Searching...
Please wait while we search the database
| CVE ID | Severity | Description | Published | Actions |
|---|---|---|---|---|
|
CVE-2006-6017
|
N/A |
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
|
21 Nov 2006
|
|
|
CVE-2006-5738
|
N/A |
Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.
|
06 Nov 2006
|
|
|
CVE-2006-5708
|
N/A |
Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.
|
04 Nov 2006
|
|
|
CVE-2006-5632
|
N/A |
Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
|
31 Oct 2006
|
|
|
CVE-2006-5610
|
N/A |
PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
|
31 Oct 2006
|
|
|
CVE-2006-5603
|
N/A |
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
30 Oct 2006
|
|
|
CVE-2006-5393
|
N/A |
Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.
|
18 Oct 2006
|
|
|
CVE-2006-5021
|
N/A |
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
|
27 Sep 2006
|
|
|
CVE-2006-5024
|
N/A |
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors.
|
27 Sep 2006
|
|
|
CVE-2006-5014
|
N/A |
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
|
27 Sep 2006
|
|
|
CVE-2006-0149
|
N/A |
Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.
|
09 Jan 2006
|
|
|
CVE-1999-0186
|
N/A |
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
|
04 Feb 2000
|
|
|
CVE-1999-0254
|
N/A |
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.
|
04 Feb 2000
|
|
|
CVE-1999-0516
|
N/A |
An SNMP community name is guessable.
|
04 Feb 2000
|
|
|
CVE-1999-0517
|
N/A |
An SNMP community name is the default (e.g. public), null, or missing.
|
04 Feb 2000
|
|
|
CVE-1999-0524
|
N/A |
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
|
04 Feb 2000
|
|
|
CVE-1999-0532
|
N/A |
A DNS server allows zone transfers.
|
04 Feb 2000
|
|
|
CVE-1999-0016
|
N/A |
Land IP denial of service.
|
29 Sep 1999
|
|
|
CVE-1999-0103
|
N/A |
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.
|
29 Sep 1999
|
|
|
CVE-1999-0472
|
N/A |
The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.
|
29 Sep 1999
|
CVE-2006-6017
N/A
21 Nov 2006
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
CVE-2006-5738
N/A
06 Nov 2006
Multiple SQL injection vulnerabilities in PunBB before 1.2.14 allow remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors.
CVE-2006-5708
N/A
04 Nov 2006
Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory leaks.
CVE-2006-5632
N/A
31 Oct 2006
Cross-site scripting (XSS) vulnerability in change_pass.php in iG Shop 1.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-5631. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2006-5610
N/A
31 Oct 2006
PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
CVE-2006-5603
N/A
30 Oct 2006
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2006-5393
N/A
18 Oct 2006
Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.
CVE-2006-5021
N/A
27 Sep 2006
Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
CVE-2006-5024
N/A
27 Sep 2006
Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors.
CVE-2006-5014
N/A
27 Sep 2006
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
CVE-2006-0149
N/A
09 Jan 2006
Cross-site scripting (XSS) vulnerability in SimpBook 1.0, with html_enable on (the default), allows remote attackers to inject arbitrary web script or HTML via the message field.
CVE-1999-0186
N/A
04 Feb 2000
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
CVE-1999-0254
N/A
04 Feb 2000
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.
CVE-1999-0516
N/A
04 Feb 2000
An SNMP community name is guessable.
CVE-1999-0517
N/A
04 Feb 2000
An SNMP community name is the default (e.g. public), null, or missing.
CVE-1999-0524
N/A
04 Feb 2000
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
CVE-1999-0532
N/A
04 Feb 2000
A DNS server allows zone transfers.
CVE-1999-0016
N/A
29 Sep 1999
Land IP denial of service.
CVE-1999-0103
N/A
29 Sep 1999
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.
CVE-1999-0472
N/A
29 Sep 1999
The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.
Page 615 of 615
Page 615 of 615