Latest CVE Feed
-
6.4
MEDIUMCVE-2006-3411
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3414
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-3417
Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard" (is_guard) systems by directory authorities.... Read more
Affected Products : tor- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3427
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.... Read more
Affected Products : internet_explorer- Published: Jul. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3402
SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the password parameter when logging in.... Read more
Affected Products : virtuastore- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3398
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor.... Read more
Affected Products : taskjitsu- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3359
Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, and (4) cat_id parameters in (a) index.php; and the (5) category parameter in... Read more
Affected Products : newsphp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3392
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes su... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3404
Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS... Read more
Affected Products : gimp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-3400
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server.... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-3378
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or reso... Read more
Affected Products : ubuntu_linux- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3396
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.... Read more
Affected Products : galleria- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-3361
PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDI... Read more
- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3397
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task.... Read more
Affected Products : taskjitsu- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-3358
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned... Read more
Affected Products : newsphp- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3365
V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.... Read more
Affected Products : v3_chat- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3370
Blueboy 1.0.3 stores bb_news_config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : blueboy- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3367
Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.... Read more
Affected Products : mp3netbox- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3366
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) l... Read more
Affected Products : v3_chat- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-3379
Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.... Read more
Affected Products : hiki_wiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025