|
349451
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
This vulnerability is addressed in the following product release:
Apple, Mac OS X, 10.4.7
|
NVD-CWE-noinfo
|
CVE-2006-1468
|
2017-07-20 10:30 |
2006-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349452
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.
|
CWE-119
バッファエラー
|
CVE-2006-1469
|
2017-07-20 10:30 |
2006-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349453
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.
|
CWE-399
リソース管理の問題
|
CVE-2006-1470
|
2017-07-20 10:30 |
2006-06-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349454
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2006-1473
|
2017-07-20 10:30 |
2006-08-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349455
|
4.3 |
MEDIUM
|
serge_rey
|
gtd-php
|
Multiple cross-site scripting (XSS) vulnerabilities in Serge Rey gtd-php (aka Getting Things Done) 0.5 allow remote attackers to inject arbitrary web script or HTML via the Description field in (1) n…
|
NVD-CWE-Other
|
CVE-2006-1479
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349456
|
6.5 |
MEDIUM
|
greymatter
|
greymatter
|
gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root. NOTE: the provenance of …
|
NVD-CWE-Other
|
CVE-2006-1485
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349457
|
4.3 |
MEDIUM
|
fusionzone
|
realestatezone
|
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) st…
|
NVD-CWE-Other
|
CVE-2006-1486
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349458
|
4.3 |
MEDIUM
|
activecampaign
|
supporttrio
|
Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search mod…
|
NVD-CWE-Other
|
CVE-2006-1487
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349459
|
5.0 |
MEDIUM
|
activecampaign
|
supporttrio
|
ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category pa…
|
NVD-CWE-Other
|
CVE-2006-1488
|
2017-07-20 10:30 |
2006-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349460
|
7.5 |
HIGH
|
fusionzone
|
couponzone
|
Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid par…
|
NVD-CWE-Other
|
CVE-2006-1489
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349461
|
7.5 |
HIGH
|
horde
|
application_framework
|
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
|
CWE-94
コード・インジェクション
|
CVE-2006-1491
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349462
|
5.0 |
MEDIUM
|
nikolay_avrionov
|
explorer_xp
|
Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter.
|
NVD-CWE-Other
|
CVE-2006-1492
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349463
|
4.3 |
MEDIUM
|
nikolay_avrionov
|
explorer_xp
|
Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter. NOTE: it is possible that this issue is re…
|
NVD-CWE-Other
|
CVE-2006-1493
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349464
|
4.3 |
MEDIUM
|
vihor
|
vihordesign
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is pro…
|
NVD-CWE-Other
|
CVE-2006-1496
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349465
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.
|
NVD-CWE-Other
|
CVE-2006-1498
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349466
|
7.5 |
HIGH
|
tilde
|
tilde_cms
|
SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQLインジェクション
|
CVE-2006-1500
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349467
|
7.5 |
HIGH
|
oneorzero
|
oneorzero
|
SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.
|
CWE-89
SQLインジェクション
|
CVE-2006-1501
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349468
|
4.3 |
MEDIUM
|
mh_software
|
connect_daily
|
Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cale…
|
NVD-CWE-Other
|
CVE-2006-1508
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349469
|
4.0 |
MEDIUM
|
microsoft
|
.net_framework
|
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers t…
|
NVD-CWE-Other
|
CVE-2006-1510
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349470
|
4.0 |
MEDIUM
|
microsoft
|
.net_framework
|
Succesful exploitation can only occur when ntdll.dll system library is used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK packages.
|
NVD-CWE-Other
|
CVE-2006-1510
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349471
|
5.1 |
MEDIUM
|
microsoft
|
.net_framework
|
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
|
NVD-CWE-Other
|
CVE-2006-1511
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349472
|
5.1 |
MEDIUM
|
abc2ps
|
abc2ps
|
Multiple buffer overflows in abc2ps before 1.3.3 allow user-assisted attackers to execute arbitrary code via crafted ABC music files.
|
CWE-119
バッファエラー
|
CVE-2006-1513
|
2017-07-20 10:30 |
2006-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349473
|
6.4 |
MEDIUM
|
libspf
|
libspf
|
Format string vulnerability in ANSI C Sender Policy Framework library (libspf) before 1.0.0-p5, when debugging is enabled, allows remote attackers to execute arbitrary code via format string specifie…
|
NVD-CWE-Other
|
CVE-2006-1520
|
2017-07-20 10:30 |
2006-05-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349474
|
3.6 |
LOW
|
linux
|
linux_kernel
|
madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with z…
|
CWE-264
認可・権限・アクセス制御
|
CVE-2006-1524
|
2017-07-20 10:30 |
2006-04-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349475
|
4.3 |
MEDIUM
|
deltascripts
|
php_classifieds
|
Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword pa…
|
NVD-CWE-Other
|
CVE-2006-1532
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349476
|
7.5 |
HIGH
|
bsd-games
|
tetris-bsd
|
Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by m…
|
NVD-CWE-Other
|
CVE-2006-1539
|
2017-07-20 10:30 |
2006-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349477
|
4.3 |
MEDIUM
|
apache
|
struts
|
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote att…
|
NVD-CWE-Other
|
CVE-2006-1548
|
2017-07-20 10:30 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349478
|
5.0 |
MEDIUM
|
apple
|
safari imageio mac_os_x mac_os_x_server
|
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated usi…
|
CWE-189
数値処理の問題
|
CVE-2006-1552
|
2017-07-20 10:30 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349479
|
4.6 |
MEDIUM
|
debian
|
debian_linux
|
Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so…
|
NVD-CWE-Other
|
CVE-2006-1564
|
2017-07-20 10:30 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349480
|
4.6 |
MEDIUM
|
debian
|
debian_linux
|
Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to …
|
NVD-CWE-Other
|
CVE-2006-1565
|
2017-07-20 10:30 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349481
|
4.6 |
MEDIUM
|
debian
|
debian_linux
|
Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users t…
|
NVD-CWE-Other
|
CVE-2006-1566
|
2017-07-20 10:30 |
2006-03-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349482
|
4.3 |
MEDIUM
|
sitesearch
|
indexer
|
Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.
|
NVD-CWE-Other
|
CVE-2006-1567
|
2017-07-20 10:30 |
2006-04-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349483
|
4.3 |
MEDIUM
|
esqlanelapse
|
esqlanelapse
|
Cross-site scripting (XSS) vulnerability in Esqlanelapse 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1570
|
2017-07-20 10:30 |
2006-04-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349484
|
5.8 |
MEDIUM
|
hitachi
|
groupmax_world_wide_web groupmax_world_wide_web_desktop groupmax_world_wide_web_desktop_scheduler groupmax_world_wide_web_scheduler
|
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web s…
|
NVD-CWE-Other
|
CVE-2006-1574
|
2017-07-20 10:30 |
2006-04-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349485
|
5.8 |
MEDIUM
|
hitachi
|
groupmax_world_wide_web groupmax_world_wide_web_desktop groupmax_world_wide_web_desktop_scheduler groupmax_world_wide_web_scheduler
|
Apply patch :
http://www.hitachi-support.com/security_e/vuls_e/HS06-005_e/index-e.html
|
NVD-CWE-Other
|
CVE-2006-1574
|
2017-07-20 10:30 |
2006-04-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349486
|
6.8 |
MEDIUM
|
mantis
|
mantis
|
Multiple cross-site scripting (XSS) vulnerabilities in view_all_set.php in Mantis 1.0.1, 1.0.0rc5, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) start_day, (2)…
|
NVD-CWE-Other
|
CVE-2006-1577
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349487
|
6.4 |
MEDIUM
|
index_data_aps
|
keystone_digital_library_suite
|
Multiple SQL injection vulnerabilities in Keystone Digital Library Suite (DLS) 1.5.4 and earlier allow remote attackers to execute arbitrary SQL commands via the subject_type_id parameter in (1) the …
|
NVD-CWE-Other
|
CVE-2006-1578
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349488
|
5.8 |
MEDIUM
|
websina
|
bugzero
|
Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) en…
|
NVD-CWE-Other
|
CVE-2006-1580
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349489
|
6.4 |
MEDIUM
|
blanknberg
|
blanknberg
|
Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.
|
NVD-CWE-Other
|
CVE-2006-1581
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349490
|
5.8 |
MEDIUM
|
blanknberg
|
blanknberg
|
Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter. NOTE: this might be resultant from t…
|
NVD-CWE-Other
|
CVE-2006-1582
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349491
|
2.1 |
LOW
|
netbsd
|
netbsd
|
NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.
|
NVD-CWE-Other
|
CVE-2006-1587
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349492
|
2.1 |
LOW
|
netbsd
|
netbsd
|
The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kern…
|
NVD-CWE-Other
|
CVE-2006-1588
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349493
|
4.9 |
MEDIUM
|
netbsd
|
netbsd
|
The elf_load_file function in NetBSD 2.0 through 3.0 allows local users to cause a denial of service (kernel crash) via an ELF interpreter that does not have a PT_LOAD section in its header, which tr…
|
NVD-CWE-Other
|
CVE-2006-1589
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349494
|
4.9 |
MEDIUM
|
netbsd
|
netbsd
|
The NetBSD 2.x versions are only affected if the kernel is compiled with the USE_TOPDOWN_VM option (not default in generic kernels).
|
NVD-CWE-Other
|
CVE-2006-1589
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349495
|
4.3 |
MEDIUM
|
kevin_johnson roman_danyliw
|
basic_analysis_and_security_engine analysis_console_for_intrusion_databases_\(acid\)
|
Analysis Console for Intrusion Databases - The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem.
Basic Analysis and Security Engine - Upgrade …
|
NVD-CWE-Other
|
CVE-2006-1590
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349496
|
4.3 |
MEDIUM
|
kevin_johnson roman_danyliw
|
basic_analysis_and_security_engine analysis_console_for_intrusion_databases_\(acid\)
|
Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows …
|
NVD-CWE-Other
|
CVE-2006-1590
|
2017-07-20 10:30 |
2006-04-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349497
|
1.7 |
LOW
|
sun
|
cluster
|
Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2006-1601
|
2017-07-20 10:30 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349498
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this in…
|
NVD-CWE-Other
|
CVE-2006-1603
|
2017-07-20 10:30 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349499
|
7.5 |
HIGH
|
exponent
|
exponent_cms
|
Unspecified vulnerability in the banner module in Exponent CMS before 0.96.5 RC 1 allows "php injection" via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2006-1607
|
2017-07-20 10:30 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349500
|
5.0 |
MEDIUM
|
hitachi
|
xfit_s xfit_s_jca xfit_s_zengin xfit_s_zgin
|
Unspecified vulnerability in Hitachi XFIT/S, XFIT/S/JCA, XFIT/S/ZGN, and XFIT/S ZENGIN TCP/IP Procedure allows remote attackers to cause a denial of service (server process and transfer control proce…
|
NVD-CWE-Other
|
CVE-2006-1609
|
2017-07-20 10:30 |
2006-04-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|