VYPR

CVEs

381,325 total · page 7241 of 7,627

  • CVE-2006-4232Aug 18, 2006
    risk 0.00cvss —epss 0.00

    Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.

  • CVE-2006-4233Aug 18, 2006
    risk 0.00cvss —epss 0.00

    Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local users to obtain sensitive information (proxy certificates) and overwrite arbitrary files via a symlink attack on temporary files in the /tmp directory, as demonstrated by files created by (1)…

  • CVE-2006-4234Aug 18, 2006
    risk 0.04cvss —epss 0.06

    PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

  • CVE-2006-4219Aug 18, 2006
    risk 0.05cvss —epss 0.22

    The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.

  • CVE-2006-4217Aug 17, 2006
    risk 0.03cvss —epss 0.02

    PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is…

  • CVE-2006-4218Aug 17, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter parameter.

  • CVE-2006-4021Aug 17, 2006
    risk 0.00cvss —epss 0.01

    The cryptographic module in ScatterChat 1.0.x allows attackers to identify patterns in large numbers of messages by identifying collisions using a birthday attack on the custom padding mechanism for ECB mode encryption.

  • CVE-2006-4195Aug 17, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in…

  • CVE-2006-4196Aug 17, 2006
    risk 0.04cvss —epss 0.10

    PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir parameter.

  • CVE-2006-4197Aug 17, 2006
    risk 0.04cvss —epss 0.15

    Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which…

  • CVE-2006-4198Aug 17, 2006
    risk 0.03cvss —epss 0.06

    PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wb_class_dir parameter.

  • CVE-2006-4199Aug 17, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page, a different vulnerability than CVE-2004-1512.

  • CVE-2006-4200Aug 17, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing.

  • CVE-2006-4201Aug 17, 2006
    risk 0.01cvss —epss 0.10

    Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation.

  • CVE-2006-4202Aug 17, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.

  • CVE-2006-4203Aug 17, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

  • CVE-2006-4204Aug 17, 2006
    risk 0.04cvss —epss 0.08

    Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_pre parameter in lib/specialdays.php and the (2) lib_path parameter in lib/dbman_filter.inc.php.

  • CVE-2006-4205Aug 17, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to /classes/ scripts including (1) Cache.class.php, (2) Customer.class.php, (3) Performance.class.php,…

  • CVE-2006-4206Aug 17, 2006
    risk 0.03cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter.

  • CVE-2006-4207Aug 17, 2006
    risk 0.03cvss —epss 0.03

    Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php.

  • CVE-2006-4208Aug 17, 2006
    risk 0.04cvss —epss 0.12

    Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.

  • CVE-2006-4209Aug 17, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter.

  • CVE-2006-4210Aug 17, 2006
    risk 0.03cvss —epss 0.02

    nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from…

  • CVE-2006-4211Aug 17, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2006-4212Aug 17, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2006-4213Aug 17, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

  • CVE-2006-4214Aug 17, 2006
    risk 0.00cvss —epss 0.03

    Multiple SQL injection vulnerabilities in Zen Cart 1.3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) GPC data to the ipn_get_stored_session function in ipn_main_handler.php, which can be leveraged to modify elements of $_SESSION; and allow…

  • CVE-2006-4215Aug 17, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter.

  • CVE-2006-3121Aug 17, 2006
    risk 0.04cvss —epss 0.14

    The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.

  • CVE-2006-3854Aug 17, 2006
    risk 0.00cvss —epss 0.04

    Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message.…

  • CVE-2006-3859Aug 17, 2006
    risk 0.00cvss —epss 0.01

    IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.

  • CVE-2006-3860Aug 17, 2006
    risk 0.00cvss —epss 0.03

    IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 allows allows remote authenticated users to execute arbitrary commands via the (1) "SET DEBUG FILE" SQL command, and the (2) start_onpload and (3) dbexp functions.

  • CVE-2006-4189Aug 17, 2006
    risk 0.00cvss —epss 0.06

    Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php, (5) click.php, (6) faq.php, (7) gallery.php, (8) im.php, (9)…

  • CVE-2006-4190Aug 17, 2006
    risk 0.03cvss —epss 0.01

    Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation.

  • CVE-2006-4191Aug 17, 2006
    risk 0.04cvss —epss 0.10

    Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an…

  • CVE-2006-4192Aug 17, 2006
    risk 0.04cvss —epss 0.09

    Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the…

  • CVE-2006-4193Aug 17, 2006
    risk 0.07cvss —epss 0.47

    Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME),…

  • CVE-2006-4194Aug 17, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006-4032. NOTE: the…

  • CVE-2006-4184Aug 17, 2006
    risk 0.00cvss —epss 0.00

    SmartLine DeviceLock before 5.73 Build 305 does not properly enforce access control lists (ACL) in raw mode, which allows local users to bypass NTFS controls and obtain sensitive information.

  • CVE-2006-4185Aug 17, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the NCPENGINE in Novell eDirectory 8.7.3.8 allows local users to cause a denial of service (CPU consumption) via unspecified vectors, as originally demonstrated using a Nessus scan.

  • CVE-2006-4186Aug 17, 2006
    risk 0.00cvss —epss 0.01

    The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes passwords in plaintext to a log file, which allows local users to obtain passwords by reading the file.

  • CVE-2006-4187Aug 17, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in HP-UX B.11.00, B.11.11 and B.11.23, when running in trusted mode, allows local users to cause a denial of service via unspecified vectors.

  • CVE-2006-4188Aug 17, 2006
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in the LP subsystem in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.

  • CVE-2006-4030Aug 16, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "two file exposure bugs."

  • CVE-2006-4155Aug 16, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic."

  • CVE-2006-4156Aug 16, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtotemplate parameter. NOTE: a third party claims that the researcher is incorrect, because template.php defines…

  • CVE-2006-4157Aug 16, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.

  • CVE-2006-4158Aug 16, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

  • CVE-2006-4159Aug 16, 2006
    risk 0.04cvss —epss 0.15

    Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _BASE parameter to scripts in Classes/ including (1) Evenement.php, (2) Event.php, (3) Event_for_month.php, (4)…

  • CVE-2006-4160Aug 16, 2006
    risk 0.04cvss —epss 0.09

    Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the glConf[path_library] parameter to (1) BaseCommand.php, (2) BaseLoader.php, and (3) BaseView.php.