VYPR

CVEs

381,742 total · page 7220 of 7,635

  • CVE-2006-5784Nov 7, 2006
    risk 0.03cvss —epss 0.03

    Unspecified vulnerability in enserver.exe in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to read arbitrary files via crafted data on a "3200+SYSNR" TCP port, as demonstrated by port 3201. NOTE: this issue can be leveraged by…

  • CVE-2006-5785Nov 7, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in SAP Web Application Server 6.40 before patch 136 and 7.00 before patch 66 allows remote attackers to cause a denial of service (enserver.exe crash) via a 0x72F2 sequence on UDP port 64999.

  • CVE-2006-5786Nov 7, 2006
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.

  • CVE-2006-5787Nov 7, 2006
    risk 0.03cvss —epss 0.03

    admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, possibly related to an authentication issue in admin/chk_admin.php.

  • CVE-2006-5788Nov 7, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute arbitrary PHP code via a URL in the p parameter.

  • CVE-2006-5789Nov 7, 2006
    risk 0.03cvss —epss 0.03

    War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands. NOTE: it is possible that vector 1 is an…

  • CVE-2006-5790Nov 7, 2006
    risk 0.00cvss —epss 0.03

    Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) an entry with an attachment whose name contains format string specifiers (el_submit function), and…

  • CVE-2006-5791Nov 7, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct function, and (2) the Type…

  • CVE-2006-5792Nov 7, 2006
    risk 0.08cvss —epss 0.61

    Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability than CVE-2006-5780. As of…

  • CVE-2006-5651Nov 7, 2006
    risk 0.00cvss —epss 0.02

    list.php in DigiOz Guestbook before 1.7.1 allows remote attackers to obtain sensitive information via a non-numeric page parameter, which displays the installation path in the resulting error message.

  • CVE-2006-5781Nov 7, 2006
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in the handshake function in iodine 0.3.2 allows remote attackers to execute arbitrary code via a crafted DNS response.

  • CVE-2006-5650Nov 7, 2006
    risk 0.08cvss —epss 0.67

    The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.

  • CVE-2006-5778Nov 7, 2006
    risk 0.00cvss —epss 0.00

    ftpd in linux-ftpd 0.17, and possibly other versions, performs a chdir before setting the UID, which allows local users to bypass intended access restrictions by redirecting their home directory to a restricted directory.

  • CVE-2006-5779HigNov 7, 2006
    risk 0.55cvss 7.5epss 0.76

    OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.

  • CVE-2006-5780Nov 7, 2006
    risk 0.08cvss —epss 0.62

    Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm.

  • CVE-2006-4572Nov 7, 2006
    risk 0.00cvss —epss 0.04

    ip6_tables in netfilter in the Linux kernel before 2.6.16.31 allows remote attackers to (1) bypass a rule that disallows a protocol, via a packet with the protocol header not located immediately after the fragment header, aka "ip6_tables protocol bypass bug;" and (2) bypass a…

  • CVE-2006-4806Nov 7, 2006
    risk 0.00cvss —epss 0.04

    Multiple integer overflows in imlib2 allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) ARGB (loader_argb.c), (2) PNG (loader_png.c), (3) LBM (loader_lbm.c), (4) JPEG (loader_jpeg.c), or (5) TIFF…

  • CVE-2006-4807Nov 7, 2006
    risk 0.00cvss —epss 0.02

    loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.

  • CVE-2006-4808Nov 7, 2006
    risk 0.00cvss —epss 0.04

    Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.

  • CVE-2006-4809Nov 7, 2006
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in loader_pnm.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM image.

  • CVE-2006-5776Nov 7, 2006
    risk 0.00cvss —epss 0.02

    Multiple PHP remote file inclusions in Ariadne 2.4.1 allows remote attackers to execute arbitrary PHP code via the ariadne parameter in (1) ftp/loader.php and (2) lib/includes/loader.cmd.php. NOTE: this issue is disputed by CVE, since installation instructions recommend that…

  • CVE-2006-5777Nov 7, 2006
    risk 0.03cvss —epss 0.03

    Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame parameter to (1) addnewcont.php, (2) adminpassw.php, (3) amministrazione.php, (4) artins.php, (5) bgcolor.php, (6) cancartcat.php,…

  • CVE-2006-5760Nov 6, 2006
    risk 0.03cvss —epss 0.04

    Multiple PHP remote file inclusion vulnerabilities in phpDynaSite 3.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the racine parameter to (1) function_log.php, (2) function_balise_url.php, or (3) connection.php.

  • CVE-2006-5761Nov 6, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Rhadrix If-CMS 1.01 and 2.07 allows remote attackers to inject arbitrary web script or HTML via the rns parameter.

  • CVE-2006-5762Nov 6, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: this issue was later reported for the "File Upload System" which is a component…

  • CVE-2006-5763Nov 6, 2006
    risk 0.03cvss —epss 0.05

    Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. …

  • CVE-2006-5764Nov 6, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from…

  • CVE-2006-5765Nov 6, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in rss.php in Article Script 1.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

  • CVE-2006-5766Nov 6, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in volume.php in Article System 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config[public_dir] parameter.

  • CVE-2006-5767Nov 6, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in includes/xhtml.php in Drake CMS 0.2.2 alpha rev.846 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the d_root parameter.

  • CVE-2006-5768Nov 6, 2006
    risk 0.04cvss —epss 0.10

    Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the av parameter to (1) msg/view.php, (2) msg/inc_message.php, (3) msg/inc_envoi.php, and (4)…

  • CVE-2006-5769Nov 6, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in admin.tool CMS 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fSid or (2) fSrcBegriffe parameters in unspecified vectors.

  • CVE-2006-5770Nov 6, 2006
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via (1) Bloks, (2) Newnews, (3) lBlok, and (4) foooot parameter in (a) index.php; Newnews, (5) newmsgs, and Bloks parameter in (b) MobileNews.php;…

  • CVE-2006-5771Nov 6, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Arkoon SSL360 1.0 and 2.0 before 2.0/2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-5772Nov 6, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod parameter.

  • CVE-2006-5773Nov 6, 2006
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a .. (dot dot) in the action parameter.

  • CVE-2006-5774Nov 6, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Hyper NIKKI System before 2.19.9 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2006-5775Nov 6, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in profile.php in FunkBoard 0.71 before 4 November 2006 at 18:16 GMT allows remote attackers to inject arbitrary web script or HTML, possibly via the name parameter.

  • CVE-2006-5759Nov 6, 2006
    risk 0.00cvss —epss 0.01

    index.php in Rhadrix If-CMS, possibly 1.01 and 2.07, allows remote attackers to obtain the full path of the web server via empty (1) rns[] or (2) pag[] arguments, which reveals the path in an error message.

  • CVE-2006-5757Nov 6, 2006
    risk 0.03cvss —epss 0.01

    Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data structures.

  • CVE-2006-5758Nov 6, 2006
    risk 0.04cvss —epss 0.06

    The Graphics Rendering Engine in Microsoft Windows 2000 through 2000 SP4 and Windows XP through SP2 maps GDI Kernel structures on a global shared memory section that is mapped with read-only permissions, but can be remapped by other processes as read-write, which allows local…

  • CVE-2006-5729Nov 6, 2006
    risk 0.00cvss —epss 0.01

    Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related…

  • CVE-2006-5730Nov 6, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. NOTE: it is possible that this is a…

  • CVE-2006-5731Nov 6, 2006
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code,…

  • CVE-2006-5732Nov 6, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in logout.php in T.G.S. CMS 0.1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the myauthorid cookie.

  • CVE-2006-5733Nov 6, 2006
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log…

  • CVE-2006-5734Nov 6, 2006
    risk 0.00cvss —epss 0.01

    Multiple PHP remote file inclusion vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) section parameter in (a) documentation/common/frame_toc.php and (b) documentation/common/search.php, the (2) req_lang parameter in…

  • CVE-2006-5735Nov 6, 2006
    risk 0.01cvss —epss 0.14

    Directory traversal vulnerability in include/common.php in PunBB before 1.2.14 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the language parameter, related to register.php storing a language value in the users table.

  • CVE-2006-5736Nov 6, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in search.php in PunBB before 1.2.14, when the PHP installation is vulnerable to CVE-2006-3017, allows remote attackers to execute arbitrary SQL commands via the result_list array parameter, which is not initialized.

  • CVE-2006-5737Nov 6, 2006
    risk 0.00cvss —epss 0.00

    PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time), which might allow local users to perform unauthorized actions.