|
348851
|
7.5 |
HIGH
|
adobe
|
dreamweaver
|
This vulnerability affects all versions of Adobe, Dreamweaver, 8.0 before 8.0.2
This vulnerability is addressed in the following product releases:
Adobe, Dreamweaver, 8.0.2
Code update for Macrome…
|
NVD-CWE-Other
|
CVE-2006-2042
|
2017-07-20 10:31 |
2006-05-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348852
|
5.0 |
MEDIUM
|
application_dynamics
|
cartweaver_coldfusion
|
Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) category, or (4) keywords…
|
NVD-CWE-Other
|
CVE-2006-2047
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348853
|
6.4 |
MEDIUM
|
quickestore
|
quickestore
|
Multiple SQL injection vulnerabilities in QuickEStore 7.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the OrderID parameter in (a) shipping.cfm and (b) checkout.cfm, …
|
NVD-CWE-Other
|
CVE-2006-2053
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348854
|
5.0 |
MEDIUM
|
3com
|
3c16486
|
3Com Baseline Switch 2848-SFP Plus Model #3C16486 with firmware before 1.0.2.0 allows remote attackers to cause a denial of service (unstable operation) via long DHCP packets.
|
NVD-CWE-Other
|
CVE-2006-2054
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348855
|
5.0 |
MEDIUM
|
3com
|
3c16486
|
Update to firmware version 1.0.2.0.
http://www.3com.com/products/en_...e&order=desc&prodcat=all
|
NVD-CWE-Other
|
CVE-2006-2054
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348856
|
4.6 |
MEDIUM
|
sun
|
solaris
|
Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 might allow local users to gain privileges or cause a denial of service (application failure) via unknown attack vectors that invo…
|
NVD-CWE-Other
|
CVE-2006-2064
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348857
|
5.0 |
MEDIUM
|
hitachi
|
jp1-cm2-network_node_manager jp1-cm2-network_node_manager_250 jpi_automatic_job_management_system_2 jpi_performance_management jpi_pfm_snmp_system_observer jpi_security_integrated_mana…
|
Unspecified vulnerability in Hitachi JP1 products allow remote attackers to cause a denial of service (application stop or fail) via unexpected requests or data.
|
NVD-CWE-Other
|
CVE-2006-2068
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348858
|
5.0 |
MEDIUM
|
powerdns
|
powerdns
|
The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.
|
CWE-399
リソース管理の問題
|
CVE-2006-2069
|
2017-07-20 10:31 |
2006-04-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348859
|
5.0 |
MEDIUM
|
delegate
|
delegate
|
Multiple unspecified vulnerabilities in DeleGate 9.x before 9.0.6 and 8.x before 8.11.6 allow remote attackers to cause a denial of service via crafted DNS responses messages that cause (1) a buffer …
|
NVD-CWE-Other
|
CVE-2006-2072
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348860
|
5.0 |
MEDIUM
|
isc
|
bind
|
Unspecified vulnerability in ISC BIND allows remote attackers to cause a denial of service via a crafted DNS message with a "broken" TSIG, as demonstrated by the OUSPG PROTOS DNS test suite.
|
NVD-CWE-Other
|
CVE-2006-2073
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348861
|
10.0 |
HIGH
|
juniper
|
junose
|
Unspecified vulnerability in Juniper Networks JUNOSe E-series routers before 7-1-1 has unknown impact and remote attack vectors related to the DNS "client code," as demonstrated by the OUSPG PROTOS D…
|
NVD-CWE-Other
|
CVE-2006-2074
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348862
|
5.0 |
MEDIUM
|
don_moore
|
mydns
|
Unspecified vulnerability in MyDNS 1.1.0 allows remote attackers to cause a denial of service via a crafted DNS message, aka "Query-of-death," as demonstrated by the OUSPG PROTOS DNS test suite.
|
NVD-CWE-Other
|
CVE-2006-2075
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348863
|
5.0 |
MEDIUM
|
pdnsd
|
pdnsd
|
Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remote attackers to cause a denial of service (memory consumption) via a DNS query with an unsupported (1) QTYPE or (2) QCLASS, as demonstrated …
|
NVD-CWE-Other
|
CVE-2006-2076
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348864
|
10.0 |
HIGH
|
pdnsd
|
pdnsd
|
Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has unknown impact and attack vectors. NOTE: this issue might be related to the OUSPG PROTOS DNS test suite.
|
NVD-CWE-Other
|
CVE-2006-2077
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348865
|
7.8 |
HIGH
|
furukawa_electric
|
fitelnet mucho-ev_pk
|
Multiple unspecified vulnerabilities in multiple FITELnet products, including FITELnet-F40, F80, F100, F120, F1000, and E20/E30, allow remote attackers to cause a denial of service via crafted DNS me…
|
NVD-CWE-Other
|
CVE-2006-2078
|
2017-07-20 10:31 |
2006-04-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348866
|
7.5 |
HIGH
|
andrew_tridgell
|
rsync
|
Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that t…
|
NVD-CWE-Other
|
CVE-2006-2083
|
2017-07-20 10:31 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348867
|
5.0 |
MEDIUM
|
hitachi
|
groupmax_integrated_desktop groupmax_mail groupmax_world_wide_web groupmax_world_wide_web_desktop
|
The Gmax Mail client in Hitachi Groupmax before 20060426 allows remote attackers to cause a denial of service (application hang or erroneous behavior) via an attachment with an MS-DOS device filename.
|
NVD-CWE-Other
|
CVE-2006-2087
|
2017-07-20 10:31 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348868
|
5.0 |
MEDIUM
|
hp
|
storageworks_secure_path_windows
|
Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-2092
|
2017-07-20 10:31 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348869
|
5.0 |
MEDIUM
|
phex
|
phex
|
Phex before 2.8.6 allows remote attackers to cause a denial of service (application hang) by initiating multiple chat requests to a single user and then logging off.
|
CWE-264
認可・権限・アクセス制御
|
CVE-2006-2095
|
2017-07-20 10:31 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348870
|
6.8 |
MEDIUM
|
kmail
|
kmail
|
Multiple cross-site scripting (XSS) vulnerabilities in Kamgaing Email System (kmail) 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter to main.php,…
|
NVD-CWE-Other
|
CVE-2006-2104
|
2017-07-20 10:31 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348871
|
4.3 |
MEDIUM
|
edgewall_software
|
trac
|
Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors related to a "wiki macro…
|
NVD-CWE-Other
|
CVE-2006-2106
|
2017-07-20 10:31 |
2006-04-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348872
|
2.1 |
LOW
|
virtual_private_server
|
vserver
|
Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only in…
|
NVD-CWE-Other
|
CVE-2006-2110
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348873
|
2.1 |
LOW
|
virtual_private_server
|
vserver
|
This vulnerability is addressed in the following product releases:
Virtual Private Server, Vserver, 2.0.2-rc18
Virtual Private Server, Vserver, 2.1.1-rc18
|
NVD-CWE-Other
|
CVE-2006-2110
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348874
|
6.4 |
MEDIUM
|
network_administration_visualized
|
network_administration_visualized
|
Multiple SQL injection vulnerabilities in the report interface in Network Administration Visualized (NAV) before 3.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-2123
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348875
|
5.8 |
MEDIUM
|
turnkey_solutions
|
sunshop_shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) ite…
|
NVD-CWE-Other
|
CVE-2006-2124
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348876
|
6.4 |
MEDIUM
|
avalon_ltd
|
maxtrade
|
SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categori and (2) stranica parameters.
|
NVD-CWE-Other
|
CVE-2006-2126
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348877
|
5.5 |
MEDIUM
|
deltascripts
|
pro_publish
|
Direct static code injection vulnerability in Pro Publish 2.0 allows remote authenticated administrators to execute arbitrary PHP code by editing certain settings, which are stored in set_inc.php.
|
NVD-CWE-Other
|
CVE-2006-2129
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348878
|
5.1 |
MEDIUM
|
advanced_poll
|
advanced_poll
|
SQL injection vulnerability in include/class_poll.php in Advanced Poll 2.0.4 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
|
NVD-CWE-Other
|
CVE-2006-2130
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348879
|
5.1 |
MEDIUM
|
advanced_poll
|
advanced_poll
|
Successful exploitation requires that magic_quotes_gpc is set to off.
|
NVD-CWE-Other
|
CVE-2006-2130
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348880
|
5.0 |
MEDIUM
|
advanced_poll
|
advanced_poll
|
include/class_poll.php in Advanced Poll 2.0.4 uses the HTTP_X_FORWARDED_FOR (X-Forwarded-For HTTP header) to identify the IP address of a client, which makes it easier for remote attackers to spoof t…
|
NVD-CWE-Other
|
CVE-2006-2131
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348881
|
7.5 |
HIGH
|
boonex
|
barracuda
|
SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) link_dir_target and (2) link_id_target parameter, po…
|
NVD-CWE-Other
|
CVE-2006-2133
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348882
|
7.5 |
HIGH
|
ruperts_news
|
ruperts_news
|
SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2006-2135
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348883
|
7.5 |
HIGH
|
ruperts_news
|
ruperts_news
|
Successful exploitation requires that magic_quotes_gpc is set to off.
|
NVD-CWE-Other
|
CVE-2006-2135
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348884
|
7.5 |
HIGH
|
aznews
|
aznews
|
SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter.
|
NVD-CWE-Other
|
CVE-2006-2136
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348885
|
7.5 |
HIGH
|
aznews
|
aznews
|
Other versions of this product may also be affected by this vulnerability.
|
NVD-CWE-Other
|
CVE-2006-2136
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348886
|
6.4 |
MEDIUM
|
wilsonncareabusinesses
|
php_newsfeed
|
Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) u…
|
NVD-CWE-Other
|
CVE-2006-2139
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348887
|
5.8 |
MEDIUM
|
orbitscripts
|
orbithyip
|
Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter…
|
NVD-CWE-Other
|
CVE-2006-2140
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348888
|
4.3 |
MEDIUM
|
collaborative_portal_server_project
|
collaborative_portal_server
|
Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.
|
NVD-CWE-Other
|
CVE-2006-2141
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348889
|
6.4 |
MEDIUM
|
harold_bakker
|
hb-ns
|
Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) topic or (2) id parameter.
|
NVD-CWE-Other
|
CVE-2006-2145
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348890
|
5.8 |
MEDIUM
|
harold_bakker
|
hb-ns
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in HB-NS 1.1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) poster_name, (2) poster_email, (3) poster_hom…
|
NVD-CWE-Other
|
CVE-2006-2146
|
2017-07-20 10:31 |
2006-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348891
|
3.6 |
LOW
|
resmgr
|
resmgrd
|
resmgrd in resmgr for SUSE Linux and other distributions does not properly handle when access to a USB device is granted by using "usb:<bus>,<dev>" notation, which grants access to all USB devices an…
|
NVD-CWE-Other
|
CVE-2006-2147
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348892
|
7.5 |
HIGH
|
cgiirc
|
cgiirc
|
Multiple buffer overflows in client.c in CGI:IRC (CGIIRC) before 0.5.8 might allow remote attackers to execute arbitrary code via (1) cookies or (2) the query string.
|
NVD-CWE-Other
|
CVE-2006-2148
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348893
|
7.2 |
HIGH
|
emc
|
retrospect
|
EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the F…
|
NVD-CWE-Other
|
CVE-2006-2154
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348894
|
7.2 |
HIGH
|
emc
|
retrospect
|
Apply Retrospect Driver Update 7.5.1.105.
Apply Application Security Update 7.0.344 (requires Retrospect 7.0.326 or Retrospect Express 7.0.301).
Apply Application Security Update 6.5.382 (requires …
|
NVD-CWE-Other
|
CVE-2006-2154
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348895
|
4.6 |
MEDIUM
|
emc
|
retrospect
|
EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 allows local users to execute arbitrary code by replacing the Retrospect.exe file, possibly due to improper…
|
NVD-CWE-Other
|
CVE-2006-2155
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348896
|
4.6 |
MEDIUM
|
emc
|
retrospect
|
Retrospect 7.5:
Apply Retrospect Driver Update 7.5.1.105.
http://ftp.dantz.com/pub/updates/ru751105.exe
Retrospect 7.0:
Apply Application Security Update 7.0.344 (requires Retrospect 7.0.326 or…
|
NVD-CWE-Other
|
CVE-2006-2155
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348897
|
7.5 |
HIGH
|
plogger
|
plogger
|
SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to "slideshow". NOTE:…
|
CWE-89
SQLインジェクション
|
CVE-2006-2157
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348898
|
6.4 |
MEDIUM
|
stadtaus
|
guestbook_script
|
Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables vi…
|
NVD-CWE-Other
|
CVE-2006-2158
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348899
|
6.4 |
MEDIUM
|
stadtaus
|
guestbook_script
|
Download Guestbook Script 1.9
|
NVD-CWE-Other
|
CVE-2006-2158
|
2017-07-20 10:31 |
2006-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348900
|
2.6 |
LOW
|
desert_dog_software
|
pinnacle_cart
|
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.
|
NVD-CWE-Other
|
CVE-2006-2163
|
2017-07-20 10:31 |
2006-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|