Latest CVE Feed
-
5.0
MEDIUMCVE-2006-0416
SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php.... Read more
Affected Products : sleeperchat- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0414
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.... Read more
Affected Products : tor- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0225
scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.... Read more
Affected Products : openssh- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0417
SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.... Read more
Affected Products : minibloggie- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0412
SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.... Read more
Affected Products : cybershop- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0418
Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.... Read more
Affected Products : 123_flash_chat_server- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0409
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.... Read more
Affected Products : photoblog- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0404
Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords.... Read more
Affected Products : note-a-day_weblog- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0405
The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/... Read more
Affected Products : libtiff- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0224
Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration fil... Read more
Affected Products : libast- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0403
Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the "... Read more
Affected Products : e-moblog- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0410
SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.... Read more
Affected Products : adodb- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0402
SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.... Read more
Affected Products : zoph- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0407
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the orig... Read more
Affected Products : az_bulletin_board- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0408
rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.... Read more
Affected Products : grid_engine- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0406
search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.... Read more
Affected Products : mybulletinboard- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0321
fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.... Read more
Affected Products : fetchmail- Published: Jan. 24, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0037
ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to b... Read more
Affected Products : linux_kernel- Published: Jan. 23, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0036
ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null... Read more
Affected Products : linux_kernel- Published: Jan. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0378
Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the a... Read more
Affected Products : x-site_manager- Published: Jan. 23, 2006
- Modified: Apr. 03, 2025