VYPR

CVEs

381,724 total · page 7223 of 7,635

  • CVE-2006-5600Oct 28, 2006
    risk 0.00cvss —epss 0.00

    Axalto Protiva 1.1, possibly only non-commercial versions, stores passwords in plaintext in files with insecure permissions, which allows local users to gain privileges by reading the passwords from (1) KeyTool\keytool.config or (2) webapps\protiva\WEB-INF\classes\authserver.conf…

  • CVE-2006-5601Oct 28, 2006
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary code via unspecified vectors.

  • CVE-2006-5602Oct 28, 2006
    risk 0.00cvss —epss 0.01

    Multiple memory leaks in xsupplicant before 1.2.6, and possibly other versions, allow attackers to cause a denial of service (memory consumption) via unspecified vectors.

  • CVE-2006-4513Oct 28, 2006
    risk 0.00cvss —epss 0.04

    Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO…

  • CVE-2006-4574HigOct 28, 2006
    risk 0.49cvss 7.5epss 0.04

    Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.

  • CVE-2006-5469Oct 28, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.

  • CVE-2006-5595Oct 28, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the AirPcap support in Wireshark (formerly Ethereal) 0.99.3 has unspecified attack vectors related to WEP key parsing.

  • CVE-2006-5596Oct 28, 2006
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

  • CVE-2006-5597Oct 28, 2006
    risk 0.03cvss —epss 0.03

    join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.

  • CVE-2006-4805Oct 27, 2006
    risk 0.00cvss —epss 0.05

    epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark (formerly Ethereal) 0.9.8 through 0.99.3 allows remote attackers to cause a denial of service (memory consumption and crash) via an encoded XOT packet that produces a zero length value when it is…

  • CVE-2006-5468Oct 27, 2006
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors.

  • CVE-2006-5740Oct 27, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.

  • CVE-2006-5467Oct 27, 2006
    risk 0.00cvss —epss 0.05

    The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, as demonstrated using a specifier that begins with a "-"…

  • CVE-2006-5587Oct 27, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers to execute arbitrary PHP code via a URL in the chemin_appli parameter in (1) admin/inc/organisations/form_org.inc.php and (2)…

  • CVE-2006-5588Oct 27, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and magic_quotes_gpc are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter to (1) includes/rss-reader.php or (2)…

  • CVE-2006-5589Oct 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in LedgerSMB (LSMB) 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (1) OE.pm, (2) AM.pm, and (3) Form.pm.

  • CVE-2006-5590Oct 27, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

  • CVE-2006-5591Oct 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Admin/check.asp in PacPoll 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

  • CVE-2006-5592Oct 27, 2006
    risk 0.00cvss —epss 0.02

    Admin/adpoll.asp in PacPoll 4.0 and earlier allows remote attackers to bypass authentication by setting the polllog cookie value to "xx".

  • CVE-2006-5593Oct 27, 2006
    risk 0.00cvss —epss 0.03

    Buffer overflow in Desknet's (niokeru) before 5.0J R1.0 might allow remote authenticated users to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.

  • CVE-2006-5594Oct 27, 2006
    risk 0.00cvss —epss 0.01

    PHP remote file inclusion vulnerability in University of British Columbia iPeer 2.0, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: it is possible that this issue is related to CakePHP.

  • CVE-2006-5556Oct 27, 2006
    risk 0.03cvss —epss 0.01

    Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.

  • CVE-2006-5557Oct 27, 2006
    risk 0.03cvss —epss 0.01

    Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to…

  • CVE-2006-5558Oct 27, 2006
    risk 0.04cvss —epss 0.08

    Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to…

  • CVE-2006-5559Oct 27, 2006
    risk 0.06cvss —epss 0.44

    The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a…

  • CVE-2006-5560Oct 27, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE: some of these details…

  • CVE-2006-5561Oct 27, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.

  • CVE-2006-5562Oct 27, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter.

  • CVE-2006-5563Oct 27, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite. NOTE: the provenance of this information is unknown; the…

  • CVE-2006-5564Oct 27, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-5565Oct 27, 2006
    risk 0.00cvss —epss 0.01

    CRLF injection vulnerability in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary HTTP headers via a CRLF sequence in the (1) name, (2) file, (3) module, and (4) func parameters in (a) index.php; and the (5) file parameter in (b) modules.php. NOTE: the provenance…

  • CVE-2006-5566Oct 27, 2006
    risk 0.03cvss —epss 0.02

    CRLF injection vulnerability in premium/index.php in Shop-Script allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the (1) links_exchange, (2) news, (3) search_with_change_category_ability, (4) logging, (5)…

  • CVE-2006-5567Oct 27, 2006
    risk 0.04cvss —epss 0.15

    Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.

  • CVE-2006-5568Oct 27, 2006
    risk 0.03cvss —epss 0.03

    FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command.

  • CVE-2006-5569Oct 27, 2006
    risk 0.00cvss —epss 0.01

    FtpXQ Server 3.0.1 installs with two default testing accounts, which allows remote attackers to read or write arbitrary files via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

  • CVE-2006-5570Oct 27, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to read arbitrary files via a .. (dot dot) in the doc parameter.

  • CVE-2006-5571Oct 27, 2006
    risk 0.04cvss —epss 0.08

    Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter.

  • CVE-2006-5526Oct 26, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c)…

  • CVE-2006-5527Oct 26, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the sys_path parameter.

  • CVE-2006-5528Oct 26, 2006
    risk 0.03cvss —epss 0.02

    Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2006-5529Oct 26, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of these details are obtained…

  • CVE-2006-5530Oct 26, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this…

  • CVE-2006-5531Oct 26, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.

  • CVE-2006-5532Oct 26, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in rmgs/images.php in RMSOFT Gallery System 2.0 allows remote attackers to inject arbitrary web script or HTML via the kw parameter. NOTE: some of these details are obtained from third party information.

  • CVE-2006-5533Oct 26, 2006
    risk 0.00cvss —epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in AROUNDMe 0.6.9, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter in template/barnraiser_01/pol_view.tpl.php and other…

  • CVE-2006-5534Oct 26, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these details are…

  • CVE-2006-5535Oct 26, 2006
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to scripts2/editzonetemplate.

  • CVE-2006-5536Oct 26, 2006
    risk 0.04cvss —epss 0.14

    Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.

  • CVE-2006-5537Oct 26, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allow remote attackers to inject arbitrary web script or HTML via the (1) upnp:settings/state or (2) upnp:settings/connection parameters.

  • CVE-2006-5538Oct 26, 2006
    risk 0.00cvss —epss 0.01

    D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to list contents of the cgi-bin directory via unspecified vectors, probably a direct request.