Latest CVE Feed
-
5.1
MEDIUMCVE-2006-3637
Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Render... Read more
- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3450
Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layou... Read more
- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3451
Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecif... Read more
Affected Products : ie- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3638
Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the Direc... Read more
- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3583
Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote attackers to hijack web sessions via a crafted link and the administrator section.... Read more
Affected Products : jetbox_cms- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3584
Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.... Read more
Affected Products : jetbox_cms- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3856
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows local users to cause a denial of service (crash) via unspecified vectors.... Read more
Affected Products : informix_dynamic_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3862
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through 9.40.xC7 and 10.00.TC1 through 10.00.xC3 allows attackers to execute arbitrary code via the SQLIDEBUG environment variable (envariable).... Read more
Affected Products : informix_dynamic_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-3114
PC Tools AntiVirus 2.1.0.51 uses insecure default permissions on the "PC Tools AntiVirus" directory, which allows local users to gain privileges and execute commands.... Read more
Affected Products : pc_tools_antivirus- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3857
Multiple buffer overflows in IBM Informix Dynamic Server (IDS) before 9.40.TC6 and 10.00 before 10.00.TC3 allow remote authenticated users to execute arbitrary code via (1) the getname function, as used by (a) _sq_remview, (b) _sq_remproc, (c) _sq_remperm... Read more
Affected Products : informix_dynamic_database_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3853
Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 and 10.00 before 10.00.TC3, when running on Windows, allows remote attackers to execute arbitrary code via a long username.... Read more
Affected Products : informix_dynamic_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-3855
The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR."... Read more
Affected Products : informix_dynamic_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3858
IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before 10.00.xC4 stores passwords in plaintext in shared memory, which allows local users to obtain passwords by reading the memory (product defects 171893, 171894, 173772).... Read more
Affected Products : informix_dynamic_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-3861
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 does not use database creation permissions, which allows remote authenticated users to create arbitrary databases.... Read more
Affected Products : informix_dynamic_server- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4018
Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.... Read more
Affected Products : clamav- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-4020
scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments an index past the end of an array and triggers a buffer ... Read more
Affected Products : php- Published: Aug. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4008
PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter.... Read more
Affected Products : faq- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4016
Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS stable 1.0.3 and earlier, and unstable 1.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via the s parameter.... Read more
Affected Products : toendacms- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4012
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbitrary PHP code via a URL in the SITE_Path parameter to (1) poll/poll.php or (2) poll/view_polls.php. NOTE: the menu_dx.php vector is al... Read more
Affected Products : savewebportal- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4003
The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.... Read more
Affected Products : hobbit_monitor- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025