VYPR

CVEs

380,939 total · page 7251 of 7,619

  • CVE-2006-3269Jun 28, 2006
    risk 0.03cvss —epss 0.03

    PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

  • CVE-2006-3270Jun 28, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in cms_admin.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via multiple unspecified parameters, such as the add_link_mid parameter. NOTE: the provenance of this information is unknown; portions of the details are…

  • CVE-2006-3271Jun 28, 2006
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in (c) products.php, (d)…

  • CVE-2006-3272Jun 28, 2006
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in menu.php in Some Chess 1.5 rc2 allows remote attackers to conduct actions as another user, such as changing usernames and passwords, via unspecified vectors. NOTE: the provenance of this information is unknown; the details are…

  • CVE-2006-3273Jun 28, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 rc1 allows remote attackers to inject arbitrary web script or HTML via the user parameter ("New Name" field).

  • CVE-2006-3274Jun 28, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) characters in the URL to certain directories under the web root, such as the image directory.

  • CVE-2006-3275Jun 28, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and earlier allows remote attackers to execute SQL commands via a double-encoded user parameter in a viewprofile action.

  • CVE-2006-3276Jun 28, 2006
    risk 0.01cvss —epss 0.14

    Heap-based buffer overflow in RealNetworks Helix DNA Server 10.0 and 11.0 allows remote attackers to execute arbitrary code via (1) a long User-Agent HTTP header in the RTSP service and (2) unspecified vectors involving the "parsing of HTTP URL schemes".

  • CVE-2006-3277Jun 28, 2006
    risk 0.03cvss —epss 0.06

    The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument,…

  • CVE-2006-3278Jun 28, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) next_template, (2) start, (3) curr_menu_id, and (4) arid parameters in psoft/servlet/resadmin/psoft.hsphere.CP when using the…

  • CVE-2006-3279Jun 28, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in aeDating 4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) Sex parameter in index.php, (2) ProfileType parameter in join_form.php, and (3) Email parameter in forgot.php.

  • CVE-2006-3280Jun 28, 2006
    risk 0.07cvss —epss 0.56

    Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that…

  • CVE-2006-3281Jun 28, 2006
    risk 0.07cvss —epss 0.48

    Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the…

  • CVE-2006-3282Jun 28, 2006
    risk 0.00cvss —epss 0.01

    requirements.php in Dating Agent PRO 4.7.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.

  • CVE-2006-3283Jun 28, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php.

  • CVE-2006-3284Jun 28, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in (1) webmaster/index.php and (2) search.php.

  • CVE-2006-3285Jun 28, 2006
    risk 0.00cvss —epss 0.03

    The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and password, which allows remote authenticated users to read, and possibly modify, sensitive configuration data (aka bugs CSCsd15955).

  • CVE-2006-2200Jun 28, 2006
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4)…

  • CVE-2006-3253Jun 28, 2006
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the…

  • CVE-2006-3254Jun 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

  • CVE-2006-3255Jun 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

  • CVE-2006-3256Jun 28, 2006
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

  • CVE-2006-3257Jun 28, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7 allow remote attackers to inject arbitrary HTML or web script via unspecified attack vectors, possibly including (1) calendar/myagenda.php, (2) document/document.php, (3) phpbb/newtopic.php, (4)…

  • CVE-2006-0456Jun 27, 2006
    risk 0.00cvss —epss 0.00

    The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.

  • CVE-2006-1469Jun 27, 2006
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.

  • CVE-2006-1470Jun 27, 2006
    risk 0.04cvss —epss 0.08

    OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.

  • CVE-2006-1471Jun 27, 2006
    risk 0.00cvss —epss 0.00

    Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted…

  • CVE-2006-1468Jun 27, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information.

  • CVE-2006-3223Jun 27, 2006
    risk 0.01cvss —epss 0.07

    Format string vulnerability in CA Integrated Threat Management (ITM), eTrust Antivirus (eAV), and eTrust PestPatrol (ePP) r8 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a scan job with format strings in the description field.

  • CVE-2006-3258Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.html in BNBT TrinEdit and EasyTracker 7.7r3.2004.10.27 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) filter or (2) sort parameters.

  • CVE-2006-3259Jun 27, 2006
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment).

  • CVE-2006-3260Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in vlbook 1.02 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

  • CVE-2006-3261Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Trend Micro Control Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web script or HTML via the username field on the login page, which is not properly sanitized before being displayed in the error log.

  • CVE-2006-3262Jun 27, 2006
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

  • CVE-2006-3263Jun 27, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

  • CVE-2006-3264Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo DeepSearch 4.5 allows remote attackers to inject arbitrary web script or HTML via the p parameter.

  • CVE-2006-3265Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Qdig before 1.2.9.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pre_gallery or (2) post_gallery parameters.

  • CVE-2006-3266Jun 27, 2006
    risk 0.04cvss —epss 0.18

    Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and (b) include/rootGui.inc.php;…

  • CVE-2006-3267Jun 27, 2006
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in index.php in Infinite Core Technologies (ICT) 1.0 Gold and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.

  • CVE-2006-3250Jun 27, 2006
    risk 0.01cvss —epss 0.07

    Heap-based buffer overflow in Windows Live Messenger 8.0 allows user-assisted attackers to execute arbitrary code via a crafted Contact List (.ctt) file, which triggers the overflow when it is imported by the user.

  • CVE-2006-3251Jun 27, 2006
    risk 0.00cvss —epss 0.04

    Heap-based buffer overflow in the array_push function in hashcash.c for Hashcash before 1.21 might allow attackers to execute arbitrary code via crafted entries.

  • CVE-2006-3252Jun 27, 2006
    risk 0.08cvss —epss 0.62

    Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request.

  • CVE-2006-3134Jun 27, 2006
    risk 0.01cvss —epss 0.11

    Buffer overflow in GraceNote CDDBControl ActiveX Control, as used by multiple products that use Gracenote CDDB, allows remote attackers to execute arbitrary code via a long option string.

  • CVE-2006-3230Jun 27, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows remote attackers to inject arbitrary web script or HTML via the search parameter.

  • CVE-2006-3231Jun 27, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."

  • CVE-2006-3232Jun 27, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."

  • CVE-2006-3233Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in Open WebMail (OWM) 2.52, and other versions released before 06/18/2006, allows remote attackers to inject arbitrary web script or HTML via the from field. NOTE: some third party sources have mentioned the "to"…

  • CVE-2006-3234Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) produkt, (2) id_produc, and (3) id_kat parameters.

  • CVE-2006-3235Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc parameters.

  • CVE-2006-3236Jun 27, 2006
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in thinkWMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) index.php or (b) printarticle.php, and the (2) catid parameter in index.php.