Latest CVE Feed
-
4.6
MEDIUMCVE-2006-1227
Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.... Read more
Affected Products : drupal- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1233
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.... Read more
Affected Products : wmnews- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1230
Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was l... Read more
Affected Products : vcard- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1225
CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.... Read more
Affected Products : drupal- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1226
Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : drupal- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0399
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in th... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0400
CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1222
Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields.... Read more
Affected Products : zeroboard- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0396
Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the ov... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0397
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in th... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2006-1221
Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm's own folders before other folders that are specified in a user's PATH, which might allow local users to execute c... Read more
Affected Products : zonealarm_security_suite- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1224
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.... Read more
Affected Products : guppy- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0398
Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in th... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1223
Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.... Read more
Affected Products : jupiter_cms- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1217
SQL injection vulnerability in DSPoll 1.1 allows remote attackers to execute arbitrary SQL commands via the pollid parameter to (1) results.php, (2) topolls.php, (3) pollit.php.... Read more
Affected Products : dspoll- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1216
Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : runcms- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1218
Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1".... Read more
Affected Products : bordermanager- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1215
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the origin... Read more
Affected Products : burning_board- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1219
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.... Read more
Affected Products : gallery- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-1220
Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.... Read more
- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025