Latest CVE Feed
-
7.8
HIGHCVE-2006-0021
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via an IGMP packet with an invalid IP option, aka the "IGMP v3 DoS Vulnerability."... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2006-0013
Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-200... Read more
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0677
telnetd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2 allows remote unauthenticated attackers to cause a denial of service (server crash) via unknown vectors that trigger a null dereference.... Read more
Affected Products : heimdal- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0676
Cross-site scripting (XSS) vulnerability in header.php in PHP-Nuke 6.0 to 7.8 allows remote attackers to inject arbitrary web script or HTML via the pagetitle parameter.... Read more
Affected Products : php-nuke- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0672
Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors.... Read more
Affected Products : psc_1210_all-in-one- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0668
SQL injection vulnerability in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in message.php in the espace_membre module. NOTE: the provenance of this information is unknown; the details... Read more
Affected Products : pwsphp- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0669
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that ... Read more
Affected Products : gas_forum_light- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0670
Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.... Read more
Affected Products : hcidump- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0674
Buffer overflow in the arp command of IBM AIX 5.3 L, 5.3, 5.2.2, 5.2 L, and 5.2 allows local users to cause a denial of service (crash) via a long iftype argument.... Read more
Affected Products : aix- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0671
Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0673
Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.... Read more
Affected Products : magic_calendar_lite- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0675
Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : siteframe- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0662
Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser.... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0663
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"... Read more
- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0598
Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.... Read more
Affected Products : elog_web_logbook- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0599
The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.... Read more
Affected Products : elog_web_logbook- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0653
Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter.... Read more
Affected Products : phpht_topsites- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0649
Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : dataparksearch- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0658
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Confi... Read more
Affected Products : fckeditor- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0660
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbi... Read more
Affected Products : farsinews- Published: Feb. 13, 2006
- Modified: Apr. 03, 2025