Latest CVE Feed
-
7.5
HIGHCVE-2006-0403
Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the "... Read more
Affected Products : e-moblog- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0410
SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.... Read more
Affected Products : adodb- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0402
SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.... Read more
Affected Products : zoph- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0407
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the orig... Read more
Affected Products : az_bulletin_board- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0408
rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.... Read more
Affected Products : grid_engine- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0406
search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.... Read more
Affected Products : mybulletinboard- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0321
fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.... Read more
Affected Products : fetchmail- Published: Jan. 24, 2006
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2006-0037
ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to b... Read more
Affected Products : linux_kernel- Published: Jan. 23, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0036
ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null... Read more
Affected Products : linux_kernel- Published: Jan. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0378
Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the a... Read more
Affected Products : x-site_manager- Published: Jan. 23, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0373
Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely ... Read more
Affected Products : followweb- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0366
Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.... Read more
Affected Products : phpclanwebsite- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0376
The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc m... Read more
- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0359
Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash)... Read more
Affected Products : eyebeam_sip_softphone- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0355
Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.... Read more
Affected Products : homeftp- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0374
Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-syst... Read more
Affected Products : p202s- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0371
Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.... Read more
Affected Products : rcblog- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0369
MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that... Read more
Affected Products : mysql- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0367
Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via ... Read more
Affected Products : call_manager- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0361
Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.... Read more
Affected Products : bit_5_blog- Published: Jan. 22, 2006
- Modified: Apr. 03, 2025