Latest CVE Feed
-
2.1
LOWCVE-2006-1050
Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information i... Read more
Affected Products : kwik-pay_payroll- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1042
Multiple SQL injection vulnerabilities in Gregarius 0.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) folder parameter to feed.php or (2) rss_query parameter to search.php.... Read more
Affected Products : gregarius- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1039
SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.... Read more
Affected Products : sap_web_application_server- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1041
Multiple cross-site scripting (XSS) vulnerabilities in Gregarius 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_query parameter to search.php or (2) tag parameter to tags.php.... Read more
Affected Products : gregarius- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1043
Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Sol... Read more
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1048
Joomla! 1.0.7 and earlier allows attackers to bypass intended access restrictions and gain certain privileges via certain attack vectors related to the (1) Weblink, (2) Polls, (3) Newsfeeds, (4) Weblinks, (5) Content, (6) Content Section, (7) Content Cate... Read more
Affected Products : joomla- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1034
Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance ... Read more
Affected Products : burning_board- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1045
The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive informati... Read more
Affected Products : thunderbird- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1032
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.... Read more
Affected Products : phprpc- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1040
Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.... Read more
Affected Products : vbulletin- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1035
Unspecified vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to access diagnostics tests via unknown attack vectors.... Read more
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1044
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will ... Read more
Affected Products : listserv- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1031
config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.... Read more
Affected Products : igenus_webmail- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1046
server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.... Read more
Affected Products : monopd- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1047
Unspecified vulnerability in the "Remember Me login functionality" in Joomla! 1.0.7 and earlier has unknown impact and attack vectors.... Read more
Affected Products : joomla- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0047
packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.... Read more
Affected Products : freeciv- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1036
Multiple unspecified vulnerabilities in the Oracle Diagnostics module 2.2 and earlier have unknown impact and attack vectors, related to "permissions."... Read more
Affected Products : diagnostics- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1038
Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string.... Read more
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1037
SQL injection vulnerability in the Oracle Diagnostics module 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1049
Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : joomla- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025