VYPR

CVEs

381,758 total · page 7214 of 7,636

  • CVE-2006-6138Nov 28, 2006
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.

  • CVE-2006-6139Nov 28, 2006
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in downloadexcel.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitrary files via the fn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-6140Nov 28, 2006
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to execute arbitrary PHP code via a URL in the slnt parameter to (1) index.php and (2) print.php. NOTE: The provenance of this information is unknown; the details are obtained…

  • CVE-2006-6141Nov 28, 2006
    risk 0.00cvss —epss 0.04

    Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window.

  • CVE-2006-6130Nov 28, 2006
    risk 0.03cvss —epss 0.01

    Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

  • CVE-2006-6131Nov 28, 2006
    risk 0.03cvss —epss 0.01

    Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows local users with webstar privileges to gain root privileges via a malicious libucache.dylib helper library in the current working…

  • CVE-2006-6132Nov 28, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Link Exchange Lite allow remote attackers to execute arbitrary SQL commands via (1) the search engine field to search.asp and (2) psearch parameter to linkslist.asp.

  • CVE-2006-6133Nov 28, 2006
    risk 0.07cvss —epss 0.52

    Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote attackers to execute arbitrary…

  • CVE-2006-6134Nov 28, 2006
    risk 0.03cvss —epss 0.42

    Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary…

  • CVE-2006-5896Nov 27, 2006
    risk 0.00cvss —epss 0.02

    REMLAB Web Mech Designer 2.0.5 allows remote attackers to obtain the full path of the script via an incorrect Tonnage parameter to calculate.php that triggers a divide-by-zero error, which leaks the path in an error message.

  • CVE-2006-5750Nov 27, 2006
    risk 0.01cvss —epss 0.14

    Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the…

  • CVE-2006-6125Nov 27, 2006
    risk 0.04cvss —epss 0.15

    Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID.

  • CVE-2006-6126Nov 27, 2006
    risk 0.00cvss —epss 0.00

    Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.

  • CVE-2006-6127Nov 27, 2006
    risk 0.00cvss —epss 0.00

    Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.

  • CVE-2006-6128Nov 27, 2006
    risk 0.00cvss —epss 0.00

    The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed.

  • CVE-2006-6129Nov 27, 2006
    risk 0.03cvss —epss 0.01

    Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.

  • CVE-2006-5965Nov 26, 2006
    risk 0.00cvss —epss 0.00

    PassGo SSO Plus 2.1.0.32, and probably earlier versions, uses insecure permissions (Everyone/Full Control) for the PassGo Technologies directory, which allows local users to gain privileges by modifying critical programs.

  • CVE-2006-6121Nov 26, 2006
    risk 0.04cvss —epss 0.12

    Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.

  • CVE-2006-6122Nov 26, 2006
    risk 0.00cvss —epss 0.01

    Multiple buffer overflows in TIN before 1.8.2 have unspecified impact and attack vectors, a different vulnerability than CVE-2006-0804.

  • CVE-2006-6123Nov 26, 2006
    risk 0.00cvss —epss 0.01

    Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical…

  • CVE-2006-6124Nov 26, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2006-5869Nov 26, 2006
    risk 0.00cvss —epss 0.02

    pstotext before 1.9 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a file name.

  • CVE-2006-6108Nov 26, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

  • CVE-2006-6109Nov 26, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.

  • CVE-2006-6110Nov 26, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp.

  • CVE-2006-6111Nov 26, 2006
    risk 0.03cvss —epss 0.02

    Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873.

  • CVE-2006-6115Nov 26, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

  • CVE-2006-6116Nov 26, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.

  • CVE-2006-6117Nov 26, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.

  • CVE-2006-6118Nov 26, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2006-6119Nov 26, 2006
    risk 0.00cvss —epss 0.01

    mmgallery 1.55 allows remote attackers to obtain sensitive information via a direct request for thumbs.php, which reveals the installation path in various error messages.

  • CVE-2006-6082Nov 24, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.

  • CVE-2006-6083Nov 24, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in search.asp in CreaScripts Creadirectory allows remote attackers to execute arbitrary SQL commands via the category parameter.

  • CVE-2006-6084Nov 24, 2006
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in abitwhizzy.php in aBitWhizzy allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2006-6085Nov 24, 2006
    risk 0.00cvss —epss 0.01

    Kile before 1.9.3 does not assign a backup file the same permissions as the original file, which might allow local users to obtain sensitive information.

  • CVE-2006-6086Nov 24, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_pear_path parameter.

  • CVE-2006-6087Nov 24, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter.

  • CVE-2006-6088Nov 24, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) n or (2) d parameter in igallery.asp, or (3) an unspecified parameter related to search, possibly the Search Gallery field,…

  • CVE-2006-6089Nov 24, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) groupname (Group Name), or (3) detail (Message) field.

  • CVE-2006-6090Nov 24, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in BaalAsp forum allow remote attackers to execute arbitrary SQL commands via the (1) password parameter to (a) adminlogin.asp, the (2) name or (3) password parameter to (b) userlogin.asp, or the (3) search parameter to search.asp.

  • CVE-2006-6091Nov 24, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Grim Pirate GrimBB before 2006_11_21 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-6092Nov 24, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in vehiclelistings.asp in 20/20 Auto Gallery allow remote attackers to execute arbitrary SQL commands via the (1) vehicleID, (2) categoryID_list, (3) sale_type, (4) stock_number, (5) manufacturer, (6) model, (7) vehicleID, (8) year, (9)…

  • CVE-2006-6093Nov 24, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in adminprint.php in PicturesPro Photo Cart 3.9 allow remote attackers to execute arbitrary PHP code via a URL in the (1) admin_folder and (2) path parameters.

  • CVE-2006-6094Nov 24, 2006
    risk 0.03cvss —epss 0.04

    Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to…

  • CVE-2006-6095Nov 24, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp…

  • CVE-2006-6096Nov 24, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.

  • CVE-2006-6097Nov 24, 2006
    risk 0.04cvss —epss 0.11

    GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and…

  • CVE-2006-6072Nov 24, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in bpg/publications_list.asp in BPG-InfoTech Easy Publisher and Smart Publisher//Pro 2.7.7 allows remote attackers to execute arbitrary SQL commands via the vjob parameter. NOTE: the provenance of this information is unknown; the details are obtained…

  • CVE-2006-6073Nov 24, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) ProductID parameter in productdetail.asp or the (2) categoryid parameter in products.asp.

  • CVE-2006-6074Nov 24, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Enthrallweb eShopping Cart allow remote attackers to execute arbitrary SQL commands via (1) the ProductID parameter in (a) reviews.asp, or the (2) cat_id or (3) sub_id parameter in (b) subProducts.asp. NOTE: the productdetail.asp vector…