Latest CVE Feed
-
7.5
HIGHCVE-2006-3375
PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter.... Read more
Affected Products : randshop- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3380
Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more
Affected Products : freestyle_wiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3372
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.... Read more
Affected Products : safari- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3374
PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter.... Read more
Affected Products : randshop- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3387
Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code t... Read more
Affected Products : fusion_news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3373
Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary files, related to logfetch running as setuid root.... Read more
Affected Products : hobbit_monitor- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3385
Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3395
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.... Read more
Affected Products : sitebuilder-fx- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3357
Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of a... Read more
Affected Products : internet_explorer- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes su... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3404
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS... Read more
Affected Products : gimp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3389
index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party ... Read more
Affected Products : wordpress- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3362
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when inst... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-3388
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.... Read more
Affected Products : phpmyadmin- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3384
SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3386
index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.... Read more
Affected Products : news- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3363
PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.... Read more
Affected Products : xoops_glossaire_module- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-3393
Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded du... Read more
Affected Products : nascar_racing- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3400
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server.... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3355
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an ... Read more
Affected Products : mpg123- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025