Latest CVE Feed
-
7.8
HIGHCVE-2006-1090
register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.... Read more
Affected Products : punbb- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-1091
Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors.... Read more
Affected Products : kaspersky_anti-virus- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0742
The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled with certain versions of gcc, has the "noreturn" attribute set, which allows local users to cause a denial of service by causing user ... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1101
The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrate... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1092
Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to al... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1105
Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the vendor has disputed some issues from the original disclosure, but due t... Read more
Affected Products : pixelpost- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1098
Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher... Read more
Affected Products : nz_ecommerce- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1112
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.... Read more
Affected Products : aztek_forum- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1075
Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remote attackers to execute arbitrary code via format string specifiers in (1) a nickname, (2) a dedicated server name, or (3) a mapname in ... Read more
Affected Products : liero_xtreme- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1074
Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or hang) via a long argument to the connect command.... Read more
Affected Products : liero_xtreme- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1083
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other pa... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-1087
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not f... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-1088
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1082
Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the... Read more
Affected Products : phparcadescript- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-1079
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is nor... Read more
Affected Products : thttpd- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0746
Certain patches for kpdf do not include all relevant patches from xpdf that were associated with CVE-2005-3627, which allows context-dependent attackers to exploit vulnerabilities that were present in CVE-2005-3627.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1076
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.... Read more
Affected Products : invision_power_board- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1085
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the spe... Read more
Affected Products : php-stats- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-1081
SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.... Read more
Affected Products : pluggedout_nexus- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1080
Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.... Read more
Affected Products : game-panel- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025