VYPR

CVEs

343,267 total · page 6549 of 6,866

  • CVE-2006-0633Feb 10, 2006
    risk 0.00cvss epss 0.01

    The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to…

  • CVE-2006-0634Feb 10, 2006
    risk 0.00cvss epss 0.00

    Borland C++Builder 6 (BCB6) with Update Pack 4 Enterprise edition (ent_upd4) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.

  • CVE-2006-0635Feb 10, 2006
    risk 0.00cvss epss 0.00

    Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the "i>sizeof(int)" expression to false when i equals -1, which might introduce integer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.

  • CVE-2006-0636Feb 10, 2006
    risk 0.00cvss epss 0.02

    desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start function, which allows remote attackers to execute arbitrary PHP code and possibly conduct other attacks by modifying critical assumed-immutable variables, as…

  • CVE-2006-0637Feb 10, 2006
    risk 0.03cvss epss 0.02

    Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than…

  • CVE-2006-0638Feb 10, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter.

  • CVE-2006-0639Feb 10, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E.

  • CVE-2006-0640Feb 10, 2006
    risk 0.00cvss epss 0.00

    Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon.

  • CVE-2006-0641Feb 10, 2006
    risk 0.00cvss epss 0.01

    Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of sensitive information…

  • CVE-2006-0642Feb 10, 2006
    risk 0.00cvss epss 0.02

    Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances,…

  • CVE-2006-0643Feb 10, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users to inject arbitrary web script or HTML via the topic name of a conference.

  • CVE-2006-0644Feb 10, 2006
    risk 0.04cvss epss 0.08

    Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and…

  • CVE-2006-0627Feb 9, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary web script or HTML via the (1) Referer or (2) X-Forwarded-For headers in an HTTP request, which are not properly handled when the administrator accesses Site…

  • CVE-2006-0625Feb 9, 2006
    risk 0.03cvss epss 0.05

    Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code…

  • CVE-2006-0626Feb 9, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.

  • CVE-2006-0613Feb 9, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Java Web Start after 1.0.1_02, as used in J2SE 5.0 Update 5 and earlier, allows remote attackers to obtain privileges via unspecified vectors involving untrusted applications.

  • CVE-2006-0614Feb 9, 2006
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 3 and earlier, SDK and JRE 1.3.x through 1.3.1_16 and 1.4.x through 1.4.2_08 allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the…

  • CVE-2006-0615Feb 9, 2006
    risk 0.00cvss epss 0.05

    Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "second and third…

  • CVE-2006-0616Feb 9, 2006
    risk 0.00cvss epss 0.04

    Unspecified vulnerability in Sun Java JDK and JRE 5.0 Update 4 and earlier allows remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fourth issue."

  • CVE-2006-0617Feb 9, 2006
    risk 0.00cvss epss 0.04

    Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 5 and earlier allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, aka the "fifth, sixth, and seventh issues."

  • CVE-2006-0618Feb 9, 2006
    risk 0.00cvss epss 0.00

    Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name).

  • CVE-2006-0619Feb 9, 2006
    risk 0.00cvss epss 0.01

    Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so.2) or (3) a long PHOTON_PATH environment variable to the setitem function in the…

  • CVE-2006-0620Feb 9, 2006
    risk 0.03cvss epss 0.01

    Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.

  • CVE-2006-0621Feb 9, 2006
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.

  • CVE-2006-0622Feb 9, 2006
    risk 0.00cvss epss 0.00

    QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a "break *0xb032d59f" command to gdb.

  • CVE-2006-0623Feb 9, 2006
    risk 0.03cvss epss 0.01

    QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.

  • CVE-2006-0624Feb 9, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

  • CVE-2006-0610Feb 9, 2006
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in 2200net Calendar system 1.2, with gpc_magic_quotes disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the fm_data[id] parameter to calendar.php and (2) the $ad['acc'] variable in…

  • CVE-2006-0611Feb 9, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in compose.pl in @Mail 4.3 and earlier for Windows allows remote attackers to upload arbitrary files to arbitrary locations via a .. (dot dot) in the unique parameter.

  • CVE-2006-0612Feb 9, 2006
    risk 0.00cvss epss 0.00

    Powersave daemon before 0.10.15.2 allows local users to gain privileges (unauthorized access to an X session) via unspecified vectors. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

  • CVE-2006-0602Feb 8, 2006
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5)…

  • CVE-2006-0603Feb 8, 2006
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter.

  • CVE-2006-0604Feb 8, 2006
    risk 0.00cvss epss 0.03

    check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access.

  • CVE-2006-0605Feb 8, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields.

  • CVE-2006-0606Feb 8, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

  • CVE-2006-0607Feb 8, 2006
    risk 0.00cvss epss 0.02

    check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication.

  • CVE-2006-0608Feb 8, 2006
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknown attack vectors to scripts that display information from the database.

  • CVE-2006-0609Feb 8, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2006-0023Feb 8, 2006
    risk 0.00cvss epss 0.01

    Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery…

  • CVE-2006-0578Feb 8, 2006
    risk 0.00cvss epss 0.02

    Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.

  • CVE-2006-0579Feb 8, 2006
    risk 0.00cvss epss 0.04

    Multiple integer overflows in (1) the new_demux_packet function in demuxer.h and (2) the demux_asf_read_packet function in demux_asf.c in MPlayer 1.0pre7try2 and earlier allow remote attackers to execute arbitrary code via an ASF file with a large packet length value. NOTE: the…

  • CVE-2006-0580Feb 8, 2006
    risk 0.00cvss epss 0.03

    IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).

  • CVE-2006-0581Feb 8, 2006
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.

  • CVE-2006-0582Feb 8, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors.

  • CVE-2006-0583Feb 8, 2006
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

  • CVE-2006-0584Feb 8, 2006
    risk 0.00cvss epss 0.00

    The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a dictionary attack that compares output strings.

  • CVE-2006-0585Feb 8, 2006
    risk 0.01cvss epss 0.15

    jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function,…

  • CVE-2006-0586Feb 8, 2006
    risk 0.03cvss epss 0.05

    Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5)…

  • CVE-2006-0587Feb 8, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in util.php in Gallery before 1.5.2-pl2 allows remote authenticated users with trick an owner into modifying stored album data and possibly executing arbitrary code via unspecified vectors involving a crafted link to a crafted file.

  • CVE-2006-0588Feb 8, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in search.php in MyTopix 1.2.3 allows remote attackers to execute arbitrary SQL commands via the (1) mid and (2) keywords parameters.