Latest CVE Feed
-
7.5
HIGHCVE-2006-0337
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote... Read more
- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0339
Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.... Read more
Affected Products : bitcomet- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2006-0344
Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.... Read more
Affected Products : filecopa- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2006-0342
RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".... Read more
Affected Products : mailsite- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2006-0340
Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and net... Read more
Affected Products : ios- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0328
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.... Read more
Affected Products : tftpd32- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0329
SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : hitsenser_data_mart_server- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0334
Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only pub... Read more
Affected Products : my_amazon_store_manager- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0330
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).... Read more
Affected Products : gallery- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2006-0331
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : change_passwd- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0335
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HT... Read more
Affected Products : winroute_firewall- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0325
Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands vi... Read more
Affected Products : etomite- Published: Jan. 20, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0019
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.... Read more
Affected Products : kde- Published: Jan. 20, 2006
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2006-0045
crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.... Read more
Affected Products : dungeon_crawl- Published: Jan. 20, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0324
SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.... Read more
Affected Products : webspotblogging- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2006-0322
Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."... Read more
Affected Products : mediawiki- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0313
Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.... Read more
Affected Products : pdfdirectory- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2006-0318
SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.... Read more
Affected Products : blogphp- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2006-0315
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and p... Read more
Affected Products : ezdatabase- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0226
Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.... Read more
Affected Products : freebsd- Published: Jan. 19, 2006
- Modified: Apr. 03, 2025