Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2006-3393

    Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded du... Read more

    Affected Products : nascar_racing
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3386

    index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.... Read more

    Affected Products : news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3392

    Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes su... Read more

    Affected Products : webmin usermin
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3398

    The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.... Read more

    Affected Products : taskjitsu
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3359

    Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in... Read more

    Affected Products : newsphp
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3401

    Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values.... Read more

    Affected Products : quake_3_engine
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3402

    SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the password parameter when logging in.... Read more

    Affected Products : virtuastore
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3400

    Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server.... Read more

    Affected Products : quake_3_engine soldier_of_fortune_2
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3355

    Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an ... Read more

    Affected Products : mpg123
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3375

    PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute arbitrary PHP code via the dateiPfad parameter.... Read more

    Affected Products : randshop
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-3373

    Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary files, related to logfetch running as setuid root.... Read more

    Affected Products : hobbit_monitor
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3374

    PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attackers to execute arbitrary PHP code via a URL in the incl parameter.... Read more

    Affected Products : randshop
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3372

    Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.... Read more

    Affected Products : safari
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3376

    Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a W... Read more

    Affected Products : libwmf wv2
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3364

    SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more

    Affected Products : blog_cms
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-3356

    The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This... Read more

    Affected Products : mac_os_x mac_os_x_server
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3380

    Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more

    Affected Products : freestyle_wiki
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-3368

    Efone 20000723 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.... Read more

    Affected Products : efone
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-3394

    SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary SQL commands via the where parameter in a view action.... Read more

    Affected Products : bxcp
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
  • 5.8

    MEDIUM
    CVE-2006-3385

    Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.... Read more

    Affected Products : news
    • Published: Jul. 06, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294726 Results