Latest CVE Feed
-
9.3
HIGHCVE-2006-1304
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1302
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerabilit... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3135
Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter in the (a) news module, (2) searchstring parameter in (b) the search mod... Read more
Affected Products : cms_mundo- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3587
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.... Read more
Affected Products : flash_player- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3581
Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1) DTM and (2) S3M files.... Read more
Affected Products : adplug- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3582
Multiple heap-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via the size specified in the package header of (1) CFF, (2) MTK, (3) DMO, and (4) U6M files.... Read more
Affected Products : adplug- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3453
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.... Read more
Affected Products : acrobat- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3579
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : serverview- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3577
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.... Read more
Affected Products : lifetype- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3580
SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.... Read more
Affected Products : asp_stats_generator- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3574
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts"... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3578
Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : serverview- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3576
SQL injection vulnerability in search.php in SenseSites CommonSense CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the Date parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party i... Read more
Affected Products : commonsense_cms- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3573
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.... Read more
Affected Products : sparklet- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3575
Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module name", or (3) "API name" fields.... Read more
Affected Products : virusscan- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3565
SQL injection vulnerability in search.results.php in HiveMail 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the fields[] parameter.... Read more
Affected Products : hivemail- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3567
Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field... Read more
Affected Products : dx- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3566
search.results.php in HiveMail 3.1 and earlier allows remote attackers to obtain the installation path via certain manipulations related to the (1) searchdate and (2) folderids parameters.... Read more
Affected Products : hivemail- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3563
Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : winged_gallery- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3562
PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.php, (2) rss.php, or (3) search.php, a different set of vectors and versions... Read more
Affected Products : plume_cms- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025