Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-1983 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 6.4 MEDIUM | N/A |
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family. | |||||
CVE-2006-1984 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference. | |||||
CVE-2006-1985 | 1 Apple | 3 Mac Os X, Mac Os X Server, Safari | 2017-07-19 | 5.1 MEDIUM | N/A |
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function. | |||||
CVE-2006-1986 | 1 Apple | 1 Safari | 2017-07-19 | 7.5 HIGH | N/A |
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl. | |||||
CVE-2006-1987 | 1 Apple | 1 Safari | 2017-07-19 | 7.5 HIGH | N/A |
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible. | |||||
CVE-2006-1988 | 1 Apple | 1 Safari | 2017-07-19 | 5.0 MEDIUM | N/A |
The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE. | |||||
CVE-2006-1989 | 1 Clam Anti-virus | 1 Clamav | 2017-07-19 | 5.1 MEDIUM | N/A |
Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers. | |||||
CVE-2006-1991 | 1 Php | 1 Php | 2017-07-19 | 6.4 MEDIUM | N/A |
The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument. | |||||
CVE-2006-1994 | 1 Dforum | 1 Dforum | 2017-07-19 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php. | |||||
CVE-2006-1997 | 1 Sybase | 1 Pylon Anywhere | 2017-07-19 | 2.1 LOW | N/A |
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors. | |||||
CVE-2006-2000 | 1 Logmethods | 1 Logmethods | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter. | |||||
CVE-2006-2006 | 1 Ivan Zahariev | 1 Izarc | 2017-07-19 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in IZArc Archiver 3.5 beta 3 allow remote attackers to write arbitrary files via a ..\ (dot dot backslash) in a (1) .rar, (2) .tar, (3) .zip, (4) .jar, or (5) .gz archive. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-2007 | 1 Winny | 1 Winny | 2017-07-19 | 7.5 HIGH | N/A |
Heap-based buffer overflow in Winny 2.0 b7.1 and earlier allows remote attackers to execute arbitrary code via long strings to certain commands sent to the file transfer port. | |||||
CVE-2006-2013 | 1 Web-provence | 1 Sl Site | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in page.php in SL_site 1.0 allows remote attackers to execute arbitrary SQL commands via the id_page parameter. NOTE: this issue could be used to produce resultant XSS from an error message. | |||||
CVE-2006-2014 | 1 Web-provence | 1 Sl Site | 2017-07-19 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message. | |||||
CVE-2006-2015 | 1 Web-provence | 1 Sl Site | 2017-07-19 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php. NOTE: other XSS vectors, as reported in the original disclosure, are resultant from other primary vulnerabilities that have separate CVE names. | |||||
CVE-2006-2017 | 1 Dnsmasq | 1 Dnsmasq | 2017-07-19 | 5.0 MEDIUM | N/A |
Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request. | |||||
CVE-2006-2031 | 1 Phpmyadmin | 1 Phpmyadmin | 2017-07-19 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |||||
CVE-2006-2038 | 1 Amplecom | 1 Ampleshop | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in ampleShop 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) RecordID parameter in (a) Customeraddresses_RecordAction.cfm and (b) youraccount.cfm; (2) solus parameter in (c) detail.cfm; and (3) cat parameter in (d) category.cfm. | |||||
CVE-2006-2039 | 1 Ubertec | 1 Help Center Live | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors. |