Latest CVE Feed
-
4.9
MEDIUMCVE-2006-1538
The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware toke... Read more
Affected Products : x-wall_asic- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1537
Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.p... Read more
Affected Products : webcalendar- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1534
Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.... Read more
Affected Products : null_news- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1541
SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.... Read more
Affected Products : ezaspsite- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1545
Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.... Read more
Affected Products : vnews- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1543
Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.... Read more
Affected Products : vnews- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1539
Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable... Read more
Affected Products : tetris-bsd- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1535
Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.... Read more
Affected Products : phxcontacts- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1533
SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.... Read more
Affected Products : newsletter- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1544
Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.... Read more
Affected Products : vnews- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2006-1542
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has... Read more
Affected Products : python- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1503
PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter. NOTE: this is a different vulner... Read more
Affected Products : virtual_war- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1504
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.... Read more
Affected Products : arab_portal- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1508
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a... Read more
Affected Products : connect_daily- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1510
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a ... Read more
Affected Products : .net_framework- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-1509
/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.... Read more
Affected Products : hp-ux- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1505
base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".... Read more
Affected Products : base- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1507
Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.... Read more
Affected Products : phpkit- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1506
Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.... Read more
- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1511
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.... Read more
Affected Products : .net_framework- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025