VYPR

CVEs

343,710 total · page 6531 of 6,875

  • CVE-2006-2028Apr 26, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. NOTE: this issue might be resultant from directory traversal.

  • CVE-2006-2029Apr 26, 2006
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter…

  • CVE-2006-2030Apr 26, 2006
    risk 0.00cvss epss 0.01

    The Allied Telesyn AT-9724TS switch allows remote attackers to cause a denial of service via a large amount of UDP data to the switch, which leads to unstable operation and possibly failure of the management interface or routing.

  • CVE-2006-2031Apr 26, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin 2.8.0.3, 2.8.0.2, 2.8.1-dev, and 2.9.0-dev allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

  • CVE-2006-2032Apr 26, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.

  • CVE-2006-2033Apr 26, 2006
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter. NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue.

  • CVE-2006-2034Apr 26, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php.

  • CVE-2006-2035Apr 26, 2006
    risk 0.00cvss epss 0.00

    Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a "/?" sequence to a URL.

  • CVE-2006-2036Apr 26, 2006
    risk 0.00cvss epss 0.00

    iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring.

  • CVE-2006-2024Apr 25, 2006
    risk 0.04cvss epss 0.09

    Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c)…

  • CVE-2006-2025Apr 25, 2006
    risk 0.04cvss epss 0.11

    Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.

  • CVE-2006-2026Apr 25, 2006
    risk 0.04cvss epss 0.10

    Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."

  • CVE-2006-1863Apr 25, 2006
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864.

  • CVE-2006-2020Apr 25, 2006
    risk 0.04cvss epss 0.08

    Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.

  • CVE-2006-2021Apr 25, 2006
    risk 0.00cvss epss 0.02

    Absolute path traversal vulnerability in recordings/misc/audio.php in the Asterisk Recording Interface (ARI) web interface in Asterisk@Home before 2.8 allows remote attackers to read arbitrary MP3, WAV, and GSM files via a full pathname in the recording parameter. NOTE: this…

  • CVE-2006-2022Apr 25, 2006
    risk 0.04cvss epss 0.15

    Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL.

  • CVE-2006-2023Apr 25, 2006
    risk 0.00cvss epss 0.02

    Integer overflow in the RTSP_msg_len function in rtsp/RTSP_msg_len.c in Fenice 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a large HTTP Content-Length value, which leads to an invalid memory access.

  • CVE-2006-2019Apr 25, 2006
    risk 0.03cvss epss 0.04

    Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.

  • CVE-2006-1513Apr 25, 2006
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in abc2ps before 1.3.3 allow user-assisted attackers to execute arbitrary code via crafted ABC music files.

  • CVE-2006-1932Apr 25, 2006
    risk 0.00cvss epss 0.03

    Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.

  • CVE-2006-1933Apr 25, 2006
    risk 0.00cvss epss 0.04

    Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (large or infinite loops) viarafted packets to the (1) UMA and (2) BER dissectors.

  • CVE-2006-1934Apr 25, 2006
    risk 0.00cvss epss 0.05

    Multiple buffer overflows in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) ALCAP dissector, (2) Network Instruments file code, or (3) NetXray/Windows Sniffer file code.

  • CVE-2006-1935Apr 25, 2006
    risk 0.00cvss epss 0.05

    Buffer overflow in Ethereal 0.9.15 up to 0.10.14 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the COPS dissector.

  • CVE-2006-1936Apr 25, 2006
    risk 0.00cvss epss 0.04

    Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.

  • CVE-2006-1937Apr 25, 2006
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and…

  • CVE-2006-1938Apr 25, 2006
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.

  • CVE-2006-1939Apr 25, 2006
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8)…

  • CVE-2006-1940Apr 25, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.

  • CVE-2006-1993Apr 25, 2006
    risk 0.07cvss epss 0.51

    Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted…

  • CVE-2006-1994Apr 25, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7)…

  • CVE-2006-1995Apr 25, 2006
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.

  • CVE-2006-1996Apr 25, 2006
    risk 0.00cvss epss 0.02

    Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message.

  • CVE-2006-1997Apr 25, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.

  • CVE-2006-1998Apr 25, 2006
    risk 0.03cvss epss 0.01

    OpenTTD 0.4.7 and earlier allows local users to cause a denial of service (application exit) via a large invalid error number, which triggers an error.

  • CVE-2006-1999Apr 25, 2006
    risk 0.04cvss epss 0.09

    The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.

  • CVE-2006-2000Apr 25, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in /lms/a2z.jsp in logMethods 0.9 allows remote attackers to inject arbitrary web script or HTML via the kwd parameter.

  • CVE-2006-2001Apr 25, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector.

  • CVE-2006-2002Apr 25, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter.

  • CVE-2006-2003Apr 25, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html. NOTE: the provenance of this information is unknown; the…

  • CVE-2006-2004Apr 25, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields.

  • CVE-2006-2005Apr 25, 2006
    risk 0.03cvss epss 0.03

    Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as…

  • CVE-2006-2006Apr 25, 2006
    risk 0.00cvss epss 0.02

    Multiple directory traversal vulnerabilities in IZArc Archiver 3.5 beta 3 allow remote attackers to write arbitrary files via a ..\ (dot dot backslash) in a (1) .rar, (2) .tar, (3) .zip, (4) .jar, or (5) .gz archive. NOTE: the provenance of this information is unknown; the…

  • CVE-2006-2007Apr 25, 2006
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Winny 2.0 b7.1 and earlier allows remote attackers to execute arbitrary code via long strings to certain commands sent to the file transfer port.

  • CVE-2006-2008Apr 25, 2006
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.

  • CVE-2006-2009Apr 25, 2006
    risk 0.00cvss epss 0.06

    PHP remote file inclusion vulnerability in agenda.php3 in phpMyAgenda 3.0 Final and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootagenda parameter.

  • CVE-2006-2010Apr 25, 2006
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in check_login.asp in Bloggage allow remote attackers to execute arbitrary SQL commands via the (1) acc_name and (2) password parameter.

  • CVE-2006-2011Apr 25, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.

  • CVE-2006-2012Apr 25, 2006
    risk 0.03cvss epss 0.04

    Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.

  • CVE-2006-2013Apr 25, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in page.php in SL_site 1.0 allows remote attackers to execute arbitrary SQL commands via the id_page parameter. NOTE: this issue could be used to produce resultant XSS from an error message.

  • CVE-2006-2014Apr 25, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to…