Latest CVE Feed
-
4.3
MEDIUMCVE-2006-0699
Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : qwikiwiki- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0695
Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.... Read more
Affected Products : ansilove- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0706
Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.... Read more
Affected Products : gastebuch- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0709
Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.... Read more
- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0705
Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server fo... Read more
- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0708
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u ... Read more
Affected Products : winamp- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0691
edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.... Read more
Affected Products : time_tracking_software- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0712
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.... Read more
Affected Products : squishdot- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0689
Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.... Read more
Affected Products : time_tracking_software- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0685
The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : virtual_hosting_control_system- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0687
process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.... Read more
Affected Products : docmgr- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0686
add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.... Read more
Affected Products : virtual_hosting_control_system- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0680
Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL.... Read more
Affected Products : webgui- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0682
Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : e107- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0681
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.... Read more
Affected Products : power_daemon- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0683
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled ... Read more
Affected Products : virtual_hosting_control_system- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0684
change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.... Read more
Affected Products : virtual_hosting_control_system- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0452
dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a l... Read more
Affected Products : fedora_core- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0382
Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0453
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.... Read more
Affected Products : fedora_core- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025