Latest CVE Feed
-
5.1
MEDIUMCVE-2006-0764
The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-serv... Read more
- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0750
SQL injection vulnerability in army.php in supersmashbrothers (SSB) Army System 2.1.0 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the userstat parameter in an army action to index.php.... Read more
Affected Products : army_system- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0752
Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd.... Read more
Affected Products : honeyd- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0761
Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWis... Read more
- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-0765
GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a... Read more
- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0759
Multiple SQL injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the contactgroupid parameter in addressbook.update.php, (2) the messageid parameter in addressbook.add.php, (3) the folderi... Read more
Affected Products : hivemail- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0760
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP... Read more
Affected Products : lighttpd- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0738
Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) t... Read more
Affected Products : softphone- Published: Feb. 17, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0460
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.... Read more
Affected Products : bomberclone- Published: Feb. 17, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0739
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits.... Read more
Affected Products : softphone- Published: Feb. 17, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0737
eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field.... Read more
Affected Products : softphone- Published: Feb. 17, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0679
SQL injection vulnerability in index.php in the Your_Account module in PHP-Nuke 7.8 and earlier allows remote attackers to execute arbitrary SQL commands via the username variable (Nickname field).... Read more
Affected Products : php-nuke_ev- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0733
Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the resear... Read more
Affected Products : wordpress- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0729
SQL injection vulnerability in functions.php in Teca Diary PE 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) yy, (2) mm, and (3) dd parameters.... Read more
Affected Products : teca_diary- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0721
SQL injection vulnerability in pmlite.php in RunCMS 1.2 and 1.3a allows remote attackers to execute arbitrary SQL commands via the to_userid parameter.... Read more
Affected Products : runcms- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0730
Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) do... Read more
Affected Products : dovecot- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0731
WmRoot/adapter-index.dsp in SAP Business Connector Core Fix 7 and earlier allows remote attackers to conduct spoofing (phishing) attacks via an absolute URL in the url parameter, which loads the URL inside a frame.... Read more
Affected Products : business_connector- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0723
PHP remote file inclusion vulnerability in preview.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the php_script_path parameter.... Read more
Affected Products : magic_news_lite- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0727
SQL injection vulnerability in mstrack.php in MusOX DF MSAnalysis (DFMSA), as used in some environments that use CPG-Nuke Dragonfly CMS, allows remote attackers to trigger path disclosure from a SQL syntax error, and possibly execute arbitrary SQL command... Read more
Affected Products : df_msanalysis- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0726
Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users.... Read more
Affected Products : dragonfly_cms- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025