Latest CVE Feed
-
7.5
HIGHCVE-2006-1386
The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.... Read more
Affected Products : twiki- Published: Mar. 26, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-1390
The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overw... Read more
Affected Products : linux- Published: Mar. 25, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1389
Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.... Read more
Affected Products : hp-ux- Published: Mar. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1391
The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.... Read more
- Published: Mar. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1388
Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.... Read more
- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0816
Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.... Read more
Affected Products : orion_application_server- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1380
ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonito... Read more
Affected Products : interscan_messaging_security_suite- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1384
Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.... Read more
Affected Products : tivoli_business_systems_manager- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1382
PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath parameter.... Read more
Affected Products : impex- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1383
Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on wh... Read more
Affected Products : baby_ftp_server- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1385
Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.... Read more
Affected Products : kismac- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1381
Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.... Read more
Affected Products : officescan- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1379
Trend Micro PC-cillin Internet Security 2006 14.00.1485 and 14.10.0.1023, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying executable programs such as (1) tmntsrv.exe and (2) tmproxy.exe.... Read more
Affected Products : pc-cillin_2006- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1373
Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter.... Read more
Affected Products : php_live- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1374
SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter.... Read more
Affected Products : adman- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1372
Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.... Read more
Affected Products : 1webcalendar- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-1378
PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generati... Read more
Affected Products : password_safe- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1377
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.... Read more
- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1375
AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php.... Read more
Affected Products : adman- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1376
The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service (disk consumption).... Read more
Affected Products : debian_linux- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025