VYPR

CVEs

343,281 total · page 6543 of 6,866

  • CVE-2006-0966Mar 2, 2006
    risk 0.00cvss epss 0.00

    NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (CPU consumption) via a large number of arguments to ncprwsnt.exe, possibly due to a buffer overflow.

  • CVE-2006-0967Mar 2, 2006
    risk 0.00cvss epss 0.00

    NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000. NOTE: this issue was reported as a buffer overflow,…

  • CVE-2006-0968Mar 2, 2006
    risk 0.00cvss epss 0.00

    The ncprwsnt service in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to execute arbitrary code by modifying the connect.bat script, which is automatically executed by the service after a connection is established.

  • CVE-2006-0383Mar 2, 2006
    risk 0.00cvss epss 0.04

    IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".

  • CVE-2006-0384Mar 2, 2006
    risk 0.00cvss epss 0.04

    automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".

  • CVE-2006-0938Mar 1, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.

  • CVE-2006-0939Mar 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.

  • CVE-2006-0940Mar 1, 2006
    risk 0.03cvss epss 0.03

    Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.

  • CVE-2006-0941Mar 1, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.

  • CVE-2006-0942Mar 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.

  • CVE-2006-0943Mar 1, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

  • CVE-2006-0944Mar 1, 2006
    risk 0.03cvss epss 0.04

    Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.

  • CVE-2006-0945Mar 1, 2006
    risk 0.00cvss epss 0.01

    PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated administrators to execute arbitrary PHP code via a URL ending in a NULL (%00) in the index parameter.

  • CVE-2006-0946Mar 1, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.

  • CVE-2006-0947Mar 1, 2006
    risk 0.03cvss epss 0.03

    Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the…

  • CVE-2006-0909Feb 28, 2006
    risk 0.00cvss epss 0.01

    Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2)…

  • CVE-2006-0910Feb 28, 2006
    risk 0.00cvss epss 0.01

    Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5)…

  • CVE-2006-0911Feb 28, 2006
    risk 0.04cvss epss 0.16

    NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving…

  • CVE-2006-0912Feb 28, 2006
    risk 0.00cvss epss 0.02

    Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a "certain RTP sequence."

  • CVE-2006-0913Feb 28, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileges to execute arbitrary SQL commands via the whinedays parameter, as accessible from editparams.cgi.

  • CVE-2006-0914Feb 28, 2006
    risk 0.00cvss epss 0.01

    Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to trigger a SQL error.

  • CVE-2006-0915Feb 28, 2006
    risk 0.00cvss epss 0.01

    Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which allows remote attackers to trigger a SQL error.

  • CVE-2006-0916Feb 28, 2006
    risk 0.00cvss epss 0.01

    Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to generate a partial URL in a form action that causes the user's browser to send the form data to another domain.

  • CVE-2006-0917Feb 28, 2006
    risk 0.00cvss epss 0.00

    Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly…

  • CVE-2006-0918Feb 28, 2006
    risk 0.00cvss epss 0.04

    Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.

  • CVE-2006-0919Feb 28, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

  • CVE-2006-0920Feb 28, 2006
    risk 0.03cvss epss 0.01

    Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.

  • CVE-2006-0921Feb 28, 2006
    risk 0.00cvss epss 0.02

    Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.

  • CVE-2006-0922Feb 28, 2006
    risk 0.04cvss epss 0.08

    CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to…

  • CVE-2006-0923Feb 28, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.

  • CVE-2006-0924Feb 28, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2006-0925Feb 28, 2006
    risk 0.03cvss epss 0.03

    Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers.

  • CVE-2006-0926Feb 28, 2006
    risk 0.00cvss epss 0.02

    Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive.

  • CVE-2006-0927Feb 28, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b)…

  • CVE-2006-0928Feb 28, 2006
    risk 0.00cvss epss 0.02

    The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP command, which reveals the operating system, registered user, and registration code.

  • CVE-2006-0929Feb 28, 2006
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. (dot dot) in the RENAME command.

  • CVE-2006-0930Feb 28, 2006
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the UIDL parameter.

  • CVE-2006-0931Feb 28, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.

  • CVE-2006-0932Feb 28, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.

  • CVE-2006-0933Feb 28, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2006-0934Feb 28, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the message field in the Contact Form.

  • CVE-2006-0935Feb 28, 2006
    risk 0.01cvss epss 0.06

    Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.

  • CVE-2006-0936Feb 28, 2006
    risk 0.03cvss epss 0.02

    Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.

  • CVE-2006-0937Feb 28, 2006
    risk 0.00cvss epss 0.02

    U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.

  • CVE-2006-0906Feb 28, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.

  • CVE-2006-0907Feb 28, 2006
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands via encoded /%2a (/*) sequences in the query string, which bypasses regular expressions that are intended to protect against SQL injection, as demonstrated…

  • CVE-2006-0908Feb 28, 2006
    risk 0.00cvss epss 0.02

    PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences with the "ad_click" word in the query string, as demonstrated via the kala parameter.

  • CVE-2006-0903Feb 27, 2006
    risk 0.03cvss epss 0.01

    MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor…

  • CVE-2006-0736Feb 27, 2006
    risk 0.01cvss epss 0.07

    Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2006-0899Feb 27, 2006
    risk 0.04cvss epss 0.10

    Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.