VYPR

CVEs

344,021 total · page 6496 of 6,881

  • CVE-2006-4118Aug 14, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in GeheimChaos 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Temp_entered_login or (2) Temp_entered_email parameters to (a) gc.php, and in multiple parameters in (b) include/registrieren.php, possibly…

  • CVE-2006-4119Aug 14, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in gc.php in GeheimChaos 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the Temp_entered_password parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-4120Aug 14, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-4121Aug 14, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

  • CVE-2006-4122Aug 14, 2006
    risk 0.03cvss epss 0.03

    Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php.

  • CVE-2006-4123Aug 14, 2006
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the url_index parameter.

  • CVE-2006-4124Aug 14, 2006
    risk 0.00cvss epss 0.00

    The libXm library in LessTif 0.95.0 and earlier allows local users to gain privileges via the DEBUG_FILE environment variable, which is used to create world-writable files when libXm is run from a setuid program.

  • CVE-2006-4125Aug 14, 2006
    risk 0.04cvss epss 0.08

    Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function.

  • CVE-2006-4126Aug 14, 2006
    risk 0.04cvss epss 0.09

    The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference.

  • CVE-2006-4127Aug 14, 2006
    risk 0.00cvss epss 0.02

    Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cmd.user.c, (b)…

  • CVE-2006-4128Aug 14, 2006
    risk 0.00cvss epss 0.06

    Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501,…

  • CVE-2006-4129Aug 14, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter.

  • CVE-2006-4130Aug 14, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path…

  • CVE-2006-4131Aug 14, 2006
    risk 0.04cvss epss 0.08

    Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the…

  • CVE-2006-4132Aug 14, 2006
    risk 0.00cvss epss 0.02

    ArcSoft MMS Composer 1.5.5.6 and possibly earlier, and 2.0.0.13 and possibly earlier, allow remote attackers to cause a denial of service (resource exhaustion and application crash) via WAPPush messages to UDP port UDP 2948.

  • CVE-2006-4133Aug 14, 2006
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via an HTTP request with an ADM:GETLOGFILE command and a long portwatcher argument,…

  • CVE-2006-4134Aug 14, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to cause a denial of service (service shutdown) via certain HTTP requests. NOTE: This information is based upon a vague…

  • CVE-2006-4135Aug 14, 2006
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in cal_config.inc.php in Calendarix 0.7.20060401 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the calpath parameter. NOTE: this issue has been disputed by a third party, who says that the affected…

  • CVE-2006-4136Aug 14, 2006
    risk 0.00cvss epss 0.01

    Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others.

  • CVE-2006-4137Aug 14, 2006
    risk 0.00cvss epss 0.01

    IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command line," and (3) traces.

  • CVE-2006-4138Aug 14, 2006
    risk 0.05cvss epss 0.20

    Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files.

  • CVE-2006-4139Aug 14, 2006
    risk 0.00cvss epss 0.01

    Race condition in Sun Solaris 10 allows attackers to cause a denial of service (system panic) via unspecified vectors related to ifconfig and either netstat or SNMP queries.

  • CVE-2006-4140Aug 14, 2006
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded…

  • CVE-2006-4141Aug 14, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby and (2) sortorder parameters.

  • CVE-2006-4142Aug 14, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter.

  • CVE-2006-4111Aug 14, 2006
    risk 0.00cvss epss 0.02

    Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

  • CVE-2006-4112Aug 14, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or…

  • CVE-2006-4113Aug 14, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.

  • CVE-2006-4114Aug 14, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.

  • CVE-2006-4115Aug 14, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter.

  • CVE-2006-4116Aug 14, 2006
    risk 0.00cvss epss 0.03

    Multiple stack-based buffer overflows in Lhaz before 1.32 allow user-assisted attackers to execute arbitrary code via a long filename in (1) an LHZ archive, when saving the filename during extraction; and (2) an LHZ archive with an invalid CRC checksum, when constructing an…

  • CVE-2006-4117Aug 14, 2006
    risk 0.00cvss epss 0.01

    The squeue_drain function in Sun Solaris 10, possibly only when run on CMT processors, allows remote attackers to cause a denial of service ("bad trap" and system panic) by opening and closing a large number of TCP connections ("heavy TCP/IP loads"). NOTE: the original report…

  • CVE-2006-1168Aug 14, 2006
    risk 0.00cvss epss 0.05

    The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

  • CVE-2006-4102Aug 14, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.

  • CVE-2006-4103Aug 14, 2006
    risk 0.03cvss epss 0.04

    PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.

  • CVE-2006-4104Aug 14, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via "password input."

  • CVE-2006-4105Aug 14, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Fill Threads Database (FTD) 3.7.3 allows remote attackers to inject arbitrary web script or HTML via the (1) search field or (2) an e-mail message.

  • CVE-2006-4106Aug 14, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 allows remote attackers to inject arbitrary web script or HTML via a comment title.

  • CVE-2006-4107Aug 14, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search.

  • CVE-2006-4108Aug 14, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-4109Aug 14, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-4110Aug 14, 2006
    risk 0.06cvss epss 0.37

    Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file…

  • CVE-2006-3813Aug 11, 2006
    risk 0.00cvss epss 0.00

    A regression error in the Perl package for Red Hat Enterprise Linux 4 omits the patch for CVE-2005-0155, which allows local users to overwrite arbitrary files with debugging information.

  • CVE-2006-4019Aug 11, 2006
    risk 0.04cvss epss 0.09

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.

  • CVE-2006-3817Aug 11, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrated by the…

  • CVE-2006-3818Aug 11, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter.

  • CVE-2006-4081Aug 11, 2006
    risk 0.03cvss epss 0.04

    preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.

  • CVE-2006-4082Aug 11, 2006
    risk 0.00cvss epss 0.00

    Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a hardcoded password for the admin account for logins from 127.0.0.1 (localhost), which allows local users to gain privileges.

  • CVE-2006-4083Aug 11, 2006
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in viewevent.php in myWebland myEvent 1.x allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter, a different vector than CVE-2006-4040. NOTE: the provenance of this information is unknown; the…

  • CVE-2006-4084Aug 11, 2006
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in phpAutoMembersArea (phpAMA) before 3.2.4 has unknown impact and attack vectors, related to "a potential security exploit which is critical."