Latest CVE Feed
-
6.8
MEDIUMCVE-2006-1660
Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. NOTE: the provenance of this information is unknown; the details are obtained from third... Read more
Affected Products : image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1673
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.... Read more
Affected Products : vbug_tracker- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1658
Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T. 1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.... Read more
Affected Products : n.t.- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1667
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $pro... Read more
Affected Products : crafty_syntax_image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1668
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullima... Read more
Affected Products : crafty_syntax_image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1664
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, allows remote attackers to execute arbitrary code via a crafted MPEG stream.... Read more
Affected Products : xine-lib- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-1659
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id... Read more
Affected Products : image_gallery- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1630
The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."... Read more
Affected Products : clamav- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1629
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.... Read more
- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1615
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code. NOTE: as of 20060410, it is unclear whether this is a vulnerability, as there is some evidence tha... Read more
Affected Products : clamav- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2006-1614
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.... Read more
Affected Products : clamav- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1647
An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes ... Read more
Affected Products : synchroneyes- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1636
PHP remote file inclusion vulnerability in get_header.php in VWar 1.5.0 R12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter. NOTE: this is a different vulnerability than CVE-2006-1503.... Read more
Affected Products : virtual_war- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1637
Multiple cross-site scripting (XSS) vulnerabilities in aWebBB 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) tname or (2) fpost parameters to (a) post.php; (3) fullname, (4) emailadd, (5) country, (6) sig, or (7) otherav par... Read more
Affected Products : awebbb- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1650
Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application... Read more
Affected Products : firefox- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2006-1645
Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitrary web script or HTML and gain leverage to execute arbitrary PHP code via the User-Agent HTTP header, wh... Read more
Affected Products : reloadcms- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-1655
Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. NOTE: this issue might be related to CVE-2004-0991, but it is not... Read more
Affected Products : mpg123- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1640
Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : czarnews- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
9.0
HIGHCVE-2006-1652
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port ... Read more
- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1656
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.... Read more
Affected Products : util-vserver- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025