Latest CVE Feed
-
7.2
HIGHCVE-2006-3500
The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," probably related to an untrusted search path vulnerability.... Read more
- Published: Aug. 03, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0392
Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.... Read more
- Published: Aug. 03, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3502
Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly ha... Read more
- Published: Aug. 03, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3459
Multiple stack-based buffer overflows in the TIFF library (libtiff) before 3.8.2, as used in Adobe Reader 9.3.0 and other products, allow context-dependent attackers to execute arbitrary code or cause a denial of service via unspecified vectors, including... Read more
- Published: Aug. 03, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3462
Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors involving decoding large RLE images.... Read more
Affected Products : libtiff- Published: Aug. 03, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3496
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.... Read more
- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3971
Cross-site scripting (XSS) vulnerability in visitor/livesupport/chat.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to inject arbitrary web script or HTML via the userid parameter.... Read more
Affected Products : ajax_chat- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1473
Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.... Read more
- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3498
Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request.... Read more
- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3497
Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive.... Read more
- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3495
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users.... Read more
- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3972
Directory traversal vulnerability in includes/operator_chattranscript.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to read arbitrary files via a .. (dot dot) in the chatid parameter.... Read more
Affected Products : ajax_chat- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1472
Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the search results.... Read more
- Published: Aug. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3968
The crypto provider in Sun Solaris 10 3/05 HW2 without patch 121236-01, when running on Sun Fire T2000 platforms, incorrectly verifies a DSA signature, which might prevent applications from detecting that the data has been modified.... Read more
Affected Products : solaris- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3963
Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (... Read more
Affected Products : banex- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3967
PHP remote file inclusion vulnerability in component/option,com_moskool/Itemid,34/admin.moskool.php in MamboXChange Moskool 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : moskool- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3962
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesiannaivefilter) 1.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosCon... Read more
Affected Products : bayesiannaivefilter- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3969
PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : colophon- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3970
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : lmo- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3966
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.... Read more
- Published: Aug. 01, 2006
- Modified: Apr. 03, 2025