: Some details are obtained from third party information.... Read more
Affected Products : cchost- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4783
SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the squadID parameter.... Read more
Affected Products : webspell- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4781
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constr... Read more
Affected Products : tftp_server_multithreaded- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4780
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : phpbb_xs- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-4787
AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information.... Read more
Affected Products : alphamail- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-4782
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php... Read more
Affected Products : webspell- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4779
PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : vitrax_premodded_phpbb- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4785
SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, ... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4784
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4786
Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4771
Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte parameter.... Read more
Affected Products : forumjbc- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4773
Sun StorEdge 6130 Array Controllers with firmware 06.12.10.11 and earlier allow remote attackers to cause a denial of service (controller reboot) via a flood of traffic on the LAN.... Read more
Affected Products : storedge_6130_arrays- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4725
Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox.... Read more
Affected Products : coldfusion- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4724
Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command.... Read more
Affected Products : coldfusion- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4726
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.... Read more
Affected Products : coldfusion- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-4774
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to cause a denial of service by sending a VTP version 1 summary frame with a VTP version field value of 2.... Read more
Affected Products : ios- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025