Total
29620 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2006-6875 | 1 Openser | 2 Openser, Openser Osp Module | 2025-04-09 | N/A |
Buffer overflow in the validateospheader function in the Open Settlement Protocol (OSP) module in OpenSER 1.1.0 and earlier allows remote attackers to execute arbitrary code via a crafted OSP header. | ||||
CVE-2006-6876 | 1 Openser | 1 Openser | 2025-04-09 | N/A |
Buffer overflow in the fetchsms function in the SMS handling module (libsms_getsms.c) in OpenSER 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SMS message, triggering memory corruption when the "beginning" buffer is copied to the third (pdu) argument. | ||||
CVE-2006-6877 | 1 Matteo Lucarelli | 1 3editor Cms | 2025-04-09 | N/A |
Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. | ||||
CVE-2006-6878 | 1 Php-update | 1 Php-update | 2025-04-09 | N/A |
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action. | ||||
CVE-2006-6879 | 1 Php-update | 1 Php-update | 2025-04-09 | N/A |
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter. | ||||
CVE-2006-6883 | 1 Phpirc Bot | 1 Phpirc Bot | 2025-04-09 | N/A |
PHP remote file inclusion vulnerability in php4you.php in PHPIrc_bot 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE, since the dir variable is declared before being used | ||||
CVE-2006-6885 | 1 Macromedia | 1 Shockwave | 2025-04-09 | N/A |
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long string in the swURL attribute. | ||||
CVE-2006-6888 | 1 P-news | 1 P-news | 2025-04-09 | N/A |
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for db/user.dat. | ||||
CVE-2006-7067 | 1 Oracle | 1 Database Server | 2025-04-09 | N/A |
Oracle 10g R2 and possibly other versions allows remote attackers to trigger internal errors, and possibly have other impacts, via an "alter session set events" command with invalid arguments. NOTE: this issue was originally disputed by a third party, but the dispute was retracted. NOTE: this issue was called an "integer overflow" in the original source, but this might be incorrect. | ||||
CVE-2006-7082 | 1 Rigter Portal System | 1 Rigter Portal System | 2025-04-09 | N/A |
Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to bypass authentication and upload arbitrary files via direct requests to (1) adm/photos/images.php and (2) adm/down/files.php. | ||||
CVE-2006-7083 | 1 Rigter Portal System | 1 Rigter Portal System | 2025-04-09 | N/A |
Directory traversal vulnerability in index.php in Rigter Portal System (RPS) 1.0, 2.0, and 3.0 allows remote attackers to read arbitrary files via ".." sequences in the id parameter. | ||||
CVE-2007-0059 | 1 Apple | 1 Quicktime | 2025-04-09 | N/A |
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitrary code and list filesystem contents via a QuickTime movie (.MOV) with an HREF Track (HREFTrack) that contains an automatic action tag with a local URI, which is executed in a local zone during preview, as exploited by a MySpace worm. | ||||
CVE-2007-0077 | 1 Lblog | 1 Lblog | 2025-04-09 | N/A |
lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/. | ||||
CVE-2007-0084 | 1 Microsoft | 1 Message Compiler | 2025-04-09 | N/A |
Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename. NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed | ||||
CVE-2007-0085 | 1 Openbsd | 1 Openbsd | 2025-04-09 | N/A |
Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when the kernel is compiled with the PCIAGP option and a non-AGP device is being used, allows local users to gain privileges via unspecified vectors, possibly related to agp_ioctl NULL pointer reference. | ||||
CVE-2007-0090 | 1 Fermentigrafici | 1 Wineglass | 2025-04-09 | N/A |
WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb. | ||||
CVE-2007-0093 | 1 Cms-center | 1 Simple Web Cms | 2025-04-09 | N/A |
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
CVE-2007-0094 | 1 Sven Moderow | 1 Sven Moderow Guestbook | 2025-04-09 | N/A |
Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/. | ||||
CVE-2007-1156 | 1 Man Machine Systems | 1 Jbrowser | 2025-04-09 | N/A |
JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/. | ||||
CVE-2007-1331 | 1 Tks Banking Solutions | 1 Eportfolio | 2025-04-09 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program. NOTE: some of these details are obtained from third party information. |