VYPR

CVEs

343,212 total · page 6557 of 6,865

  • CVE-2006-0139Jan 9, 2006
    risk 0.00cvss epss 0.02

    The send-private-message functionality (send-private-message.asp) in PD9 Software MegaBBS 2.1 allows remote attackers to read private messages of other users via a modified replyid parameter.

  • CVE-2006-0114Jan 9, 2006
    risk 0.00cvss epss 0.02

    The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.

  • CVE-2006-0115Jan 9, 2006
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in OnePlug Solutions OnePlug CMS allow remote attackers to execute arbitrary SQL commands via the (1) Press_Release_ID parameter in press/details.asp, (2) Service_ID parameter in services/details.asp, and (3) Product_ID parameter in…

  • CVE-2006-0116Jan 9, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.

  • CVE-2006-0117Jan 9, 2006
    risk 0.00cvss epss 0.02

    Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".

  • CVE-2006-0118Jan 9, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.

  • CVE-2006-0119Jan 9, 2006
    risk 0.00cvss epss 0.04

    Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4)…

  • CVE-2006-0120Jan 9, 2006
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact…

  • CVE-2006-0121Jan 9, 2006
    risk 0.00cvss epss 0.02

    Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the…

  • CVE-2006-0122Jan 9, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Public/Index.asp in Aquifer CMS allows remote attackers to inject arbitrary web script or HTML via the Keyword parameter.

  • CVE-2006-0123Jan 9, 2006
    risk 0.03cvss epss 0.03

    Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.

  • CVE-2006-0124Jan 9, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.

  • CVE-2006-0125Jan 9, 2006
    risk 0.04cvss epss 0.06

    Unspecified vulnerability in appserv/main.php in AppServ 2.4.5 allows remote attackers to include arbitrary files via the appserv_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. There is not…

  • CVE-2006-0126Jan 9, 2006
    risk 0.00cvss epss 0.00

    rxvt-unicode before 6.3, on certain platforms that use openpty and non-Unix pty devices such as Linux and most BSD platforms, does not maintain the intended permissions of tty devices, which allows local users to gain read and write access to the devices.

  • CVE-2006-0127Jan 9, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.

  • CVE-2006-0128Jan 9, 2006
    risk 0.00cvss epss 0.03

    Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors.

  • CVE-2006-0129Jan 9, 2006
    risk 0.00cvss epss 0.02

    Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames via user requests to TCP port 106.

  • CVE-2006-0130Jan 9, 2006
    risk 0.00cvss epss 0.01

    Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or…

  • CVE-2006-0131Jan 9, 2006
    risk 0.00cvss epss 0.01

    boastMachine 3.1 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php and (2) side_menu.php, which reveals the path in an error message.

  • CVE-2006-0132Jan 9, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.

  • CVE-2006-0133Jan 9, 2006
    risk 0.03cvss epss 0.01

    Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability…

  • CVE-2006-0134Jan 9, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.

  • CVE-2006-0135Jan 9, 2006
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).

  • CVE-2006-0136Jan 9, 2006
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3)…

  • CVE-2006-0137Jan 9, 2006
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2006-0138Jan 9, 2006
    risk 0.04cvss epss 0.06

    aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).

  • CVE-2006-0112Jan 7, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

  • CVE-2006-0113Jan 7, 2006
    risk 0.00cvss epss 0.01

    Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message.

  • CVE-2006-0107Jan 7, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the…

  • CVE-2006-0108Jan 7, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the…

  • CVE-2006-0109Jan 7, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

  • CVE-2006-0110Jan 7, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to inject arbitrary web script via the email parameter.

  • CVE-2006-0111Jan 7, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in index.php in Boxcar Media Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the (1) parent or (2) pg parameter.

  • CVE-2006-0106Jan 6, 2006
    risk 0.00cvss epss 0.04

    gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows attackers to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.

  • CVE-2006-0095Jan 6, 2006
    risk 0.00cvss epss 0.00

    dm-crypt in Linux kernel 2.6.15 and earlier does not clear a structure before it is freed, which leads to a memory disclosure that could allow local users to obtain sensitive information about a cryptographic key.

  • CVE-2006-0096Jan 6, 2006
    risk 0.00cvss epss 0.00

    wan/sdla.c in Linux kernel 2.6.x before 2.6.11 and 2.4.x before 2.4.29 does not require the CAP_SYS_RAWIO privilege for an SDLA firmware upgrade, with unknown impact and local attack vectors. NOTE: further investigation suggests that this issue requires root privileges to…

  • CVE-2006-0097Jan 6, 2006
    risk 0.04cvss epss 0.08

    Stack-based buffer overflow in the create_named_pipe function in libmysql.c in PHP 4.3.10 and 4.4.x before 4.4.3 for Windows allows attackers to execute arbitrary code via a long (1) arg_host or (2) arg_unix_socket argument, as demonstrated by a long named pipe variable in the…

  • CVE-2006-0098Jan 6, 2006
    risk 0.00cvss epss 0.00

    The dupfdopen function in sys/kern/kern_descrip.c in OpenBSD 3.7 and 3.8 allows local users to re-open arbitrary files by using setuid programs to access file descriptors using /dev/fd/.

  • CVE-2006-0099Jan 6, 2006
    risk 0.03cvss epss 0.04

    PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/templates/categories/ PHP scripts in Valdersoft Shopping Cart 3.0 allows remote attackers to execute arbitrary code via a URL in the catalogDocumentRoot parameter.

  • CVE-2006-0100Jan 6, 2006
    risk 0.00cvss epss 0.00

    Buffer overflow in NicoFTP 3.0.1.19 and earlier might allow local users to execute arbitrary code via a long string in the "Name of site" field of an FTP account. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not…

  • CVE-2006-0101Jan 6, 2006
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php.

  • CVE-2006-0102Jan 6, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.

  • CVE-2006-0103Jan 6, 2006
    risk 0.03cvss epss 0.04

    TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.

  • CVE-2006-0104Jan 6, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.

  • CVE-2006-0341Jan 6, 2006
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

  • CVE-2006-0063Jan 5, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of…

  • CVE-2006-0084Jan 5, 2006
    risk 0.00cvss epss 0.02

    Cross-site scripting vulnerability in index.php in raSMP 2.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the $_SERVER[HTTP_USER_AGENT] variable (User-Agent header).

  • CVE-2006-0085Jan 5, 2006
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Nkads 1.0 alfa 3 allows remote attackers to execute arbitrary SQL commands via the (1) usuario_nkads_admin or (2) password_nkads_admin parameters.

  • CVE-2006-0086Jan 5, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2006-0087Jan 5, 2006
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in (1) pages.php and (2) detail.php in Lizard Cart CMS 1.04 allows remote attackers to execute arbitrary SQL commands via the id parameter.