Latest CVE Feed
-
4.6
MEDIUMCVE-2006-1241
Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.... Read more
Affected Products : firebird- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1243
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter... Read more
Affected Products : simple_php_blog- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-1240
Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.... Read more
- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1242
The ip_push_pending_frames function in Linux 2.4.x and 2.6.x before 2.6.16 increments the IP ID field when sending a RST after receiving unsolicited TCP SYN-ACK packets, which allows remote attackers to conduct an Idle Scan (nmap -sI) attack, which bypass... Read more
- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1238
SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.... Read more
Affected Products : dslogin- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0024
Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.... Read more
Affected Products : flash_player- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1239
Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field. NOTE: the provenance of this information is unknown; the details are ... Read more
Affected Products : gemini- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1237
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.... Read more
Affected Products : dsnewsletter- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1236
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010.... Read more
Affected Products : crossfire- Published: Mar. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1235
Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the r... Read more
Affected Products : hithost- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0031
Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which le... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0009
Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as ... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0029
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0028
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to m... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0030
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1231
CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.... Read more
Affected Products : capi4hylafax- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1232
Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php.... Read more
Affected Products : dsdownload- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1234
SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.... Read more
Affected Products : dscounter- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1229
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from... Read more
Affected Products : hosting_controller- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1228
Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.... Read more
Affected Products : drupal- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025