Latest CVE Feed
-
9.3
HIGHCVE-2006-4482
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.... Read more
- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-4481
The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. NOTE: the error_log function is covered by CVE-2006-3011, and the imap_open f... Read more
Affected Products : php- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3125
Array index error in tetrinet.c in gtetrinet 0.7.8 and earlier allows remote attackers to execute arbitrary code via a packet specifying a negative number of players, which is used as an array index.... Read more
Affected Products : gtetrinet- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4478
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter.... Read more
Affected Products : ezcontents- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4480
Incomplete blacklist vulnerability in the nk_CSS function in nuked.php in Nuked-Klan 1.7 SP4.3 allows remote attackers to bypass anti-XSS features and inject arbitrary web script or HTML via JavaScript in an attribute value that is not in the blacklist, a... Read more
Affected Products : nuked-klan- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-4483
The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related t... Read more
Affected Products : php- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4477
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1) GLOBALS[admin_home] parameter in (a) diary/event_l... Read more
Affected Products : ezcontents- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4485
The stripos function in PHP before 5.1.5 has unknown impact and attack vectors related to an out-of-bounds read.... Read more
Affected Products : php- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-4479
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter.... Read more
Affected Products : ezcontents- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4486
Integer overflow in memory allocation routines in PHP before 5.1.6, when running on a 64-bit system, allows context-dependent attackers to bypass the memory_limit restriction.... Read more
Affected Products : php- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4484
Buffer overflow in the LWZReadByte_ function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow wh... Read more
Affected Products : php- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4465
Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer er... Read more
Affected Products : terminal_server- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4475
Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.... Read more
Affected Products : joomla- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4474
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.11 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) Admin Module Manager, (2) Admin Help, and (3) Search.... Read more
Affected Products : joomla- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-4468
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mosMail, (2) JosIsValidEmail, and (3) josSpoofValue functions; (4) the lack of... Read more
- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4466
Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to have an unspecified impact. NOTE: it could be argued t... Read more
Affected Products : joomla- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4467
Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to per... Read more
Affected Products : simple_machines_forum- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-4470
Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion.... Read more
- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4461
Paessler IPCheck Server Monitor before 5.3.3.639/640 does not properly implement a "list of acceptable host IP addresses in the probe settings," which has unknown impact and attack vectors.... Read more
Affected Products : ipcheck_server_monitor- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-4464
The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string.... Read more
Affected Products : symbian- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025