|
345351
|
2.1 |
LOW
|
tor
|
tor
|
Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for…
|
CWE-200
Information Exposure
|
CVE-2010-0384
|
2011-04-27 13:00 |
2010-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345352
|
6.8 |
MEDIUM
|
fetchmail
|
fetchmail
|
The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (applic…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-0562
|
2011-04-27 13:00 |
2010-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345353
|
5.1 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly …
|
NVD-CWE-noinfo
|
CVE-2006-3497
|
2011-04-7 13:00 |
2006-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345354
|
4.3 |
MEDIUM
|
ibm
|
webi
|
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2010-1242
|
2011-04-7 12:18 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345355
|
7.5 |
HIGH
|
ibm
|
webi
|
The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2010-1243
|
2011-04-7 12:18 |
2010-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345356
|
4.3 |
MEDIUM
|
apple
|
safari webkit
|
The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle the :visited …
|
CWE-200
Information Exposure
|
CVE-2010-2264
|
2011-03-18 11:50 |
2010-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345357
|
7.2 |
HIGH
|
apple
|
itunes
|
Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges via a malicious C:\program.exe file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2005-2938
|
2011-03-10 14:00 |
2005-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345358
|
5.8 |
MEDIUM
|
django_project
|
django
|
The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to con…
|
CWE-352
Origin Validation Error
|
CVE-2008-3909
|
2011-03-8 12:11 |
2008-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345359
|
7.5 |
HIGH
|
cchost
|
cchost
|
SQL injection vulnerability in Creative Commons Tools ccHost before 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URL, which is used to populate the file ID. NOTE: Some…
|
NVD-CWE-Other
|
CVE-2006-4778
|
2011-03-8 11:42 |
2006-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345360
|
6.2 |
MEDIUM
|
roxio
|
toast
|
Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary files, including dejavu_manual.rb, which are execu…
|
CWE-362
Race Condition
|
CVE-2006-4801
|
2011-03-8 11:42 |
2006-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345361
|
10.0 |
HIGH
|
iodine
|
iodine
|
Unspecified vulnerability in IP over DNS is now easy (iodine) before 0.3.2 has unknown impact and attack vectors, related to "potential security problems."
|
NVD-CWE-Other
|
CVE-2006-4831
|
2011-03-8 11:42 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345362
|
10.0 |
HIGH
|
iodine
|
iodine
|
This vulnerability is addressed in the following product release:
Iodine, Iodine, 0.3.2
|
NVD-CWE-Other
|
CVE-2006-4831
|
2011-03-8 11:42 |
2006-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345363
|
5.1 |
MEDIUM
|
joomla
|
joomla
|
Unspecified vulnerability in com_content in Joomla! before 1.0.11, when $mosConfig_hideEmail is set, allows attackers to perform the emailform and emailsend tasks.
|
NVD-CWE-Other
|
CVE-2006-4473
|
2011-03-8 11:41 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345364
|
7.5 |
HIGH
|
joomla
|
joomla
|
Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-4475
|
2011-03-8 11:41 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345365
|
7.5 |
HIGH
|
joomla
|
joomla
|
Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) globals.php, which uses include_once() instead of requir…
|
CWE-94 CWE-264
Code Injection Permissions, Privileges, and Access Controls
|
CVE-2006-4476
|
2011-03-8 11:41 |
2006-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345366
|
7.2 |
HIGH
|
ibm
|
aix
|
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-4522
|
2011-03-8 11:41 |
2006-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345367
|
6.8 |
MEDIUM
|
vtiger
|
vtiger_crm
|
Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 4.2.4, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) description parameter in unspe…
|
NVD-CWE-Other
|
CVE-2006-4587
|
2011-03-8 11:41 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345368
|
7.5 |
HIGH
|
vtiger
|
vtiger_crm
|
vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to bypass authentication and access administrative modules via a direct request to index.php with a modified module parameter, as demon…
|
NVD-CWE-Other
|
CVE-2006-4588
|
2011-03-8 11:41 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345369
|
7.5 |
HIGH
|
bare_concept_media
|
pheap_cms
|
PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenan…
|
NVD-CWE-Other
|
CVE-2006-4621
|
2011-03-8 11:41 |
2006-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345370
|
7.5 |
HIGH
|
alwil
|
avast_antivirus
|
Heap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file that contains extended headers with file and direc…
|
NVD-CWE-Other
|
CVE-2006-4626
|
2011-03-8 11:41 |
2006-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345371
|
7.5 |
HIGH
|
alwil
|
avast_antivirus
|
This vulnerability is addressed in the following product releases:
ALWIL, avast! antivirus, 4.7.869 (for Desktops)
ALWIL, avast! antivirus, Server 4.7.660 (for Servers)
|
NVD-CWE-Other
|
CVE-2006-4626
|
2011-03-8 11:41 |
2006-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345372
|
7.5 |
HIGH
|
uni-vert
|
phpleague
|
SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the id_joueur parameter. NOTE: the provenance …
|
NVD-CWE-Other
|
CVE-2006-4643
|
2011-03-8 11:41 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345373
|
5.0 |
MEDIUM
|
ibm
|
director
|
Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests an…
|
NVD-CWE-Other
|
CVE-2006-4682
|
2011-03-8 11:41 |
2006-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345374
|
5.0 |
MEDIUM
|
ibm
|
director
|
This vulnerability is addressed in the following product release:
IBM, Director, 5.10
|
NVD-CWE-Other
|
CVE-2006-4682
|
2011-03-8 11:41 |
2006-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345375
|
5.0 |
MEDIUM
|
ibm
|
director
|
IBM Director before 5.10 allows remote attackers to obtain sensitive information from HTTP headers via HTTP TRACE.
|
NVD-CWE-Other
|
CVE-2006-4683
|
2011-03-8 11:41 |
2006-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345376
|
5.0 |
MEDIUM
|
zope
|
zope
|
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary…
|
NVD-CWE-Other
|
CVE-2006-4684
|
2011-03-8 11:41 |
2006-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345377
|
7.5 |
HIGH
|
drupal
|
drupal_pubcookie_module
|
The login redirection mechanism in the Drupal 4.7 Pubcookie module before 1.2.2.4 2006/09/06 and the Drupal 4.6 Pubcookie module before 1.6.2.1 2006/09/07 allows remote attackers to bypass authentica…
|
NVD-CWE-Other
|
CVE-2006-4717
|
2011-03-8 11:41 |
2006-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345378
|
7.5 |
HIGH
|
drupal
|
drupal_pubcookie_module
|
Drupal core is not affected. If you do not use the pubcookie module, no action is necessary.
|
NVD-CWE-Other
|
CVE-2006-4717
|
2011-03-8 11:41 |
2006-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345379
|
5.0 |
MEDIUM
|
symantec
|
brightmail_antispam
|
Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control Center is allowed to connect from any computer, allows remote attackers to cause a denial of service (application freeze) "by sendin…
|
NVD-CWE-Other
|
CVE-2006-4014
|
2011-03-8 11:40 |
2006-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345380
|
4.3 |
MEDIUM
|
toenda_software_development
|
toendacms
|
Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS stable 1.0.3 and earlier, and unstable 1.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via the s pa…
|
NVD-CWE-Other
|
CVE-2006-4016
|
2011-03-8 11:40 |
2006-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345381
|
4.6 |
MEDIUM
|
intel
|
2100_proset_wireless
|
Intel 2100 PRO/Wireless Network Connection driver PROSet before 7.1.4.6 allows local users to corrupt memory and execute code via "requests for capabilities from higher-level protocol drivers or user…
|
NVD-CWE-Other
|
CVE-2006-4022
|
2011-03-8 11:40 |
2006-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345382
|
7.5 |
HIGH
|
festalon
|
festalon
|
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr…
|
NVD-CWE-Other
|
CVE-2006-4024
|
2011-03-8 11:40 |
2006-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345383
|
5.0 |
MEDIUM
|
gallery_project
|
gallery
|
Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "two file exposure bu…
|
NVD-CWE-Other
|
CVE-2006-4030
|
2011-03-8 11:40 |
2006-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345384
|
5.0 |
MEDIUM
|
gallery_project
|
gallery
|
Update to version 1.5-pl1.
|
NVD-CWE-Other
|
CVE-2006-4030
|
2011-03-8 11:40 |
2006-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345385
|
10.0 |
HIGH
|
fenestrae
|
faxination_server
|
Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet.
|
NVD-CWE-Other
|
CVE-2006-4037
|
2011-03-8 11:40 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345386
|
7.5 |
HIGH
|
ehmig
|
me_download_system
|
Multiple PHP remote file inclusion vulnerabilities in ME Download System 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) Vb8878b936c2bd8ae0cab parameter to (a) inc/sett_…
|
NVD-CWE-Other
|
CVE-2006-4054
|
2011-03-8 11:40 |
2006-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345387
|
5.1 |
MEDIUM
|
wim_fleischhauer
|
docpile_we
|
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parame…
|
NVD-CWE-Other
|
CVE-2006-4076
|
2011-03-8 11:40 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345388
|
5.1 |
MEDIUM
|
wim_fleischhauer
|
docpile_we
|
Successful exploitation requires that "register_globals" is enabled.
|
NVD-CWE-Other
|
CVE-2006-4076
|
2011-03-8 11:40 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345389
|
4.3 |
MEDIUM
|
ozjournals
|
ozjournals
|
Cross-site scripting (XSS) vulnerability in index.php in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.…
|
NVD-CWE-Other
|
CVE-2006-4086
|
2011-03-8 11:40 |
2006-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345390
|
7.5 |
HIGH
|
ibm
|
websphere_application_server
|
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadId…
|
CWE-200 CWE-264
Information Exposure Permissions, Privileges, and Access Controls
|
CVE-2006-4136
|
2011-03-8 11:40 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345391
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server before 6.1.0.1 allows attackers to obtain sensitive information via unspecified vectors related to (1) the log file, (2) "script generated syntax on wsadmin command l…
|
NVD-CWE-Other
|
CVE-2006-4137
|
2011-03-8 11:40 |
2006-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345392
|
7.5 |
HIGH
|
invision_power_services
|
invision_power_board
|
Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic."
|
NVD-CWE-Other
|
CVE-2006-4155
|
2011-03-8 11:40 |
2006-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345393
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.0.2.13 have unspecified vectors and impact, including (1) an "authority problem" in ThreadIdentitySupport as identifi…
|
NVD-CWE-Other
|
CVE-2006-4222
|
2011-03-8 11:40 |
2006-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345394
|
5.0 |
MEDIUM
|
twiki
|
twiki
|
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
|
NVD-CWE-Other
|
CVE-2006-4294
|
2011-03-8 11:40 |
2006-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345395
|
5.0 |
MEDIUM
|
cgi-rescue
|
mail_f_w_system
|
CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) before 8.3 allows remote attackers to spoof e-mails and inject e-mail headers via unspecified vectors in (1) mail.cgi and (2) query.…
|
NVD-CWE-Other
|
CVE-2006-4344
|
2011-03-8 11:40 |
2006-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345396
|
6.4 |
MEDIUM
|
doctor_web_ltd
|
dr.web
|
Heap-based buffer overflow in SpIDer for Dr.Web Scanner for Linux 4.33, and possibly earlier versions, allows remote attackers to execute arbitrary code via an LHA archive with an extended header tha…
|
NVD-CWE-Other
|
CVE-2006-4438
|
2011-03-8 11:40 |
2006-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345397
|
7.5 |
HIGH
|
ay_system_solutions
|
ay_system_solutions_cms
|
Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path[ShowProcessHandle] parameter t…
|
NVD-CWE-Other
|
CVE-2006-4441
|
2011-03-8 11:40 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345398
|
6.8 |
MEDIUM
|
clemens_wacha
|
php_iaddressbook
|
Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.95 allows remote attackers to inject arbitrary web script or HTML via the cat_name parameter, related to adding a category. (cate…
|
NVD-CWE-Other
|
CVE-2006-4442
|
2011-03-8 11:40 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345399
|
7.2 |
HIGH
|
x.org
|
emu-linux-x87-xlibs x11r6 x11r7 xdm xf86dga xinit xload xorg-server xterm
|
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow…
|
NVD-CWE-Other
|
CVE-2006-4447
|
2011-03-8 11:40 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345400
|
7.5 |
HIGH
|
cj_design
|
cj_tag_board
|
Direct static code injection vulnerability in CJ Tag Board 3.0 allows remote attackers to execute arbitrary PHP code via the (1) User-Agent HTTP header in tag.php, which is executed by all.php, and (…
|
NVD-CWE-Other
|
CVE-2006-4451
|
2011-03-8 11:40 |
2006-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|