Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-4832 | 1 Oracle | 1 Oracle10g | 2017-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197. | |||||
CVE-2005-4848 | 1 Rim | 1 Blackberry Enterprise Server | 2017-07-28 | 7.5 HIGH | N/A |
Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier before 20050607 might allow remote attackers to execute arbitrary code via certain data packets. | |||||
CVE-2005-4863 | 1 Ibm | 1 Db2 Universal Database | 2017-07-28 | 7.2 HIGH | N/A |
Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter. | |||||
CVE-2005-4864 | 1 Ibm | 1 Db2 Universal Database | 2017-07-28 | 7.2 HIGH | N/A |
Stack-based buffer overflow in libdb2.so in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long DB2LPORT environment variable. | |||||
CVE-2005-4865 | 1 Ibm | 1 Db2 Universal Database | 2017-07-28 | 10.0 HIGH | N/A |
Stack-based buffer overflow in call in IBM DB2 7.x and 8.1 allows remote attackers to execute arbitrary code via a long libname. | |||||
CVE-2005-4866 | 1 Ibm | 1 Db2 Universal Database | 2017-07-28 | 6.8 MEDIUM | N/A |
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.zip version, which causes a null terminator to be removed and leads to the overflow. | |||||
CVE-2005-4867 | 1 Ibm | 1 Db2 Universal Database | 2017-07-28 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter. | |||||
CVE-2005-4869 | 1 Ibm | 1 Db2 | 2017-07-28 | 2.1 LOW | N/A |
The (1) to_char and (2) to_date function in IBM DB2 8.1 allows local users to cause a denial of service (application crash) via an empty string in the second parameter, which causes a null pointer dereference. | |||||
CVE-2005-4870 | 1 Ibm | 1 Db2 | 2017-07-28 | 4.3 MEDIUM | N/A |
Stack-based buffer overflows in the (1) xmlvarcharfromfile, (2) xmlclobfromfile, (3) xmlfilefromvarchar, and (4) xmlfilefromclob function calls in IBM DB2 8.1 allow remote attackers to execute arbitrary code via a 94-byte second argument, which causes the return address to be overwritten with a pointer to the argument. | |||||
CVE-2005-4871 | 1 Ibm | 1 Db2 | 2017-07-28 | 4.3 MEDIUM | N/A |
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4) XMLClobFromFile. | |||||
CVE-2006-6122 | 1 Tin | 1 Tin | 2017-07-28 | 7.5 HIGH | N/A |
Multiple buffer overflows in TIN before 1.8.2 have unspecified impact and attack vectors, a different vulnerability than CVE-2006-0804. | |||||
CVE-2006-6123 | 1 Coppermine | 1 Coppermine Photo Gallery | 2017-07-28 | 2.6 LOW | N/A |
Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected. | |||||
CVE-2006-6124 | 1 Biba Software | 1 Seleniumserver Web Server | 2017-07-28 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-6126 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-28 | 2.1 LOW | N/A |
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure. | |||||
CVE-2006-6127 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-28 | 2.1 LOW | N/A |
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent. | |||||
CVE-2006-6128 | 1 Linux | 1 Linux Kernel | 2017-07-28 | 2.1 LOW | N/A |
The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed. | |||||
CVE-2006-6129 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-28 | 4.6 MEDIUM | N/A |
Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption. | |||||
CVE-2006-6130 | 1 Apple | 1 Mac Os X | 2017-07-28 | 4.9 MEDIUM | N/A |
Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket. | |||||
CVE-2006-6145 | 1 Cryptocard | 1 Crypto-server | 2017-07-28 | 2.1 LOW | N/A |
CRYPTOCard CRYPTO-Server before 6.4.56 stores LDAP credentials in plaintext in UninstallerData\installvariables.properties, which has insecure permissions and allows local users to obtain the credentials. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-6155 | 1 Hscripts | 1 Hiox Star Rating System Script | 2017-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in addrating.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ipadd or (2) url parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. |