Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-3888 | 1 Aol | 1 Ygp Pic Downloader Activex Control | 2017-07-19 | 7.5 HIGH | N/A |
Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in America Online 9.0 Security Edition, allows remote attackers to execute arbitrary code via a long argument to the SetAlbumName method. | |||||
CVE-2006-3893 | 2 Casio, Newtone | 2 Photo Loader, Imagekit | 2017-07-19 | 10.0 HIGH | N/A |
Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML document. | |||||
CVE-2006-3908 | 1 Gillius Programming | 1 Game Networking Engine | 2017-07-19 | 7.5 HIGH | N/A |
Format string vulnerability in the flush_output function in ConsoleStreambuf.cpp in Game Network Engine (GNE) 0.70 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute code via format string specifiers in unspecified vectors involving output to the gout console. | |||||
CVE-2006-3910 | 1 Microsoft | 1 Ie | 2017-07-19 | 5.0 MEDIUM | N/A |
Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference. | |||||
CVE-2006-3916 | 1 Solucija | 1 Snews | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. | |||||
CVE-2006-3919 | 1 Sd Studio | 1 Sd Studio Cms | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in SD Studio CMS allows remote attackers to execute arbitrary SQL commands via the (1) news_id, (2) tid, and (3) page_id parameters. | |||||
CVE-2006-3921 | 1 Sun | 2 Java System Application Server, Java System Web Server | 2017-07-19 | 4.0 MEDIUM | N/A |
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI. | |||||
CVE-2006-3925 | 1 Interactual Technologies | 1 Interactual Player | 2017-07-19 | 6.4 MEDIUM | N/A |
Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Files method. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-3926 | 1 Php Pro Bid | 1 Php Pro Bid | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php. | |||||
CVE-2006-3927 | 1 Php Pro Bid | 1 Php Pro Bid | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the advsrc parameter. | |||||
CVE-2006-3932 | 1 Gonafish | 1 Linkscaffe | 2017-07-19 | 5.1 MEDIUM | N/A |
SQL injection vulnerability in links.php in Gonafish LinksCaffe 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-3941 | 1 Sun | 1 N1 Grid Engine | 2017-07-19 | 7.5 HIGH | N/A |
Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate. | |||||
CVE-2006-3943 | 1 Microsoft | 1 Ie | 2017-07-19 | 2.6 LOW | N/A |
Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties. | |||||
CVE-2006-3944 | 1 Microsoft | 1 Ie | 2017-07-19 | 5.0 MEDIUM | N/A |
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference. | |||||
CVE-2006-3946 | 1 Apple | 2 Mac Os X, Safari | 2017-07-19 | 7.5 HIGH | N/A |
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally reported for the KHTMLParser::popOneBlock function in Apple Safari 2.0.4 using Javascript that changes document.body.innerHTML within a DIV tag. | |||||
CVE-2006-3950 | 1 X-scripts | 1 X-statistics | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | |||||
CVE-2006-3952 | 1 Efs Software | 1 Efs Ftp Server | 2017-07-19 | 7.5 HIGH | N/A |
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-3958 | 1 Pkr Internet | 1 Taskjitsu | 2017-07-19 | 4.3 MEDIUM | N/A |
Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end Category Editor system, and (4) "Pages that display task status, email addresses, URL, customer, and project information." | |||||
CVE-2006-3959 | 1 X-scripts | 1 X-statistics | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter. | |||||
CVE-2006-3968 | 1 Sun | 1 Solaris | 2017-07-19 | 5.0 MEDIUM | N/A |
The crypto provider in Sun Solaris 10 3/05 HW2 without patch 121236-01, when running on Sun Fire T2000 platforms, incorrectly verifies a DSA signature, which might prevent applications from detecting that the data has been modified. |