VYPR

CVEs

381,927 total · page 7202 of 7,639

  • CVE-2006-6863CriDec 31, 2006
    risk 0.68cvss 9.8epss 0.13

    PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value

  • CVE-2006-6864Dec 31, 2006
    risk 0.03cvss —epss 0.05

    PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter.

  • CVE-2006-6865Dec 31, 2006
    risk 0.03cvss —epss 0.05

    Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows remote attackers to read arbitrary files via a %c0%ae. (Unicode dot dot) in the path parameter, which bypasses the checks for ".." sequences.

  • CVE-2006-6866Dec 31, 2006
    risk 0.03cvss —epss 0.03

    STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt.

  • CVE-2006-6867Dec 31, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3) bu/bu_parse.php, different…

  • CVE-2006-6868Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart Web Shopping Cart before 1.3.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-6869Dec 31, 2006
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang…

  • CVE-2006-6870Dec 31, 2006
    risk 0.00cvss —epss 0.02

    The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.

  • CVE-2006-6871Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewlink operation in mod.php, (2) the intypeid parameter in a showinfo operation in the informasi module in mod.php,…

  • CVE-2006-6872Dec 31, 2006
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

  • CVE-2006-6873Dec 31, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in mod.php in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via (1) the did parameter in a (a) viewdisk operation (diskusi mod), or the (2) cid parameter in a (b) viewlink (katalog mod) or (b) viewcat (diskusi mod)…

  • CVE-2006-6874Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in friend.php in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Message or (2) Your Name field. NOTE: The provenance of this information is unknown; the details are obtained solely from…

  • CVE-2006-6875Dec 31, 2006
    risk 0.00cvss —epss 0.03

    Buffer overflow in the validateospheader function in the Open Settlement Protocol (OSP) module in OpenSER 1.1.0 and earlier allows remote attackers to execute arbitrary code via a crafted OSP header.

  • CVE-2006-6876Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Buffer overflow in the fetchsms function in the SMS handling module (libsms_getsms.c) in OpenSER 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SMS message, triggering memory corruption when the "beginning" buffer is copied to the…

  • CVE-2006-6877Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.

  • CVE-2006-6878Dec 31, 2006
    risk 0.03cvss —epss 0.02

    admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action.

  • CVE-2006-6879Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter.

  • CVE-2006-6880Dec 31, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) newmessage, (2) newname, (3) newwebsite, or (4) newemail parameter.

  • CVE-2006-6881Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Buffer overflow in the Get_Wep function in cofvnet.c for ATMEL Linux PCI PCMCIA USB Drivers drivers 3.4.1.1 corruption allows attackers to execute arbitrary code via a long name argument.

  • CVE-2006-6882Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in golden book allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-6883Dec 31, 2006
    risk 0.00cvss —epss 0.01

    PHP remote file inclusion vulnerability in php4you.php in PHPIrc_bot 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE, since the dir variable is declared before being used

  • CVE-2006-6884Dec 31, 2006
    risk 0.03cvss —epss 0.05

    Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than…

  • CVE-2006-6885Dec 31, 2006
    risk 0.04cvss —epss 0.08

    An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute.

  • CVE-2006-6886Dec 31, 2006
    risk 0.00cvss —epss 0.02

    phpwcms 1.2.5-DEV allows remote attackers to obtain sensitive information via a direct request for (1) files.public-userroot.inc.php or (2) files.private.additions.inc.php in include/inc_lib/, which reveals the path in various error messages.

  • CVE-2006-6887Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Unrestricted file upload vulnerability in logahead UNU 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), a different vulnerability than CVE-2006-6783. NOTE: The provenance…

  • CVE-2006-6888Dec 31, 2006
    risk 0.03cvss —epss 0.02

    P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for db/user.dat.

  • CVE-2006-6889Dec 31, 2006
    risk 0.03cvss —epss 0.02

    FreeStyle Wiki (fswiki) 3.6.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request for config/user.dat.

  • CVE-2006-6890Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.

  • CVE-2006-6891Dec 31, 2006
    risk 0.03cvss —epss 0.02

    Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt.

  • CVE-2006-6892Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the GetLocation function in online.php in Jonathon J. Freeman OvBB 0.13a allows remote attackers to inject arbitrary web script or HTML via the aRequest variable.

  • CVE-2006-6893Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU temperature and consequently changing the pattern of time values visible through (1) ICMP timestamps, (2) TCP sequence numbers,…

  • CVE-2006-6894Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in SPINE before 1.2 have unknown impact and attack vectors, related to (1) "Placeholders in database handler" and (2) "Macro admin security."

  • CVE-2006-6895Dec 31, 2006
    risk 0.00cvss —epss 0.01

    The Bluetooth stack in the Sony Ericsson T60 does not properly implement "Limited discoverable" mode, which allows remote attackers to obtain unauthorized inquiry responses.

  • CVE-2006-6896Dec 31, 2006
    risk 0.00cvss —epss 0.01

    The Bluetooth stack in the Plantronic Headset does not properly implement Non-pairable mode, which allows remote attackers to conduct unauthorized pair-up operations.

  • CVE-2006-6897Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in Widcomm Bluetooth for Windows (BTW) 3.0.1.905 allows remote attackers to conduct unauthorized file operations via a .. (dot dot) in an unspecified parameter.

  • CVE-2006-6898Dec 31, 2006
    risk 0.00cvss —epss 0.04

    Widcomm Bluetooth for Windows (BTW) before 4.0.1.1500 allows remote attackers to listen to and record conversations, aka the CarWhisperer attack.

  • CVE-2006-6899Dec 31, 2006
    risk 0.03cvss —epss 0.03

    hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.

  • CVE-2006-6900Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

  • CVE-2006-6901Dec 31, 2006
    risk 0.01cvss —epss 0.14

    Unspecified vulnerability in the Bluetooth stack in Microsoft Windows allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6902Dec 31, 2006
    risk 0.01cvss —epss 0.14

    Unspecified vulnerability in the Bluetooth stack in Microsoft Windows Mobile Pocket PC edition allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6903Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Toshiba Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6904Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Broadcom Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6905Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Widcomm Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors.

  • CVE-2006-6906Dec 31, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.

  • CVE-2006-6907Dec 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the Bluesoil Bluetooth stack has unknown impact and attack vectors.

  • CVE-2006-6908Dec 31, 2006
    risk 0.02cvss —epss 0.30

    Buffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BTStackServer 1.4.2.10 and 1.3.2.7 on Windows, Widcomm Bluetooth Communication Software 1.4.1.03 on Windows, and the Bluetooth…

  • CVE-2006-6909Dec 31, 2006
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in http.c in Karl Dahlke Edbrowse (aka Command line editor browser) 3.1.3 allows remote attackers to execute arbitrary code by operating an FTP server that sends directory listings with (1) long user names or (2) long group names.

  • CVE-2006-6910Dec 31, 2006
    risk 0.03cvss —epss 0.03

    formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a denial of service (daemon crash) via multiple requests containing many /../ sequences in the Name parameter.

  • CVE-2006-6911Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users to execute arbitrary SQL commands via the ordernum parameter.

  • CVE-2006-6912Dec 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in phpMyFAQ 1.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the userfile or filename parameter.