|
343691
|
- |
|
apple
|
quicktime
|
Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitiali…
|
NVD-CWE-Other
|
CVE-2006-4389
|
2018-10-18 06:36 |
2006-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343692
|
- |
|
xoops
|
xoops
|
SQL injection vulnerability in edituser.php in Xoops before 2.0.15 allows remote attackers to execute arbitrary SQL commands via the user_avatar parameter.
|
NVD-CWE-Other
|
CVE-2006-4417
|
2018-10-18 06:36 |
2006-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343693
|
- |
|
yapig
|
yapig
|
Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers to inject arbitrary web script or HTML via the D…
|
NVD-CWE-Other
|
CVE-2006-4421
|
2018-10-18 06:36 |
2006-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343694
|
- |
|
gzip
|
gzip
|
unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive.
|
NVD-CWE-Other
|
CVE-2006-4338
|
2018-10-18 06:35 |
2006-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343695
|
- |
|
openssl
|
openssl
|
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PK…
|
CWE-310
Cryptographic Issues
|
CVE-2006-4339
|
2018-10-18 06:35 |
2006-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343696
|
- |
|
microsoft
|
ie
|
The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet E…
|
NVD-CWE-Other
|
CVE-2006-4219
|
2018-10-18 06:34 |
2006-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343697
|
- |
|
ibm
|
egatherer
|
Stack-based buffer overflow in the IBM Access Support eGatherer ActiveX control before 3.20.0284.0 allows remote attackers to execute arbitrary code via a long filename parameter to the RunEgatherer …
|
NVD-CWE-Other
|
CVE-2006-4221
|
2018-10-18 06:34 |
2006-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343698
|
- |
|
vwar
|
virtual_war
|
Cross-site scripting (XSS) vulnerability in calendar.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the year parameter. NOTE: The page…
|
NVD-CWE-Other
|
CVE-2006-4224
|
2018-10-18 06:34 |
2006-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343699
|
- |
|
symantec_veritas
|
netbackup_puredisk_remote_office_edition
|
Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 before MP1 20060816 allows remote attackers to bypass authentication and gain privileges via unknown attack vectors in the management int…
|
NVD-CWE-Other
|
CVE-2006-4228
|
2018-10-18 06:34 |
2006-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343700
|
- |
|
symantec_veritas
|
netbackup_puredisk_remote_office_edition
|
This vulnerability is addresses in the following patch:
Symantec Veritas, NetBackup PureDisk Remote Office Edition, 6.0 MP1 20060816
|
NVD-CWE-Other
|
CVE-2006-4228
|
2018-10-18 06:34 |
2006-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|