VYPR

CVEs

381,943 total · page 7201 of 7,639

  • CVE-2006-4097Dec 31, 2006
    risk 0.00cvss —epss 0.04

    Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it…

  • CVE-2006-4098Dec 31, 2006
    risk 0.01cvss —epss 0.13

    Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.

  • CVE-2006-4220Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.

  • CVE-2006-4575Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10)…

  • CVE-2006-4576Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG extension, which is rendered by Internet Explorer.

  • CVE-2006-4577Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (b)…

  • CVE-2006-4578Dec 31, 2006
    risk 0.00cvss —epss 0.01

    export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.

  • CVE-2006-4579Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.

  • CVE-2006-4580Dec 31, 2006
    risk 0.00cvss —epss 0.01

    register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "confirm".

  • CVE-2006-4581Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PHP scripts.

  • CVE-2006-4582Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demonstrated by deleting arbitrary users via the id parameter in a deleteuser action in users.php.

  • CVE-2006-4695Dec 31, 2006
    risk 0.03cvss —epss 0.40

    Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."

  • CVE-2006-4727Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote attackers to inject arbitrary web script or HTML via the (1) lineId and (2) sort parameters.

  • CVE-2006-5265Dec 31, 2006
    risk 0.01cvss —epss 0.10

    Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number in a Distributed Process Server (DPS) message.

  • CVE-2006-5266Dec 31, 2006
    risk 0.01cvss —epss 0.16

    Multiple buffer overflows in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allow remote attackers to execute arbitrary code via (1) a crafted Distributed Process Manager (DPM) message to the (a) DPM component, or a (2) long string or (3) long IP address in a…

  • CVE-2006-5574Dec 31, 2006
    risk 0.02cvss —epss 0.24

    Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is not properly…

  • CVE-2006-5749Dec 31, 2006
    risk 0.00cvss —epss 0.00

    The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset state timer, which has unknown attack vectors and results in a system crash.

  • CVE-2006-5755Dec 31, 2006
    risk 0.00cvss —epss 0.00

    Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service (crash) by causing SYSENTER to set an NT flag, which can trigger a crash on the IRET of the next…

  • CVE-2006-5857Dec 31, 2006
    risk 0.01cvss —epss 0.09

    Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine pointer during rendering.

  • CVE-2006-5858Dec 31, 2006
    risk 0.01cvss —epss 0.13

    Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file.

  • CVE-2006-5867Dec 31, 2006
    risk 0.00cvss —epss 0.04

    fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to obtain sensitive information via man-in-the-middle (MITM) attacks.

  • CVE-2006-5870Dec 31, 2006
    risk 0.01cvss —epss 0.08

    Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to execute arbitrary code via a crafted (a) WMF or (b) EMF file that triggers heap-based buffer…

  • CVE-2006-5974Dec 31, 2006
    risk 0.00cvss —epss 0.04

    fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference when calling the (1) ferror or (2) fflush functions.

  • CVE-2006-6101Dec 31, 2006
    risk 0.00cvss —epss 0.00

    Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of glyph…

  • CVE-2006-6102Dec 31, 2006
    risk 0.00cvss —epss 0.03

    Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified…

  • CVE-2006-6103Dec 31, 2006
    risk 0.00cvss —epss 0.00

    Integer overflow in the ProcDbeSwapBuffers function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified…

  • CVE-2006-6143Dec 31, 2006
    risk 0.01cvss —epss 0.08

    The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attackers to cause a denial of…

  • CVE-2006-6144Dec 31, 2006
    risk 0.00cvss —epss 0.05

    The "mechglue" abstraction interface of the GSS-API library for Kerberos 5 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, allows remote attackers to cause a denial of service (crash) via unspecified vectors that…

  • CVE-2006-6336Dec 31, 2006
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in the Mail Management Server (MAILMA.exe) in Eudora WorldMail 3.1.x allows remote attackers to execute arbitrary code via a crafted request containing successive delimiters.

  • CVE-2006-6488Dec 31, 2006
    risk 0.04cvss —epss 0.08

    Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2)…

  • CVE-2006-6827Dec 31, 2006
    risk 0.03cvss —epss 0.03

    Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the Flash8b.AllowScriptAccess method.

  • CVE-2006-6828Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown;…

  • CVE-2006-6829Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained…

  • CVE-2006-6830Dec 31, 2006
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the index parameter.

  • CVE-2006-6831Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catcode parameter.

  • CVE-2006-6832Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.

  • CVE-2006-6833Dec 31, 2006
    risk 0.00cvss —epss 0.01

    com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

  • CVE-2006-6834Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

  • CVE-2006-6835Dec 31, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to journal.php.

  • CVE-2006-6836Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Multiple unspecified vulnerabilities in osp-cert in IBM OS/400 V5R3M0 have unspecified impact and attack vectors, related to ASN.1 parsing.

  • CVE-2006-6837Dec 31, 2006
    risk 0.00cvss —epss 0.04

    Multiple stack-based buffer overflows in the (1) LoadTree, (2) ReadHeader, and (3) LoadXBOXTree functions in the ISO (iso_wincmd) plugin 1.7.3.3 and earlier for Total Commander allow user-assisted remote attackers to execute arbitrary code via a long pathname in an ISO image.

  • CVE-2006-6838Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.

  • CVE-2006-6839Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."

  • CVE-2006-6840Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."

  • CVE-2006-6841Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.

  • CVE-2006-6842Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2006-6843Dec 31, 2006
    risk 0.00cvss —epss 0.01

    PHP remote file inclusion vulnerability in the BE IT EasyPartner 0.0.9 beta component for Joomla! allows remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2006-6844Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the optional user comment module in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the user comment form.

  • CVE-2006-6845Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the cntnt01searchinput parameter in a Search action.

  • CVE-2006-6846Dec 31, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the num parameter in (a) phonemessage.asp, (2) the catcode parameter in (b) faqDsp.asp, and the (3) Username and (4) Password…