Latest CVE Feed
-
5.0
MEDIUMCVE-2006-3602
Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the language parameter in the advanced theme.... Read more
Affected Products : farsinews- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3600
Multiple stack-based buffer overflows in the LookupTRM::lookup function in libtunepimp (TunePimp) 0.4.2 allow remote user-assisted attackers to cause a denial of service (application crash) and possibly execute code via a long (1) Album release date (MBE_... Read more
Affected Products : libtunepimp- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3590
mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue t... Read more
Affected Products : powerpoint- Published: Jul. 14, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1309
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1301
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1308
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3135
Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) news_id parameter in the (a) news module, (2) searchstring parameter in (b) the search mod... Read more
Affected Products : cms_mundo- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1304
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1302
Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerabilit... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3588
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.... Read more
Affected Products : flash_player- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-2388
Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3587
Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.... Read more
Affected Products : flash_player- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1306
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3582
Multiple heap-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via the size specified in the package header of (1) CFF, (2) MTK, (3) DMO, and (4) U6M files.... Read more
Affected Products : adplug- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3581
Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1) DTM and (2) S3M files.... Read more
Affected Products : adplug- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3453
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.... Read more
Affected Products : acrobat- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3578
Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : serverview- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3576
SQL injection vulnerability in search.php in SenseSites CommonSense CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the Date parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party i... Read more
Affected Products : commonsense_cms- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3575
Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module name", or (3) "API name" fields.... Read more
Affected Products : virusscan- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3573
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.... Read more
Affected Products : sparklet- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025