Latest CVE Feed
-
7.5
HIGHCVE-2006-0520
SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter. NOTE: the provenance of this information is unknown; the details are obta... Read more
Affected Products : portal_module- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0528
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a... Read more
Affected Products : evolution- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0526
The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file name, which might allow local users to gain privileges via a Trojan horse program.... Read more
Affected Products : aol_client_software- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0527
BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.... Read more
Affected Products : bind- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0521
Cross-site scripting (XSS) vulnerability in results.php in BrowserCRM allows remote attackers to inject arbitrary web script or HTML via certain manipulations of the query parameter, as demonstrated using an IMG SRC tag.... Read more
Affected Products : browsercrm- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0516
Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.... Read more
Affected Products : solaris- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0523
SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.... Read more
Affected Products : mybulletinboard- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0517
Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve p... Read more
Affected Products : spip- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0519
SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.... Read more
Affected Products : spip- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0512
PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migr... Read more
Affected Products : migrationtools- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0518
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more
Affected Products : spip- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0522
SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related ... Read more
Affected Products : sygate_management_server- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0433
Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).... Read more
Affected Products : freebsd- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0508
Easy CMS stores the images directory under the web document root with insufficient access control and browsing enabled, which allows remote attackers to list and possibly read images that are stored in that directory.... Read more
Affected Products : easy_cms- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0511
Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, s... Read more
- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0507
Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.... Read more
Affected Products : easy_cms- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0510
SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.... Read more
Affected Products : daffodil_crm- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0509
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.... Read more
Affected Products : cerberus_helpdesk- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0505
zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.... Read more
Affected Products : zbattle_client- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0506
Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.... Read more
Affected Products : nuked-klan- Published: Feb. 01, 2006
- Modified: Apr. 03, 2025