VYPR

CVEs

344,040 total · page 6468 of 6,881

  • CVE-2006-5652Nov 3, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this…

  • CVE-2006-5653Nov 3, 2006
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due…

  • CVE-2006-5654Nov 3, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified…

  • CVE-2006-5655Nov 3, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2006-5656Nov 3, 2006
    risk 0.00cvss epss 0.01

    Memory leak in the push_align function in src/util.c in Vilistextum before 2.6.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the tmp_align variable. NOTE: it is not clear whether this is a vulnerability, due to…

  • CVE-2006-5657Nov 3, 2006
    risk 0.00cvss epss 0.02

    Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors.

  • CVE-2006-5658Nov 3, 2006
    risk 0.00cvss epss 0.02

    BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3)…

  • CVE-2006-5659Nov 3, 2006
    risk 0.00cvss epss 0.00

    PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2006-5660Nov 3, 2006
    risk 0.00cvss epss 0.04

    Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.

  • CVE-2006-5661Nov 3, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

  • CVE-2006-5662Nov 3, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."

  • CVE-2006-4517Nov 1, 2006
    risk 0.00cvss epss 0.03

    Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference.

  • CVE-2006-4704Nov 1, 2006
    risk 0.06cvss epss 0.43

    Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous…

  • CVE-2006-4839Nov 1, 2006
    risk 0.00cvss epss 0.03

    Sophos Anti-Virus 5.1 allows remote attackers to cause a denial of service (memory consumption) via a file that is compressed with Petite and contains a large number of sections.

  • CVE-2006-5645Nov 1, 2006
    risk 0.04cvss epss 0.17

    Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive…

  • CVE-2006-5646Nov 1, 2006
    risk 0.04cvss epss 0.17

    Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file…

  • CVE-2006-5647Nov 1, 2006
    risk 0.05cvss epss 0.21

    Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name…

  • CVE-2006-5634Nov 1, 2006
    risk 0.03cvss epss 0.06

    Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in…

  • CVE-2006-5635Nov 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.

  • CVE-2006-5636Nov 1, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.

  • CVE-2006-5637Nov 1, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.

  • CVE-2006-5638Nov 1, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.

  • CVE-2006-5639Nov 1, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the random number generator in OpenWBEM (Web Based Enterprise Management) 3.2.0 allows attackers to gain privileges via vectors related to "local or HTTP Digest authentication."

  • CVE-2006-5640Nov 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

  • CVE-2006-5641Nov 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.

  • CVE-2006-5642Nov 1, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in NmnLogger 1.0.0 and earlier has unknown impact and attack vectors related to configuration of mesasge drivers.

  • CVE-2006-5643Nov 1, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter.

  • CVE-2006-5629Oct 31, 2006
    risk 0.03cvss epss 0.03

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present…

  • CVE-2006-5630Oct 31, 2006
    risk 0.00cvss epss 0.02

    Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID parameter in a disableforum action in DisableForum.asp and (2) create an arbitrary forum virtual directory via an empty ForumID…

  • CVE-2006-5631Oct 31, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via arbitrary query strings when the action parameter is not "1", as demonstrated using script in the action parameter, a different…

  • CVE-2006-5632MedOct 31, 2006
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are…

  • CVE-2006-5633Oct 31, 2006
    risk 0.04cvss epss 0.07

    Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a…

  • CVE-2006-5620Oct 31, 2006
    risk 0.03cvss epss 0.04

    PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a different vector than…

  • CVE-2006-5621Oct 31, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.

  • CVE-2006-5622Oct 31, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.

  • CVE-2006-5623Oct 31, 2006
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.

  • CVE-2006-5624Oct 31, 2006
    risk 0.03cvss epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of this information is…

  • CVE-2006-5625Oct 31, 2006
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.

  • CVE-2006-5626Oct 31, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as…

  • CVE-2006-5627Oct 31, 2006
    risk 0.04cvss epss 0.10

    Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/include/; (4)…

  • CVE-2006-5628Oct 31, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in login.asp in UNISOR Content Management System (CMS) allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass fields.

  • CVE-2006-4248Oct 31, 2006
    risk 0.00cvss epss 0.00

    thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.

  • CVE-2006-5606Oct 31, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.

  • CVE-2006-5619Oct 31, 2006
    risk 0.00cvss epss 0.00

    The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabels.

  • CVE-2006-5612Oct 31, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the aide parameter.

  • CVE-2006-5613Oct 31, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter

  • CVE-2006-5614Oct 31, 2006
    risk 0.09cvss epss 0.79

    Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.

  • CVE-2006-5615Oct 31, 2006
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.

  • CVE-2006-5616Oct 31, 2006
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.

  • CVE-2006-5617Oct 31, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter.