VYPR

CVEs

381,337 total · page 7236 of 7,627

  • CVE-2006-4559Sep 6, 2006
    risk 0.04cvss —epss 0.07

    Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3)…

  • CVE-2006-4560Sep 6, 2006
    risk 0.01cvss —epss 0.19

    Internet Explorer 6 on Windows XP SP2 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a…

  • CVE-2006-4561Sep 6, 2006
    risk 0.00cvss —epss 0.01

    Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name…

  • CVE-2006-4562Sep 6, 2006
    risk 0.00cvss —epss 0.01

    The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has stated that the default configuration does not proxy DNS…

  • CVE-2006-4539Sep 5, 2006
    risk 0.00cvss —epss 0.02

    (1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the…

  • CVE-2006-4540Sep 5, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • CVE-2006-4541Sep 5, 2006
    risk 0.03cvss —epss 0.01

    RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.

  • CVE-2006-4542Sep 5, 2006
    risk 0.00cvss —epss 0.03

    Webmin before 1.296 and Usermin before 1.226 do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.

  • CVE-2006-4538Sep 5, 2006
    risk 0.00cvss —epss 0.00

    Linux kernel 2.6.17 and earlier, when running on IA64 or SPARC platforms, allows local users to cause a denial of service (crash) via a malformed ELF file that triggers memory maps that cross region boundaries.

  • CVE-2006-4536Sep 5, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the podpis parameter.

  • CVE-2006-4537Sep 5, 2006
    risk 0.00cvss —epss 0.01

    NET$SESSION_CONTROL.EXE in DECnet-Plus in OpenVMS ALPHA 7.3-2 and Alpha 8.2 writes a password to an audit log file when there is a successful connection after a "network breakin" event, which allows local users to obtain passwords by reading the file.

  • CVE-2006-4339Sep 5, 2006
    risk 0.00cvss —epss 0.05

    OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from…

  • CVE-2006-4534Sep 5, 2006
    risk 0.03cvss —epss 0.34

    Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including…

  • CVE-2006-4522Sep 1, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.

  • CVE-2006-4523Sep 1, 2006
    risk 0.03cvss —epss 0.04

    The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET request.

  • CVE-2006-4524Sep 1, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameters. NOTE: some of these details are obtained from third party information.

  • CVE-2006-4525Sep 1, 2006
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.

  • CVE-2006-4526Sep 1, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in includes/content/viewCat.inc.php in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the searchArray[] parameter.

  • CVE-2006-4527Sep 1, 2006
    risk 0.00cvss —epss 0.02

    includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion attacks.

  • CVE-2006-4528Sep 1, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) recherche parameter in recherchemembre.php and the (2) email parameter in test.php.

  • CVE-2006-4529Sep 1, 2006
    risk 0.00cvss —epss 0.02

    SQL injection vulnerability in recherchemembre.php in membrepass 1.5. allows remote attackers to execute arbitrary SQL commands via the recherche parameter.

  • CVE-2006-4530Sep 1, 2006
    risk 0.00cvss —epss 0.02

    Direct static code injection vulnerability in include/change.php in membrepass 1.5 allows remote attackers to execute arbitrary PHP code via the aifon parameter, which is injected into include/variable.php.

  • CVE-2006-4531Sep 1, 2006
    risk 0.03cvss —epss 0.04

    PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter.

  • CVE-2006-4532Sep 1, 2006
    risk 0.04cvss —epss 0.07

    PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter.

  • CVE-2006-4533Sep 1, 2006
    risk 0.00cvss —epss 0.04

    Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, (2) categories.php, (3) news.php, (4) prefs.php, (5) sites.php, (6)…

  • CVE-2006-4506Aug 31, 2006
    risk 0.00cvss —epss 0.01

    idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors, possibly involving the " (quote) and \ (backslash) characters and eval injection.

  • CVE-2006-4507Aug 31, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the TIFF viewer (possibly libTIFF) in the Photo Viewer in the Sony PlaystationPortable (PSP) 2.00 through 2.80 allows local users to execute arbitrary code via crafted TIFF images. NOTE: due to lack of details, it is not clear whether this is related…

  • CVE-2006-4508Aug 31, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and 0.1.1.x before 0.1.1.23, and (2) ScatterChat before 1.0.2, allows remote attackers operating a Tor entry node to route arbitrary Tor traffic through clients or cause a denial of service (flood) via unspecified…

  • CVE-2006-4146Aug 31, 2006
    risk 0.00cvss —epss 0.03

    Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large…

  • CVE-2006-4487Aug 31, 2006
    risk 0.00cvss —epss 0.02

    DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.

  • CVE-2006-4488Aug 31, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the exbb[home_path] parameter.

  • CVE-2006-4489Aug 31, 2006
    risk 0.04cvss —epss 0.15

    Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL in the config[include_dir] parameter in actions/ipn.php or (2) an FTP path in the config[plugin_dir] parameter in…

  • CVE-2006-4490Aug 31, 2006
    risk 0.03cvss —epss 0.03

    Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2)…

  • CVE-2006-4491Aug 31, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in Cybozu Collaborex, AG before 1.2(1.5), AG Pocket before 5.2(0.8), Mailwise before 3.0(0.3), and Garoon 1 before 1.5(4.1) allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2006-4492Aug 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Cybozu Office 6.5 Build 1.2 for Windows allows remote attackers to obtain sensitive information, including users and groups, via unspecified vectors.

  • CVE-2006-4493Aug 31, 2006
    risk 0.00cvss —epss 0.00

    xbiff2 1.9 creates $HOME/.xbiff2rc in a user's home directory with insecure file permissions, which allows local users to obtain sensitive information such as login credentials. NOTE: the provenance of this information is unknown; the details are obtained from third party…

  • CVE-2006-4494Aug 31, 2006
    risk 0.05cvss —epss 0.22

    Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3)…

  • CVE-2006-4495Aug 31, 2006
    risk 0.05cvss —epss 0.21

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.

  • CVE-2006-4496Aug 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.

  • CVE-2006-4497Aug 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2006-4498Aug 31, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a different vector than CVE-2006-3922.

  • CVE-2006-4499Aug 31, 2006
    risk 0.00cvss —epss 0.01

    ModernBill 5.0.4 and earlier uses cURL with insecure settings for CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST that do not verify SSL certificates, which allows remote attackers to read network traffic via a man-in-the-middle (MITM) attack.

  • CVE-2006-4500Aug 31, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) about, (2) again, (3) lastname, (4) email, (5) password, (6) album, (7) id, (8) table, (9) desc, (10) doc, (11) mname, (12)…

  • CVE-2006-4501Aug 31, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) about, (2) album, (3) id, (4) use, (5) desc, (6) doc, (7) mname, (8) max, and possibly other parameters.

  • CVE-2006-4502Aug 31, 2006
    risk 0.00cvss —epss 0.02

    ezPortal/ztml CMS 1.0 allows remote attackers to bypass authentication controls via a direct request to the "Administration Area" script.

  • CVE-2006-4503Aug 31, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in link.php in NX5Linx 1.0 allows remote attackers to read arbitrary files via the logo parameter.

  • CVE-2006-4504Aug 31, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in NX5Linx 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) c and (2) l parameters.

  • CVE-2006-4505Aug 31, 2006
    risk 0.03cvss —epss 0.03

    CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a CRLF sequence in the url parameter.

  • CVE-2006-3125Aug 31, 2006
    risk 0.00cvss —epss 0.04

    Array index error in tetrinet.c in gtetrinet 0.7.8 and earlier allows remote attackers to execute arbitrary code via a packet specifying a negative number of players, which is used as an array index.

  • CVE-2006-4477Aug 31, 2006
    risk 0.04cvss —epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1) GLOBALS[admin_home] parameter in (a) diary/event_list.php, (b)…