VYPR

CVEs

343,267 total · page 6553 of 6,866

  • CVE-2006-0428Jan 25, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs.

  • CVE-2006-0429Jan 25, 2006
    risk 0.00cvss epss 0.00

    BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been activated by a server reboot, which could cause an administrator to perform inappropriate, security-relevant actions.

  • CVE-2006-0430Jan 25, 2006
    risk 0.00cvss epss 0.02

    Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when connection filters are enabled, cause the server to run more slowly, which makes it easier for remote attackers to cause a denial of service (server slowdown).

  • CVE-2006-0431Jan 25, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server's SSL identity via unknown attack vectors.

  • CVE-2006-0432Jan 25, 2006
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Administration Console to add custom security policies, causes incorrect policies to be created, which prevents the server from properly protecting JNDI resources.

  • CVE-2006-0379Jan 25, 2006
    risk 0.00cvss epss 0.00

    FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory.

  • CVE-2006-0380Jan 25, 2006
    risk 0.00cvss epss 0.00

    A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.

  • CVE-2006-0381Jan 25, 2006
    risk 0.01cvss epss 0.06

    A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a…

  • CVE-2006-0225Jan 25, 2006
    risk 0.00cvss epss 0.00

    scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.

  • CVE-2006-0411Jan 25, 2006
    risk 0.00cvss epss 0.02

    claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack sessions and possibly gain administrative privileges.

  • CVE-2006-0412Jan 25, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.

  • CVE-2006-0413Jan 25, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.

  • CVE-2006-0414Jan 25, 2006
    risk 0.00cvss epss 0.03

    Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.

  • CVE-2006-0415Jan 25, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.

  • CVE-2006-0416Jan 25, 2006
    risk 0.00cvss epss 0.01

    SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt parameter to (1) chat_no.php and (2) chat_if.php.

  • CVE-2006-0417Jan 25, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.

  • CVE-2006-0418Jan 25, 2006
    risk 0.03cvss epss 0.04

    Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.

  • CVE-2006-0224Jan 25, 2006
    risk 0.00cvss epss 0.01

    Buffer overflow in Library of Assorted Spiffy Things (LibAST) 0.6.1 and earlier, as used in Eterm and possibly other software, allows local users to execute arbitrary code as the utmp user via a long -X command line argument (alternative configuration file name).

  • CVE-2006-0402Jan 25, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Zoph before 0.5pre1 allows remote attackers to execute arbitrary SQL commands.

  • CVE-2006-0403Jan 25, 2006
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in e-moBLOG 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) monthy parameter to index.php or (2) login parameter to admin/index.php. NOTE: some sources have reported item 1 as involving the "monthly" parameter, but…

  • CVE-2006-0404Jan 25, 2006
    risk 0.00cvss epss 0.02

    Note-A-Day Weblog 2.2 stores sensitive data under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to archive/.phpass-admin, which contains encrypted passwords.

  • CVE-2006-0405Jan 25, 2006
    risk 0.00cvss epss 0.03

    The TIFFFetchShortPair function in tif_dirread.c in libtiff 3.8.0 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a NULL pointer dereference, possibly due to changes in type declarations and/or the TIFFVSetField…

  • CVE-2006-0406Jan 25, 2006
    risk 0.00cvss epss 0.02

    search.php in MyBB 1.0.2 allows remote attackers to obtain sensitive information via a certain search request that reveals the table prefix in a SQL error message, possibly due to invalid parameters.

  • CVE-2006-0407Jan 25, 2006
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure…

  • CVE-2006-0408Jan 25, 2006
    risk 0.00cvss epss 0.00

    rsh utility in Sun Grid Engine (SGE) before 6.0u7_1 allows local users to gain privileges and execute arbitrary code via unspecified vectors, possibly involving command line arguments.

  • CVE-2006-0409Jan 25, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.

  • CVE-2006-0410Jan 25, 2006
    risk 0.00cvss epss 0.03

    SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings.

  • CVE-2006-0321Jan 24, 2006
    risk 0.00cvss epss 0.03

    fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer when fetchmail bounces the message to the originator or local postmaster.

  • CVE-2006-0036Jan 23, 2006
    risk 0.00cvss epss 0.03

    ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows remote attackers to cause a denial of service (memory corruption or crash) via an inbound PPTP_IN_CALL_REQUEST packet that causes a null pointer to be used in…

  • CVE-2006-0037Jan 23, 2006
    risk 0.00cvss epss 0.00

    ip_nat_pptp in the PPTP NAT helper (netfilter/ip_nat_helper_pptp.c) in Linux kernel 2.6.14, and other versions, allows local users to cause a denial of service (memory corruption or crash) via a crafted outbound packet that causes an incorrect offset to be calculated from…

  • CVE-2006-0378Jan 23, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the affected program might be…

  • CVE-2006-0354Jan 22, 2006
    risk 0.04cvss epss 0.10

    Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets,…

  • CVE-2006-0355Jan 22, 2006
    risk 0.03cvss epss 0.03

    Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.

  • CVE-2006-0356Jan 22, 2006
    risk 0.00cvss epss 0.02

    Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command.

  • CVE-2006-0357Jan 22, 2006
    risk 0.03cvss epss 0.03

    Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command.

  • CVE-2006-0358Jan 22, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.

  • CVE-2006-0359Jan 22, 2006
    risk 0.03cvss epss 0.04

    Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands…

  • CVE-2006-0360Jan 22, 2006
    risk 0.00cvss epss 0.02

    MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a denial of service via a direct connection to UDP port 9090, which is undocumented and does not require authentication.

  • CVE-2006-0361Jan 22, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an tag in the comment parameter, which strips most tags but not .

  • CVE-2006-0362Jan 22, 2006
    risk 0.00cvss epss 0.02

    TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a denial of service (CPU consumption) via an unknown vector, probably involving an HTTP request with a negative number in the Content-Length…

  • CVE-2006-0363Jan 22, 2006
    risk 0.00cvss epss 0.03

    The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\Creds registry key, which might allow local users to obtain the original passwords via a program that calls…

  • CVE-2006-0364Jan 22, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without…

  • CVE-2006-0365Jan 22, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.

  • CVE-2006-0366Jan 22, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.

  • CVE-2006-0367Jan 22, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the…

  • CVE-2006-0368Jan 22, 2006
    risk 0.00cvss epss 0.04

    Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of…

  • CVE-2006-0369Jan 22, 2006
    risk 0.00cvss epss 0.01

    MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the…

  • CVE-2006-0370Jan 22, 2006
    risk 0.00cvss epss 0.02

    Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.

  • CVE-2006-0371Jan 22, 2006
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.

  • CVE-2006-0372Jan 22, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.