VYPR

CVEs

343,710 total · page 6532 of 6,875

  • CVE-2006-2015Apr 25, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SL_site 1.0 allows remote attackers to inject arbitrary web script or HTML via the recherche parameter in recherche.php. NOTE: other XSS vectors, as reported in the original disclosure, are resultant from other primary vulnerabilities…

  • CVE-2006-2016Apr 25, 2006
    risk 0.04cvss epss 0.08

    Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e)…

  • CVE-2006-2017Apr 25, 2006
    risk 0.00cvss epss 0.02

    Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request.

  • CVE-2006-2018Apr 25, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was…

  • CVE-2006-0230Apr 25, 2006
    risk 0.04cvss epss 0.16

    Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.

  • CVE-2006-0231Apr 25, 2006
    risk 0.00cvss epss 0.02

    Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications.

  • CVE-2006-0232Apr 25, 2006
    risk 0.00cvss epss 0.02

    Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.

  • CVE-2006-1057Apr 25, 2006
    risk 0.00cvss epss 0.00

    Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.

  • CVE-2006-1992Apr 25, 2006
    risk 0.06cvss epss 0.40

    mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally…

  • CVE-2006-1951Apr 24, 2006
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.

  • CVE-2006-1952Apr 24, 2006
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request.

  • CVE-2006-1990Apr 24, 2006
    risk 0.01cvss epss 0.10

    Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function…

  • CVE-2006-1991Apr 24, 2006
    risk 0.00cvss epss 0.02

    The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.

  • CVE-2006-1865Apr 21, 2006
    risk 0.00cvss epss 0.03

    Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.

  • CVE-2006-1977Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in FlexBB 0.5.7 BETA and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) message parameters.

  • CVE-2006-1978Apr 21, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.

  • CVE-2006-1979Apr 21, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.

  • CVE-2006-1980Apr 21, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.

  • CVE-2006-1981Apr 21, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.

  • CVE-2006-1982Apr 21, 2006
    risk 0.05cvss epss 0.20

    Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.

  • CVE-2006-1983Apr 21, 2006
    risk 0.01cvss epss 0.08

    Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that…

  • CVE-2006-1984Apr 21, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.

  • CVE-2006-1985Apr 21, 2006
    risk 0.04cvss epss 0.14

    Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop…

  • CVE-2006-1986Apr 21, 2006
    risk 0.00cvss epss 0.04

    Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.

  • CVE-2006-1987Apr 21, 2006
    risk 0.00cvss epss 0.04

    Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher,…

  • CVE-2006-1988Apr 21, 2006
    risk 0.00cvss epss 0.02

    The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in…

  • CVE-2006-1954Apr 21, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field.

  • CVE-2006-1955Apr 21, 2006
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.

  • CVE-2006-1956Apr 21, 2006
    risk 0.00cvss epss 0.01

    The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.

  • CVE-2006-1957Apr 21, 2006
    risk 0.00cvss epss 0.02

    The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with different values of the feed parameter.

  • CVE-2006-1958Apr 21, 2006
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php.

  • CVE-2006-1959Apr 21, 2006
    risk 0.04cvss epss 0.13

    PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.

  • CVE-2006-1960Apr 21, 2006
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to…

  • CVE-2006-1961Apr 21, 2006
    risk 0.00cvss epss 0.03

    Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS)…

  • CVE-2006-1962Apr 21, 2006
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.

  • CVE-2006-1963Apr 21, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and earlier allows remote authenticated users to include and execute arbitrary PHP code via a ".." (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually…

  • CVE-2006-1964Apr 21, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Haberler.asp in ASPSitem 1.83 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2006-1965Apr 21, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7)…

  • CVE-2006-1966Apr 21, 2006
    risk 0.00cvss epss 0.02

    An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup…

  • CVE-2006-1967Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.

  • CVE-2006-1968Apr 21, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.

  • CVE-2006-1969Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the q…

  • CVE-2006-1970Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

  • CVE-2006-1971Apr 21, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.

  • CVE-2006-1972Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter.

  • CVE-2006-1973Apr 21, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.

  • CVE-2006-1974Apr 21, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.

  • CVE-2006-1975Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.

  • CVE-2006-1976Apr 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.

  • CVE-2006-1941Apr 20, 2006
    risk 0.03cvss epss 0.04

    Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.