Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2006-0916

    Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domai... Read more

    Affected Products : bugzilla
    • Published: Feb. 28, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0908

    PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.... Read more

    Affected Products : php-nuke
    • Published: Feb. 28, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0906

    SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.... Read more

    Affected Products : d3jeeb_pro
    • Published: Feb. 28, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0907

    SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injec... Read more

    Affected Products : php-nuke
    • Published: Feb. 28, 2006
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2006-0903

    MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query functi... Read more

    Affected Products : mysql mysql
    • Published: Feb. 27, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-0736

    Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more

    • Published: Feb. 27, 2006
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2006-0900

    nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.... Read more

    Affected Products : freebsd
    • Published: Feb. 27, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0899

    Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.... Read more

    Affected Products : image_gallery_management_system
    • Published: Feb. 27, 2006
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2006-0901

    Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.... Read more

    Affected Products : solaris sunos
    • Published: Feb. 27, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0897

    SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp. NOTE: the provenance of this information is unknow... Read more

    Affected Products : vpmi_enterprise
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-0889

    Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party i... Read more

    Affected Products : calcium
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0887

    Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representat... Read more

    Affected Products : phplib
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-0891

    Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the la... Read more

    Affected Products : nocc
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-0892

    NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-mail attachment via directory traversal vulnerabilities.... Read more

    Affected Products : nocc
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-0895

    NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.... Read more

    Affected Products : nocc
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-0898

    Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.... Read more

    Affected Products : crypt_cbc
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-0893

    NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of profiles, and (2) the tmp directory, which lists names of uploaded attachme... Read more

    Affected Products : nocc
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-0894

    Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no... Read more

    Affected Products : nocc
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-0896

    Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.... Read more

    Affected Products : simple_machines_forum
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-0888

    index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.... Read more

    Affected Products : invision_power_board
    • Published: Feb. 25, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 293435 Results