Latest CVE Feed
-
1.7
LOWCVE-2006-0956
nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server.... Read more
Affected Products : nufw_firewall- Published: Mar. 02, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0384
automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".... Read more
- Published: Mar. 02, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0383
IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".... Read more
- Published: Mar. 02, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0946
Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.... Read more
Affected Products : speedtouch- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0939
SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.... Read more
Affected Products : dci-taskeen- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0943
SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.... Read more
Affected Products : pwsphp- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0940
Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.... Read more
Affected Products : shoutlive- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0942
SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.... Read more
Affected Products : pwsphp- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0944
Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.... Read more
Affected Products : weblog- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0945
PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.... Read more
Affected Products : weblog- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0941
Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.... Read more
Affected Products : shoutlive- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0947
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be ... Read more
Affected Products : speedtouch- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0938
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.... Read more
Affected Products : ez_publish- Published: Mar. 01, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0910
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_k... Read more
Affected Products : invision_power_board- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0918
Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.... Read more
Affected Products : the_bat- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0927
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slidesh... Read more
- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2006-0914
Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.... Read more
Affected Products : bugzilla- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0923
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.... Read more
Affected Products : myphpnuke- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0930
Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.... Read more
Affected Products : argosoft_mail_server- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0937
U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.... Read more
Affected Products : mailgust- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025