Latest CVE Feed
-
7.5
HIGHCVE-2006-0681
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.... Read more
Affected Products : power_daemon- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0683
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled ... Read more
Affected Products : virtual_hosting_control_system- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0684
change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.... Read more
Affected Products : virtual_hosting_control_system- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0452
dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a l... Read more
Affected Products : fedora_core- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0382
Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0453
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.... Read more
Affected Products : fedora_core- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0451
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was alloca... Read more
Affected Products : fedora_core- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0006
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code v... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_media_player windows_98 windows_98se windows_me- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0004
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF)... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0013
Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-200... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0021
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0553
PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a crafted SET ROLE to other database users, a different vulnerability than CVE-2006-0678.... Read more
Affected Products : postgresql- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0008
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clickin... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
1.5
LOWCVE-2006-0678
PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a differen... Read more
Affected Products : postgresql- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0005
Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with ... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0677
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.... Read more
Affected Products : heimdal- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0674
Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.... Read more
Affected Products : aix- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0671
Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0669
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that ... Read more
Affected Products : gas_forum_light- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0670
Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.... Read more
Affected Products : hcidump- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025