Latest CVE Feed
-
4.3
MEDIUMCVE-2006-3665
SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows remote attackers to hijack cookies in src/redirect.php via unknown vectors. NOTE: while "cookie theft" is frequently associated with XSS, the vendor disclosure is too vague to be certa... Read more
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3654
Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted Excel files.... Read more
Affected Products : works- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3653
wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.... Read more
Affected Products : works- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3662
SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possib... Read more
Affected Products : atutor- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3652
Microsoft Internet Security and Acceleration (ISA) Server 2004 allows remote attackers to bypass file extension filters via a request with a trailing "#" character. NOTE: as of 20060715, this could not be reproduced by third parties.... Read more
Affected Products : isa_server- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3674
nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a large number handled by the id_req_handler function.... Read more
Affected Products : armagetron_advanced- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3656
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 200607... Read more
Affected Products : powerpoint- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3664
Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.... Read more
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3672
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero... Read more
Affected Products : konqueror- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-3663
Finjan Vital Security Appliance 5100/8100 NG 8.3.5 stores passwords in plaintext in a backup file, which allows local users to gain privileges. NOTE: the vendor has notified CVE that this issue was fixed in 8.3.6.... Read more
Affected Products : vital_security- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3666
SQL injection vulnerability in AjaxPortal 3.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the 'Search' field, a different vulnerability than CVE-2006-3515.... Read more
Affected Products : ajaxportal- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3669
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.... Read more
Affected Products : mercury_messenger- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3658
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by accessing the object references of a FolderItem ActiveX object, which triggers a null dereference in the security check.... Read more
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3673
nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote attackers to cause a denial of service (application crash) via a large owner value, which causes an assert error.... Read more
Affected Products : armagetron_advanced- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3655
Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-... Read more
Affected Products : powerpoint- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3661
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party inf... Read more
Affected Products : cutenews- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3609
Cross-site scripting (XSS) vulnerability in index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to inject arbitrary web script or HTML via the page_name parameter with an IMG tag containing a javascript URI in the SRC attribute.... Read more
Affected Products : orbitmatrix- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3622
The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to obtain sensitive information via a ' (single quote) in the p parameter, which displays the path in an error message. NOTE: it is not clear whether this is SQL injection or a forced SQL ... Read more
Affected Products : koobi_pro- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3613
Multiple cross-site scripting (XSS) vulnerabilities in Chamberland Technology ezWaiter 3.0 Online and possibly Enterprise Software (aka enterprise edition) allow remote attackers to inject arbitrary web script or HTML via the (1) itemfor (aka "Who is this... Read more
Affected Products : ezwaiter_online- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-3608
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an... Read more
Affected Products : flatnuke- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025