Latest CVE Feed
-
7.5
HIGHCVE-2006-4045
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.... Read more
Affected Products : torbstoff_news- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-4049
Unspecified vulnerability in the utxconfig utility in Sun Ray Server Software 3.x allows local users to create or overwrite arbitrary files via unknown attack vectors.... Read more
Affected Products : ray_server_software- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4048
Netious CMS 0.4 initializes session IDs based on the client IP address, which allows remote attackers to gain access to the administration section when originating from the same IP address as the administrator. NOTE: the provenance of this information is... Read more
Affected Products : netious_cms- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4043
index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message.... Read more
Affected Products : mybloggie- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3122
The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with a 32 byte client-identifier, which causes the packet to be interpreted as a ... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4032
Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.... Read more
Affected Products : callmanager_express- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-4033
Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LZH archive with a long header, as specified by the extendedHeaderSize.... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4037
Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet.... Read more
Affected Products : faxination_server- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-4031
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4039
Multiple SQL injection vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) gastname, (2) gastwohnort, or (3) gasteintrag parameters.... Read more
Affected Products : gaestechaos- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4038
Multiple cross-site scripting (XSS) vulnerabilities in eintragen.php in GaesteChaos 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gastname or (2) gastwohnort parameters.... Read more
Affected Products : gaestechaos- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4036
PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.... Read more
Affected Products : zonex_publishers_gold_edition- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4034
PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the DIR parameter.... Read more
Affected Products : modernbill- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4035
SQL injection vulnerability in counterchaos.php in CounterChaos 0.48c and earlier allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.... Read more
Affected Products : counterchaos- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4028
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.... Read more
Affected Products : wordpress- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4029
Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 allows remote attackers to execute arbitrary code via a crafted UDP SIP packet.... Read more
Affected Products : agephone- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3083
The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which allows local users to gain privile... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3084
The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to ... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3979
The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator.... Read more
Affected Products : coldfusion- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3440
Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025