Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-2203 | 1 Kerio | 1 Kerio Mailserver | 2017-07-19 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of attachment filter." | |||||
CVE-2006-2206 | 1 Ultravnc | 1 Ultravnc | 2017-07-19 | 10.0 HIGH | N/A |
The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting passwords. | |||||
CVE-2006-2208 | 1 Planetluc | 1 Mynews | 2017-07-19 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters. | |||||
CVE-2006-2209 | 1 Php Arena | 1 Pacheckbook | 2017-07-19 | 6.4 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |||||
CVE-2006-2213 | 1 Hostapd | 1 Hostapd | 2017-07-19 | 5.0 MEDIUM | N/A |
Hostapd 0.3.7-2 allows remote attackers to cause a denial of service (segmentation fault) via an unspecified value in the key_data_length field of an EAPoL frame. | |||||
CVE-2006-2214 | 1 4images | 1 Image Gallery Management System | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2. | |||||
CVE-2006-2219 | 1 Phpbb Group | 1 Phpbb | 2017-07-19 | 5.0 MEDIUM | N/A |
phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message. | |||||
CVE-2006-2220 | 1 Phpbb | 1 Phpbb | 2017-07-19 | 5.0 MEDIUM | N/A |
phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message. | |||||
CVE-2006-2238 | 1 Apple | 1 Quicktime | 2017-07-19 | 7.5 HIGH | N/A |
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue. | |||||
CVE-2006-2239 | 1 Tuomas Airaksinen | 1 Newsadmin | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows remote attackers to execute arbitrary SQL commands via the nid parameter. | |||||
CVE-2006-2240 | 1 Fujitsu | 4 Netshelter Fw, Netshelter Fw-l, Netshelter Fw-m and 1 more | 2017-07-19 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the (1) web cache or (2) web proxy in Fujitsu NetShelter/FW allows remote attackers to cause a denial of service (device unresponsiveness) via certain DNS packets, as demonstrated by the OUSPG PROTOS DNS test suite. | |||||
CVE-2006-2243 | 1 Web4future | 1 News Portal | 2017-07-19 | 5.8 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection. | |||||
CVE-2006-2244 | 1 Web4future | 1 News Portal | 2017-07-19 | 6.4 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php. | |||||
CVE-2006-2245 | 1 Phpbb Group | 1 Phpbb-auction | 2017-07-19 | 6.8 MEDIUM | N/A |
PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |||||
CVE-2006-2248 | 1 Northern Solutions | 1 Xeneo Web Server | 2017-07-19 | 5.0 MEDIUM | N/A |
Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension. | |||||
CVE-2006-2251 | 1 Invision Power Services | 1 Invision Community Blog | 2017-07-19 | 6.4 MEDIUM | N/A |
SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter. | |||||
CVE-2006-2254 | 1 Intervations | 1 Filecopa | 2017-07-19 | 5.0 MEDIUM | N/A |
Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters. | |||||
CVE-2006-2255 | 1 Creative Software | 1 Community Portal | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php. | |||||
CVE-2006-2257 | 1 Faktorystudios | 1 Easyevent | 2017-07-19 | 5.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 allows remote attackers to inject arbitrary web script or HTML via the curr_year parameter. | |||||
CVE-2006-2258 | 1 Maxxcode | 1 Maxxschedule | 2017-07-19 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter. |