Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-0128 | 1 Rockliffe | 1 Mailsite | 2017-07-19 | 10.0 HIGH | N/A |
Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors. | |||||
CVE-2006-0139 | 1 Pd9 Software | 1 Megabbs | 2017-07-19 | 5.0 MEDIUM | N/A |
The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter. | |||||
CVE-2006-0141 | 1 Eudora | 1 Internet Mail Server | 2017-07-19 | 5.0 MEDIUM | N/A |
Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file. | |||||
CVE-2006-0142 | 1 Andromeda Software | 1 Andromeda | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in andromeda.php in Andromeda 1.9.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the s parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-0148 | 1 Netsarang | 1 Xlpd | 2017-07-19 | 5.0 MEDIUM | N/A |
NetSarang Xlpd 2.1 allows remote attackers to cause a denial of service (crash) via a large number of connections from the same IP address. | |||||
CVE-2006-0152 | 1 Phpchamber | 1 Phpchamber | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2006-0159 | 1 Javier Suarez Sanz | 1 Foro Domus | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information. | |||||
CVE-2006-0160 | 1 Venom Board | 1 Venom Board | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3. | |||||
CVE-2006-0162 | 1 Clam Anti-virus | 1 Clamav | 2017-07-19 | 7.5 HIGH | N/A |
Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files. | |||||
CVE-2006-0163 | 1 Francisco Burzi | 1 Php-nuke Ev | 2017-07-19 | 7.5 HIGH | N/A |
SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field. NOTE: This is a different vulnerability than CVE-2005-3792. | |||||
CVE-2006-0164 | 1 Woah-projekt | 1 Phgstats | 2017-07-19 | 7.5 HIGH | N/A |
phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable. | |||||
CVE-2006-0165 | 1 Plain Black | 1 Webgui | 2017-07-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form. | |||||
CVE-2006-0166 | 1 Symantec | 1 Norton System Works | 2017-07-19 | 7.5 HIGH | N/A |
Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products. | |||||
CVE-2006-0177 | 1 Cray | 1 Unicos | 2017-07-19 | 7.2 HIGH | N/A |
Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line. | |||||
CVE-2006-0178 | 1 Cray | 1 Unicos | 2017-07-19 | 7.2 HIGH | N/A |
Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability. | |||||
CVE-2006-0181 | 1 Cisco | 1 Cs-mars | 2017-07-19 | 7.2 HIGH | N/A |
Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command. | |||||
CVE-2006-0184 | 1 Mainenet Enterprises | 1 Asptopsites | 2017-07-19 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp. | |||||
CVE-2006-0206 | 1 Light Weight Calendar | 1 Light Weight Calendar | 2017-07-19 | 7.5 HIGH | N/A |
Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php. | |||||
CVE-2006-0213 | 1 Kolab | 1 Kolab Groupware Server | 2017-07-19 | 4.6 MEDIUM | N/A |
Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges. | |||||
CVE-2006-0214 | 1 Indexcor | 1 Ezdatabase | 2017-07-19 | 7.5 HIGH | N/A |
Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls. |