VYPR

CVEs

378,543 total · page 7135 of 7,571

  • CVE-2006-6897Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in Widcomm Bluetooth for Windows (BTW) 3.0.1.905 allows remote attackers to conduct unauthorized file operations via a .. (dot dot) in an unspecified parameter.

  • CVE-2006-6898Dec 31, 2006
    risk 0.00cvss —epss 0.04

    Widcomm Bluetooth for Windows (BTW) before 4.0.1.1500 allows remote attackers to listen to and record conversations, aka the CarWhisperer attack.

  • CVE-2006-6899Dec 31, 2006
    risk 0.03cvss —epss 0.03

    hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.

  • CVE-2006-6900Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

  • CVE-2006-6901Dec 31, 2006
    risk 0.01cvss —epss 0.14

    Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6902Dec 31, 2006
    risk 0.01cvss —epss 0.14

    Unspecified vulnerability in the Bluetooth stack in Microsoft Windows Mobile Pocket PC edition allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6903Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Toshiba Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6904Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Broadcom Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6905Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6906Dec 31, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.

  • CVE-2006-6907Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Bluesoil Bluetooth stack has unknown impact and attack vectors.

  • CVE-2006-6908Dec 31, 2006
    risk 0.02cvss —epss 0.30

    Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth…

  • CVE-2006-6909Dec 31, 2006
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in http.c in Karl Dahlke Edbrowse (aka Command line editor browser) 3.1.3 allows remote attackers to execute arbitrary code by operating an FTP server that sends directory listings with (1) long user names or (2) long group names.

  • CVE-2006-6910Dec 31, 2006
    risk 0.03cvss —epss 0.03

    formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.

  • CVE-2006-6911Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.

  • CVE-2006-6912Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the userfile or filename parameter.

  • CVE-2006-6913Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to upload arbitrary PHP scripts via unspecified vectors.

  • CVE-2006-6914Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote attackers to obtain sensitive information, including passwords, via unspecified vectors.

  • CVE-2006-6915Dec 31, 2006
    risk 0.00cvss —epss 0.01

    ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.

  • CVE-2006-6916Dec 31, 2006
    risk 0.00cvss —epss 0.03

    Getahead Direct Web Remoting (DWR) before 1.1.3 allows attackers to cause a denial of service (infinite loop) via unknown vectors related to "crafted input."

  • CVE-2006-6917Dec 31, 2006
    risk 0.05cvss —epss 0.30

    Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote attackers to execute arbitrary code in the Tape Engine (tapeeng.exe) via a crafted RPC request with (1) opnum 38, which is not properly handled in TAPEUTIL.dll…

  • CVE-2006-7231Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in display.asp in Civica Software Civica allows remote attackers to execute arbitrary SQL commands via the Entry parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-7232Dec 31, 2006
    risk 0.00cvss —epss 0.02

    sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.

  • CVE-2006-7233Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.6.0, and possibly other versions before 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the url parameter.

  • CVE-2006-6825Dec 29, 2006
    risk 0.00cvss —epss 0.01

    Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The provenance of this information is unknown; the details are…

  • CVE-2006-6826Dec 29, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the tab editor for Personal .NET Portal before 2.0.0 has unknown impact and attack vectors related to a "Security leak."

  • CVE-2006-6809Dec 29, 2006
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in process.php in Vladimir Menshakov buratinable templator (aka bubla) 1.0.0rc2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) bu_dir or (2) bu_config[dir] parameter.

  • CVE-2006-6810Dec 29, 2006
    risk 0.03cvss —epss 0.04

    Unspecified vulnerability in the clear_user_list function in src/main.c in DB Hub 0.3 allows remote attackers to cause a denial of service (application crash) via crafted network traffic, which triggers memory corruption.

  • CVE-2006-6811MedDec 29, 2006
    risk 0.46cvss 6.5epss 0.10

    KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue was originally reported as a…

  • CVE-2006-6812Dec 29, 2006
    risk 0.03cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP code via a URL in the cal_dir parameter to (1) admin.php, (2) contacts.php, or (3) convert-date.php.

  • CVE-2006-6813Dec 29, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

  • CVE-2006-6814Dec 29, 2006
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath parameter.

  • CVE-2006-6815Dec 29, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3)…

  • CVE-2006-6816Dec 29, 2006
    risk 0.03cvss —epss 0.04

    Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin…

  • CVE-2006-6817Dec 29, 2006
    risk 0.00cvss —epss 0.01

    AlstraSoft Web Host Directory allows remote attackers to obtain sensitive information by requesting any invalid URI, which reveals the path in an error message, a different vulnerability than CVE-2006-2617.

  • CVE-2006-6818Dec 29, 2006
    risk 0.00cvss —epss 0.02

    AlstraSoft Web Host Directory allows remote attackers to bypass authentication and change the admin password via a direct request to admin/config.

  • CVE-2006-6819Dec 29, 2006
    risk 0.03cvss —epss 0.02

    AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup database via a direct request for admin/backup/db.

  • CVE-2006-6820Dec 29, 2006
    risk 0.03cvss —epss 0.02

    myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId…

  • CVE-2006-6821Dec 29, 2006
    risk 0.03cvss —epss 0.02

    myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.

  • CVE-2006-6822Dec 29, 2006
    risk 0.03cvss —epss 0.02

    myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId…

  • CVE-2006-6823Dec 29, 2006
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

  • CVE-2006-6824Dec 29, 2006
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php,…

  • CVE-2006-6799Dec 28, 2006
    risk 0.00cvss —epss 0.03

    SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the…

  • CVE-2006-6800Dec 28, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.

  • CVE-2006-6801Dec 28, 2006
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in misc.php in SH-News 0.93, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the news_cfg[path] parameter.

  • CVE-2006-6802Dec 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter.

  • CVE-2006-6803Dec 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.

  • CVE-2006-6804Dec 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

  • CVE-2006-6805Dec 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eJobs allows remote attackers to execute arbitrary SQL commands via the ID parameter.

  • CVE-2006-6806Dec 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in newsdetail.asp in Enthrallweb eMates 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.