VYPR

CVEs

344,070 total · page 6460 of 6,882

  • CVE-2006-6159Nov 28, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) message or (2) subject parameter.

  • CVE-2006-6160Nov 28, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2006-6161Nov 28, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) uid parameter to (a) inout/status.asp, (b) inout/update.asp, and (c) forgotpass.asp. NOTE: The provenance of…

  • CVE-2006-4181Nov 28, 2006
    risk 0.00cvss epss 0.05

    Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.

  • CVE-2006-6135Nov 28, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) have unknown impact and attack vectors, related to (1) a "Potential security vulnerability" (PK29725) and (2) "Potential security exposure" (PK30831).

  • CVE-2006-6136Nov 28, 2006
    risk 0.00cvss epss 0.02

    IBM WebSphere Application Server 6.1.0 before Fix Pack 3 (6.1.0.3) does not perform EAL4 authentication checks at the proper time during "registering of response operation," which has unknown impact and attack vectors.

  • CVE-2006-6137Nov 28, 2006
    risk 0.03cvss epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the (1) exec parameter to index.php or (2) print parameter to print.php, which is also accessible via the print command to index.php.

  • CVE-2006-6138Nov 28, 2006
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

  • CVE-2006-6139Nov 28, 2006
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in downloadexcel.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the fn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-6140Nov 28, 2006
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and (2) print.php. NOTE: The provenance of this information is unknown; the details are obtained…

  • CVE-2006-6141Nov 28, 2006
    risk 0.00cvss epss 0.04

    Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window.

  • CVE-2006-6130Nov 28, 2006
    risk 0.03cvss epss 0.01

    Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

  • CVE-2006-6131Nov 28, 2006
    risk 0.03cvss epss 0.01

    Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working…

  • CVE-2006-6132Nov 28, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Link Exchange Lite allow remote attackers to execute arbitrary SQL commands via (1) the search engine field to search.asp and (2) psearch parameter to linkslist.asp.

  • CVE-2006-6133Nov 28, 2006
    risk 0.07cvss epss 0.52

    Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary…

  • CVE-2006-6134Nov 28, 2006
    risk 0.03cvss epss 0.41

    Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary…

  • CVE-2006-5896Nov 27, 2006
    risk 0.00cvss epss 0.02

    REMLAB Web Mech Designer 2.0.5 allows remote attackers to obtain the full path of the script via an incorrect Tonnage parameter to calculate.php that triggers a divide-by-zero error, which leaks the path in an error message.

  • CVE-2006-5750Nov 27, 2006
    risk 0.01cvss epss 0.14

    Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the…

  • CVE-2006-6125Nov 27, 2006
    risk 0.04cvss epss 0.14

    Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID.

  • CVE-2006-6126Nov 27, 2006
    risk 0.00cvss epss 0.00

    Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.

  • CVE-2006-6127Nov 27, 2006
    risk 0.00cvss epss 0.00

    Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.

  • CVE-2006-6128Nov 27, 2006
    risk 0.00cvss epss 0.00

    The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed.

  • CVE-2006-6129Nov 27, 2006
    risk 0.03cvss epss 0.01

    Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.

  • CVE-2006-5965Nov 26, 2006
    risk 0.00cvss epss 0.00

    PassGo SSO Plus 2.1.0.32, and probably earlier versions, uses insecure permissions (Everyone/Full Control) for the PassGo Technologies directory, which allows local users to gain privileges by modifying critical programs.

  • CVE-2006-6121Nov 26, 2006
    risk 0.04cvss epss 0.12

    Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.

  • CVE-2006-6122Nov 26, 2006
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in TIN before 1.8.2 have unspecified impact and attack vectors, a different vulnerability than CVE-2006-0804.

  • CVE-2006-6123Nov 26, 2006
    risk 0.00cvss epss 0.01

    Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical…

  • CVE-2006-6124Nov 26, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-5869Nov 26, 2006
    risk 0.00cvss epss 0.02

    pstotext before 1.9 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a file name.

  • CVE-2006-6108Nov 26, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

  • CVE-2006-6109Nov 26, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.

  • CVE-2006-6110Nov 26, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp.

  • CVE-2006-6111Nov 26, 2006
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873.

  • CVE-2006-6115Nov 26, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

  • CVE-2006-6116Nov 26, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.

  • CVE-2006-6117Nov 26, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.

  • CVE-2006-6118Nov 26, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2006-6119Nov 26, 2006
    risk 0.00cvss epss 0.01

    mmgallery 1.55 allows remote attackers to obtain sensitive information via a direct request for thumbs.php, which reveals the installation path in various error messages.

  • CVE-2006-6082Nov 24, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.

  • CVE-2006-6083Nov 24, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.

  • CVE-2006-6084Nov 24, 2006
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2006-6085Nov 24, 2006
    risk 0.00cvss epss 0.01

    Kile before 1.9.3 does not assign a backup file the same permissions as the original file, which might allow local users to obtain sensitive information.

  • CVE-2006-6086Nov 24, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pear_path parameter.

  • CVE-2006-6087Nov 24, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter.

  • CVE-2006-6088Nov 24, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery field,…

  • CVE-2006-6089Nov 24, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) groupname (Group Name), or (3) detail (Message) field.

  • CVE-2006-6090Nov 24, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in BaalAsp forum allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to (a) adminlogin.asp, the (2) name or (3) password parameter to (b) userlogin.asp, or the (3) search parameter to search.asp.

  • CVE-2006-6091Nov 24, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Grim Pirate GrimBB before 2006_11_21 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-6092Nov 24, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in vehiclelistings.asp in 20/20 Auto Gallery allow remote attackers to execute arbitrary SQL commands via the (1) vehicleID, (2) categoryID_list, (3) sale_type, (4) stock_number, (5) manufacturer, (6) model, (7) vehicleID, (8) year, (9)…

  • CVE-2006-6093Nov 24, 2006
    risk 0.03cvss epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.