Latest CVE Feed
-
5.0
MEDIUMCVE-2006-0503
IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.... Read more
Affected Products : mailenable_professional- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0497
Multiple SQL injection vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0498
Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : php_gen- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0487
Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spa... Read more
Affected Products : mailgate_email_firewall- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0492
Multiple SQL injection vulnerabilities in Calendarix allow remote attackers to execute arbitrary SQL commands via (1) the catview parameter in cal_functions.inc.php and (2) the login parameter in cal_login.php. NOTE: the catview vector might overlap CVE-... Read more
Affected Products : calendarix- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0485
The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow loc... Read more
Affected Products : ios- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0490
SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field.... Read more
Affected Products : aspthai_forums- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0491
SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.... Read more
Affected Products : szusermgnt- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0488
The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dump... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0494
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin par... Read more
Affected Products : mybulletinboard- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0495
Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable).... Read more
Affected Products : mybulletinboard- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0486
Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does n... Read more
Affected Products : ios- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0489
Buffer overflow in the font command of mIRC, probably 6.16, allows local users to execute arbitrary code via a long string. NOTE: the original researcher claims that issue has been disputed by the vendor, and that the vendor stated "as far as I can tell, ... Read more
Affected Products : mirc- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0496
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascad... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0493
Cross-site scripting (XSS) vulnerability in MG2 (formerly known as Minigal) 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field in a comment associated with a picture.... Read more
Affected Products : mg2- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0484
Directory traversal vulnerability in Vis.pl, as part of the FACE CONTROL product, allows remote attackers to read arbitrary files via a .. (dot dot) in any parameter that opens a file, such as (1) s or (2) p.... Read more
Affected Products : face_control- Published: Jan. 31, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0483
Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet.... Read more
- Published: Jan. 31, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0482
Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call.... Read more
Affected Products : linux_kernel- Published: Jan. 31, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0481
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.... Read more
Affected Products : libpng- Published: Jan. 31, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0480
Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the query parameter in the search file.... Read more
Affected Products : spaiz-nuke_cms- Published: Jan. 31, 2006
- Modified: Apr. 03, 2025