Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-4442 | 1 Clemens Wacha | 1 Php Iaddressbook | 2011-03-07 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.95 allows remote attackers to inject arbitrary web script or HTML via the cat_name parameter, related to adding a category. (categories field). NOTE: some details are obtained from third party information. | |||||
CVE-2006-4447 | 1 X.org | 9 Emu-linux-x87-xlibs, X11r6, X11r7 and 6 more | 2011-03-07 | 7.2 HIGH | N/A |
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit. | |||||
CVE-2006-4451 | 1 Cj Design | 1 Cj Tag Board | 2011-03-07 | 7.5 HIGH | N/A |
Direct static code injection vulnerability in CJ Tag Board 3.0 allows remote attackers to execute arbitrary PHP code via the (1) User-Agent HTTP header in tag.php, which is executed by all.php, and (2) the banned parameter in admin_index.php. | |||||
CVE-2006-4457 | 1 Phpecard | 1 Phpecard | 2011-03-07 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in index.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-3615 | 1 Phorum | 1 Phorum | 2011-03-07 | 5.1 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in Phorum 5.1.14, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via unspecified vectors related to an uninitialized variable. | |||||
CVE-2006-3667 | 1 Sybase | 1 Financial Fusion Consumer Banking Solution | 2011-03-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking Suite versions before 20060706 has unknown impact and remote attack vectors. | |||||
CVE-2006-3671 | 1 Hyper Estraier | 1 Hyper Estraier | 2011-03-07 | 7.5 HIGH | N/A |
Cross-site request forgery (CSRF) vulnerability in the communicate function in estmaster.c for Hyper Estraier before 1.3.3 allows remote attackers to perform unauthorized actions as other users via unknown vectors. | |||||
CVE-2006-3686 | 1 Hp | 1 Openvms | 2011-03-07 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in [SYSEXE]SMPUTIL.EXE in HP OpenVMS 7.3-2 allows local users and "remote users" to cause a denial of service (crash). | |||||
CVE-2006-3779 | 1 Citrix | 3 Metaframe, Metaframe Presentation Server, Presentation Server | 2011-03-07 | 6.5 MEDIUM | N/A |
Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an insecure ACL, which allows remote authenticated users to gain privileges. | |||||
CVE-2006-3816 | 1 Krusader | 1 Krusader | 2011-03-07 | 7.5 HIGH | N/A |
Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote connections in cleartext in the bookmark file (krbookmarks.xml), which allows attackers to steal passwords by obtaining the file. | |||||
CVE-2006-3822 | 1 Geodesicsolutions | 1 Geoauctions Enterprise | 2011-03-07 | 5.1 MEDIUM | N/A |
SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter. | |||||
CVE-2006-3892 | 1 Emc | 1 Networker | 2011-03-07 | 10.0 HIGH | N/A |
The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands. | |||||
CVE-2006-3896 | 1 Neoscale Systems | 1 Cryptostor Tape 700 | 2011-03-07 | 4.9 MEDIUM | N/A |
The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX. | |||||
CVE-2006-3902 | 1 Phpfaber | 1 Topsites | 2011-03-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites 2.0.9 allows remote attackers to inject arbitrary web script or HTML via the i_cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-3992 | 1 Intel | 2 2200bg Proset Wireless, 2915abg Proset Wireless | 2011-03-07 | 5.1 MEDIUM | N/A |
Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption. | |||||
CVE-2006-3232 | 1 Ibm | 1 Websphere Application Server | 2011-03-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used." | |||||
CVE-2006-3336 | 1 Twiki | 1 Twiki | 2011-03-07 | 4.0 MEDIUM | N/A |
TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory. | |||||
CVE-2006-3380 | 1 Freestyle | 1 Freestyle Wiki | 2011-03-07 | 5.0 MEDIUM | N/A |
Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case. | |||||
CVE-2006-3398 | 1 Pkr Internet | 1 Taskjitsu | 2011-03-07 | 5.0 MEDIUM | N/A |
The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remote attackers to obtain sensitive information from the (1) Category Editor and (2) User Information editor. | |||||
CVE-2006-3482 | 1 Phpmaillist | 1 Phpmaillist | 2011-03-07 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in maillist.php in PHPMailList 1.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter. |