Latest CVE Feed
-
7.8
HIGHCVE-2006-2919
Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via crafted inputs that trigger memory corruption.... Read more
Affected Products : netmeeting- Published: Jun. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2920
Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote attackers to bypass the URI check functionality and makes it easier to conduct phishing attacks via a URI that begins with a space character.... Read more
- Published: Jun. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2193
Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters,... Read more
Affected Products : libtiff- Published: Jun. 08, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2903
Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : particle_links- Published: Jun. 08, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2904
SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.... Read more
Affected Products : particle_links- Published: Jun. 08, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2905
Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.... Read more
Affected Products : particle_links- Published: Jun. 08, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2902
Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is legitimate, as the original researcher seems unsure.... Read more
Affected Products : particle_links- Published: Jun. 08, 2006
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2006-2906
The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop.... Read more
Affected Products : graphics_draw_library- Published: Jun. 08, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1173
Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8to7 function for performing 8-bit to 7-bit conversion, which prevents Sendmai... Read more
Affected Products : sendmail- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2901
The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system information via a request to an arbitrary .cfg file, which returns configuration information including passwords.... Read more
Affected Products : dwl-2100ap- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2900
Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the... Read more
- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2890
Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct other attacks by setting the _SESSION["pixelpost_admin"] parameter to 1 in calls to admin scripts such as admin/view_inf... Read more
Affected Products : pixelpost- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2883
Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : kmita_faq- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2894
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the char... Read more
- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2879
SQL injection vulnerability in newscomments.php in Alex News-Engine 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.... Read more
Affected Products : news-engine- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-2881
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2) auth.header.i... Read more
Affected Products : dreamaccount- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2897
Cross-site scripting (XSS) vulnerability in FunkBoard 0.71 allows remote attackers to inject arbitrary HTML or web script via unspecified vectors.... Read more
Affected Products : funkboard- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2886
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another v... Read more
Affected Products : knowledgetree_open_source- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-2896
profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action.... Read more
Affected Products : funkboard- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-2888
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter.... Read more
Affected Products : wikiwig- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025