Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-3383 | 1 Mads | 1 Mads | 2017-07-19 | 5.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in mAds 1.0 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover within a URL. NOTE: the provenance of this information is unknown; the details are obtained solely from third party reports. | |||||
CVE-2006-3391 | 1 Imbc | 1 Imbccontents Activex Control | 2017-07-19 | 5.1 MEDIUM | N/A |
The Execute function in iMBCContents ActiveX Control before 2.0.0.59 allows remote attackers to execute arbitrary files via the file URI handler. | |||||
CVE-2006-3393 | 1 Electronic Arts | 1 Nascar Racing | 2017-07-19 | 7.8 HIGH | N/A |
Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket. | |||||
CVE-2006-3395 | 1 Webdesignhq | 1 Sitebuilder-fx | 2017-07-19 | 5.1 MEDIUM | N/A |
PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter. | |||||
CVE-2006-3397 | 1 Pkr Internet | 1 Taskjitsu | 2017-07-19 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via multiple unspecified parameters, including the (1) title and (2) description parameters when creating a task. | |||||
CVE-2006-3402 | 1 Virtuastore | 1 Virtuastore | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the password parameter when logging in. | |||||
CVE-2006-3407 | 1 Tor | 1 Tor | 2017-07-19 | 6.4 MEDIUM | N/A |
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters. | |||||
CVE-2006-3408 | 1 Tor | 1 Tor | 2017-07-19 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors. | |||||
CVE-2006-3409 | 1 Tor | 1 Tor | 2017-07-19 | 7.5 HIGH | N/A |
Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists. | |||||
CVE-2006-3410 | 1 Tor | 1 Tor | 2017-07-19 | 5.0 MEDIUM | N/A |
Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unspecified statistical attacks. | |||||
CVE-2006-3420 | 1 Mybulletinboard | 1 Mybulletinboard | 2017-07-19 | 7.5 HIGH | N/A |
Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-3424 | 1 Webex Communications | 1 Webex Downloader Activex Control | 2017-07-19 | 7.5 HIGH | N/A |
Multiple buffer overflows in WebEx Downloader ActiveX Control, possibly in versions before November 2005, allow remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2006-3452 | 1 Adobe | 2 Acrobat, Acrobat Reader | 2017-07-19 | 4.6 MEDIUM | N/A |
Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure file and directory permissions, which allows local users to gain privileges by overwriting program files. | |||||
CVE-2006-3453 | 1 Adobe | 1 Acrobat | 2017-07-19 | 5.1 MEDIUM | N/A |
Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers to execute arbitrary code via unknown vectors in a document that triggers the overflow when it is distilled to PDF. | |||||
CVE-2006-3456 | 1 Symantec | 3 Norton Antivirus, Norton Internet Security, Norton System Works | 2017-07-19 | 8.5 HIGH | N/A |
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors related to content on a web site, and place Internet Explorer into a "defunct state" in which remote attackers can execute arbitrary code in addition to other Symantec ActiveX controls, regardless of whether they are marked safe for scripting. NOTE: this CVE was inadvertently used for an E-mail Auto-Protect issue, but that issue has been assigned CVE-2007-3771. | |||||
CVE-2006-3470 | 1 Dell | 1 Openmanage Cd | 2017-07-19 | 7.5 HIGH | N/A |
The Dell Openmanage CD launches X11 and SSH daemons that do not require authentication, which allows remote attackers to gain privileges. | |||||
CVE-2006-3471 | 1 Microsoft | 1 Ie | 2017-07-19 | 5.0 MEDIUM | N/A |
Microsoft Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) via a table with a frameset as a child, which triggers a null dereference, as demonstrated using the appendChild method. | |||||
CVE-2006-3473 | 1 Drupal | 1 Form Mail Module | 2017-07-19 | 7.5 HIGH | N/A |
CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending spam messages, a different issue than CVE-2006-1225. | |||||
CVE-2006-3477 | 1 Stalker | 1 Communigate | 2017-07-19 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the POP service in Stalker CommuniGate Pro 5.1c1 and earlier allows remote attackers to cause a denial of service (server crash) via unspecified vectors involving opening an empty inbox. | |||||
CVE-2006-3479 | 1 Nuked-klan | 1 Nuked-klan | 2017-07-19 | 5.0 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in the del_block function in modules/Admin/block.php in Nuked-Klan 1.7.5 and earlier and 1.7 SP4.2 allows remote attackers to delete arbitrary "blocks" via a link with a modified bid parameter in a del_block op on the block page in index.php. |