Latest CVE Feed
-
9.3
HIGHCVE-2006-2388
Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-1306
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3582
Multiple heap-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via the size specified in the package header of (1) CFF, (2) MTK, (3) DMO, and (4) U6M files.... Read more
Affected Products : adplug- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3581
Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1) DTM and (2) S3M files.... Read more
Affected Products : adplug- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3453
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF.... Read more
Affected Products : acrobat- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3576
SQL injection vulnerability in search.php in SenseSites CommonSense CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the Date parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party i... Read more
Affected Products : commonsense_cms- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3573
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.... Read more
Affected Products : sparklet- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3578
Directory traversal vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : serverview- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3579
Cross-site scripting (XSS) vulnerability in Fujitsu ServerView 2.50 up to 3.60L98 and 4.10L11 up to 4.11L81 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : serverview- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3577
SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.... Read more
Affected Products : lifetype- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3574
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Groupmax Collaboration Portal and Web Client before 07-20-/D, and uCosminexus Collaboration Portal and Forum/File Sharing before 06-20-/C, allow remote attackers to "execute malicious scripts"... Read more
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3580
SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.... Read more
Affected Products : asp_stats_generator- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3575
Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module name", or (3) "API name" fields.... Read more
Affected Products : virusscan- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3567
Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field... Read more
Affected Products : dx- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3560
SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums 1.0 allows remote attackers to execute arbitrary SQL commands via the f parameter.... Read more
Affected Products : graffiti_forums- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3572
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid parameter.... Read more
Affected Products : papoo- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-3569
Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, 7.1x, 7.1.0.1x, and 7.2RC1, RC2, and RC3, as used in IBM N series Filers and other products, allows unauthorized users to gain access to privileged commands via unknown vectors, probab... Read more
Affected Products : network_appliance_data_ontap- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3570
Cross-site scripting (XSS) vulnerability in the webform module in Drupal 4.6 before July 8, 2006 and 4.7 before July 8, 2006 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3564
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the email, (2) cond, or (3) name parameters to (a) addressbook.view.php, (4) the daysprune parameter to (... Read more
Affected Products : hivemail- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3571
Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) titel or (2) ausgabe parameters.... Read more
Affected Products : papoo- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025