Latest CVE Feed
-
2.6
LOWCVE-2006-0053
Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.... Read more
Affected Products : imager- Published: Apr. 10, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0951
The GUI (nod32.exe) in NOD32 2.5 runs with SYSTEM privileges when the scheduler runs a scheduled on-demand scan, which allows local users to execute arbitrary code during a scheduled scan via unspecified attack vectors.... Read more
Affected Products : nod32_antivirus- Published: Apr. 08, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1659
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id... Read more
Affected Products : image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1667
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $pro... Read more
Affected Products : crafty_syntax_image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1668
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullima... Read more
Affected Products : crafty_syntax_image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1658
Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T. 1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.... Read more
Affected Products : n.t.- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1666
SQL injection vulnerability in forum.php in Arab Portal 2.0.1 stable allows remote attackers to execute arbitrary SQL commands via the mineID parameter.... Read more
Affected Products : arab_portal- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1664
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.... Read more
Affected Products : xine-lib- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1669
SQL injection vulnerability in chat/messagesL.php3 in phpHeaven Team PHPMyChat 0.14.5 and earlier allows remote attackers to execute arbitrary SQL commands via the T parameter. NOTE: this issue can be leveraged to execute arbitrary shell commands since t... Read more
Affected Products : phpmychat- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1657
Cross-site scripting (XSS) vulnerability in index.php in Chucky A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not filtered when the administrator views the "Login Log" page.... Read more
Affected Products : n.t.- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1662
The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php.... Read more
Affected Products : limbo_cms- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1665
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0.1 stable allow remote attackers to inject arbitrary web script or HTML via the (1) adminJump and (2) forum_middle parameters in (a) forum.php, and the (3) form parameter in (b) members... Read more
Affected Products : arab_portal- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1670
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memory exhaustion and possibly card reset) by sending an invalid response when the final ACK is expected, aka b... Read more
Affected Products : ons_15600 ons_15454_mspp ons_15454_mstp optical_networking_systems_software ons_15310-cl_series- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1671
Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (card reset) via (1) a "crafted" IP packet to a device with secure mode EMS-to-network-element access, aka bug I... Read more
- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1672
The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.... Read more
- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1660
Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. NOTE: the provenance of this information is unknown; the details are obtained from third... Read more
Affected Products : image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1673
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.... Read more
Affected Products : vbug_tracker- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1661
Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time parameter in planning.View.action, and (3) userID param... Read more
Affected Products : skforum- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1629
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.... Read more
- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1615
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence tha... Read more
Affected Products : clamav- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025