VYPR

CVEs

343,267 total · page 6554 of 6,866

  • CVE-2006-0373Jan 22, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2006-0374Jan 22, 2006
    risk 0.00cvss epss 0.02

    Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly…

  • CVE-2006-0375Jan 22, 2006
    risk 0.00cvss epss 0.01

    Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct…

  • CVE-2006-0376Jan 22, 2006
    risk 0.01cvss epss 0.18

    The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an…

  • CVE-2006-0353Jan 22, 2006
    risk 0.00cvss epss 0.00

    unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to…

  • CVE-2006-0345Jan 21, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.

  • CVE-2006-0346Jan 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.

  • CVE-2006-0347Jan 21, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.

  • CVE-2006-0348Jan 21, 2006
    risk 0.00cvss epss 0.02

    Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2006-0349Jan 21, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.

  • CVE-2006-0350Jan 21, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.

  • CVE-2006-0351Jan 21, 2006
    risk 0.00cvss epss 0.03

    Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.

  • CVE-2006-0352Jan 21, 2006
    risk 0.00cvss epss 0.01

    The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request. NOTE: It was later reported that…

  • CVE-2006-0327Jan 21, 2006
    risk 0.00cvss epss 0.02

    TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.

  • CVE-2006-0328Jan 21, 2006
    risk 0.04cvss epss 0.07

    Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.

  • CVE-2006-0329Jan 21, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

  • CVE-2006-0330Jan 21, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).

  • CVE-2006-0331Jan 21, 2006
    risk 0.03cvss epss 0.01

    Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.

  • CVE-2006-0332Jan 21, 2006
    risk 0.00cvss epss 0.01

    Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.

  • CVE-2006-0333Jan 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.

  • CVE-2006-0334Jan 21, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the…

  • CVE-2006-0335Jan 21, 2006
    risk 0.00cvss epss 0.03

    Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.

  • CVE-2006-0336Jan 21, 2006
    risk 0.00cvss epss 0.02

    Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".

  • CVE-2006-0337Jan 21, 2006
    risk 0.00cvss epss 0.06

    Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute…

  • CVE-2006-0338Jan 21, 2006
    risk 0.00cvss epss 0.03

    Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data…

  • CVE-2006-0339Jan 21, 2006
    risk 0.00cvss epss 0.05

    Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.

  • CVE-2006-0340Jan 21, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a…

  • CVE-2006-0342Jan 21, 2006
    risk 0.00cvss epss 0.02

    RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".

  • CVE-2006-0343Jan 21, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".

  • CVE-2006-0344Jan 21, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.

  • CVE-2006-0019Jan 20, 2006
    risk 0.00cvss epss 0.06

    Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.

  • CVE-2006-0045Jan 20, 2006
    risk 0.00cvss epss 0.00

    crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.

  • CVE-2006-0325Jan 20, 2006
    risk 0.00cvss epss 0.03

    Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.

  • CVE-2006-0322Jan 19, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."

  • CVE-2006-0324Jan 19, 2006
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.

  • CVE-2006-0226Jan 19, 2006
    risk 0.00cvss epss 0.06

    Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.

  • CVE-2006-0309Jan 19, 2006
    risk 0.00cvss epss 0.01

    Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.

  • CVE-2006-0310Jan 19, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.

  • CVE-2006-0311Jan 19, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

  • CVE-2006-0312Jan 19, 2006
    risk 0.03cvss epss 0.03

    create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.

  • CVE-2006-0313Jan 19, 2006
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8)…

  • CVE-2006-0314Jan 19, 2006
    risk 0.00cvss epss 0.01

    PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.

  • CVE-2006-0315Jan 19, 2006
    risk 0.03cvss epss 0.05

    index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.

  • CVE-2006-0316Jan 19, 2006
    risk 0.01cvss epss 0.10

    Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2006-0317Jan 19, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this…

  • CVE-2006-0318Jan 19, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.

  • CVE-2006-0319Jan 19, 2006
    risk 0.04cvss epss 0.07

    Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.

  • CVE-2006-0320Jan 19, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.

  • CVE-2006-0302Jan 19, 2006
    risk 0.00cvss epss 0.01

    ZyXel P2000W VoIP 802.11b Wireless Phone running firmware WV.00.02 allows remote attackers to obtain sensitive information, such as MAC address and software version, by directly accessing UDP port 9090.

  • CVE-2006-0303Jan 19, 2006
    risk 0.00cvss epss 0.01

    Multiple unspecified vulnerabilities in the (1) publishing component, (2) Contact Component, (3) TinyMCE Compressor, and (4) other components in Joomla! 1.0.5 and earlier have unknown impact and attack vectors.