Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2006-3397

    Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.... Read more

    Affected Products : taskjitsu
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3355

    Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an ... Read more

    Affected Products : mpg123
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2006-3393

    Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded du... Read more

    Affected Products : nascar_racing
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3386

    index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.... Read more

    Affected Products : news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3384

    SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.... Read more

    Affected Products : news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3363

    PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.... Read more

    Affected Products : xoops_glossaire_module
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3361

    PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDI... Read more

    Affected Products : stud.ip stud.ip
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-3366

    Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) l... Read more

    Affected Products : v3_chat
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-3396

    PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more

    Affected Products : galleria
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-3365

    V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.... Read more

    Affected Products : v3_chat
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 4.0

    MEDIUM
    CVE-2006-3377

    Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlier, allows remote attackers to inject arbitrary web script or HTML via the (1) Keyword parameter in search.php and the (2) Username para... Read more

    Affected Products : autorank
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-3358

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned... Read more

    Affected Products : newsphp
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3370

    Blueboy 1.0.3 stores bb_news_config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more

    Affected Products : blueboy
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2006-3378

    passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or reso... Read more

    Affected Products : ubuntu_linux
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3379

    Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more

    Affected Products : hiki_wiki
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-3404

    Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS... Read more

    Affected Products : gimp
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.8

    MEDIUM
    CVE-2006-3383

    Cross-site scripting (XSS) vulnerability in index.php in mAds 1.0 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover within a URL. NOTE: the provenance of this information is unknown; the details are ... Read more

    Affected Products : mads
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3360

    Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error ... Read more

    Affected Products : phpsysinfo
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3368

    Efone 20000723 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.... Read more

    Affected Products : efone
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-3373

    Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary files, related to logfetch running as setuid root.... Read more

    Affected Products : hobbit_monitor
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294695 Results