Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2006-1732

    Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) atta... Read more

    Affected Products : firefox thunderbird seamonkey
    • Published: Apr. 14, 2006
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2006-1741

    Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page i... Read more

    • Published: Apr. 14, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1530

    Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to th... Read more

    • Published: Apr. 14, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1788

    Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.... Read more

    Affected Products : document_server
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2006-1784

    PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.... Read more

    Affected Products : sphider
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1551

    Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $method and (2) $args parameters.... Read more

    Affected Products : pajax
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1787

    Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.... Read more

    Affected Products : document_server
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.6

    LOW
    CVE-2006-1786

    Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is n... Read more

    Affected Products : document_server
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-1785

    Adobe Document Server for Reader Extensions 6.0 allows remote authenticated users to inject arbitrary web script via a leading (1) ftp or (2) http URI in the ReaderURL variable in the "Update Download Site" section of ads-readerext. NOTE: it is not clear... Read more

    Affected Products : document_server
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2006-1789

    Directory traversal vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to read arbitrary files via the $className variable.... Read more

    Affected Products : pajax
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2006-1628

    Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system.... Read more

    Affected Products : livecycle_form_manager
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1627

    Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters. NOTE: due to an error during reservatio... Read more

    Affected Products : acrobat_reader document_server
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1778

    Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) blogid parameter in (a) index.php and (b) archive.php, the (2) m and (3) y parameters in archive.php, ... Read more

    Affected Products : simplog
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1776

    PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the s parameter.... Read more

    Affected Products : simplog
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-1779

    Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter.... Read more

    Affected Products : simplog
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2006-1781

    PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and earlier are affected.... Read more

    Affected Products : monster_top_list
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-1780

    The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.... Read more

    Affected Products : solaris sunos
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2006-1772

    debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cleartext database administrator password in the mnogosea... Read more

    Affected Products : debian_linux
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 6.8

    MEDIUM
    CVE-2006-1769

    Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila 9.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the mode parameter in msgReader$1 and (2) the end of the URI in viewDepartment$.... Read more

    Affected Products : manila
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-1770

    Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design & Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admi... Read more

    Affected Products : azdgvote
    • Published: Apr. 13, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 294716 Results