CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-6671

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6672

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Burak Yylmaz Download Portal allow remote attackers to execute arbitrary SQL commands via the (1) kid or possibly (2) id parameter to (a) HABERLER.ASP and (b) ASPKAT.ASP. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Dec 2006
    1.9
    Low

    CVE-2007-0006

    Last Modified: 23 Apr 2026

    The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."

    Published: 21 Dec 2006
    7.5
    High

    CVE-2006-6661

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

    Published: 20 Dec 2006
    4.1
    Medium

    CVE-2006-6662

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 and Open Enterprise Server 9, under unspecified conditions, allows local users to log in to the console without a password.

    Published: 20 Dec 2006
    7.5
    High

    CVE-2006-6666

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via a URL in the q parameter.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6668

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in VerliAdmin 0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6669

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter.

    Published: 20 Dec 2006
    10
    Critical

    CVE-2006-6670

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL.

    Published: 20 Dec 2006
    5
    Medium

    CVE-2006-6664

    Last Modified: 23 Apr 2026

    Format string vulnerability in Marathon Aleph One before 0.17.1 and 2006-12-17 might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the TopLevelLogger::logMessageV function in Misc/Logging.cpp. NOTE: some details were obtained from third party information.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6665

    Last Modified: 23 Apr 2026

    Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name tag in a dbr file.

    Published: 20 Dec 2006
    4.3
    Medium

    CVE-2006-6660

    Last Modified: 23 Apr 2026

    The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.

    Published: 20 Dec 2006
    5
    Medium

    CVE-2006-6663

    Last Modified: 23 Apr 2026

    The server component in Marathon Aleph One before 0.17.1 and 2006-12-17 allows remote attackers to cause a denial of service (application crash) via unspecified vectors related to "gathering net games."

    Published: 20 Dec 2006
    7.5
    High

    CVE-2006-6667

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) repass.php or (b) verify.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Dec 2006
    2.4
    Low

    CVE-2006-6477

    Last Modified: 23 Apr 2026

    FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent by hijacking an HTTP FRAgent daemon and conducting a man-in-the-middle (MITM) attack.

    Published: 20 Dec 2006
    7.5
    High

    CVE-2006-6645

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the mx_root_path parameter.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6646

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Drupal (1) Project Issue Tracking 4.7.x-1.0 and 4.7.x-2.0, and (2) Project 4.6.x-1.0, 4.7.x-1.0, and 4.7.x-2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, which do not use the check_plain function.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6647

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the MySite 4.7.x before 4.7.x-3.3 and 5.x before 5.x-1.3 module for Drupal allows remote attackers to inject arbitrary web script or HTML via the Title field when editing a page. NOTE: some details were obtained from third party information.

    Published: 20 Dec 2006
    7.5
    High

    CVE-2006-6648

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6651

    Last Modified: 23 Apr 2026

    Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corruption and execute arbitrary code via a series of crafted beacon frames. NOTE: some details are obtained solely from third party information.

    Published: 20 Dec 2006
    9
    Critical

    CVE-2006-6652

    Last Modified: 23 Apr 2026

    Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.

    Published: 20 Dec 2006
    1.7
    Low

    CVE-2006-6653

    Last Modified: 23 Apr 2026

    The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an invalid (1) name or (2) namelen parameter, which may result in the socket never being closed (aka "a dangling socket").

    Published: 20 Dec 2006
    4.3
    Medium

    CVE-2006-6654

    Last Modified: 23 Apr 2026

    The sendmsg function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029, when run on a 64-bit architecture, allows attackers to cause a denial of service (kernel panic) via an invalid msg_controllen parameter to the sendit function.

    Published: 20 Dec 2006
    1.7
    Low

    CVE-2006-6655

    Last Modified: 23 Apr 2026

    The procfs implementation in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (kernel panic) by attempting to access /emul/linux/proc/0/stat on a procfs filesystem that was mounted with mount_procfs -o linux, which results in a NULL pointer dereference.

    Published: 20 Dec 2006
    7.5
    High

    CVE-2006-6642

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in haber.asp in Contra Haber Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Dec 2006
    2.1
    Low

    CVE-2006-6656

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ptrace in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read kernel memory and obtain sensitive information via certain manipulations of a PT_LWPINFO request, which leads to a memory leak and information leak.

    Published: 20 Dec 2006
    2.1
    Low

    CVE-2006-6657

    Last Modified: 23 Apr 2026

    The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors.

    Published: 20 Dec 2006
    2.6
    Low

    CVE-2006-5681

    Last Modified: 23 Apr 2026

    QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.

    Published: 20 Dec 2006
    7.1
    High

    CVE-2006-6475

    Last Modified: 23 Apr 2026

    FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode with SSL enabled, allows remote attackers to cause a denial of service (refused connections) via malformed requests, which results in a mishandled exception.

    Published: 20 Dec 2006
    2.4
    Low

    CVE-2006-6476

    Last Modified: 23 Apr 2026

    FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a denial of service (loss of daemon operation).

    Published: 20 Dec 2006
    5
    Medium

    CVE-2006-6643

    Last Modified: 23 Apr 2026

    Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long arguments.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6650

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 20 Dec 2006
    5
    Medium

    CVE-2006-6658

    Last Modified: 23 Apr 2026

    Inktomi Search 4.1.4 allows remote attackers to obtain sensitive information via direct requests with missing parameters to (1) help/header.html, (2) thesaurus.html, and (3) topics.html, which leak the installation path in the resulting error message, a related issue to CVE-2006-5970.

    Published: 20 Dec 2006
    5
    Medium

    CVE-2006-6659

    Last Modified: 23 Apr 2026

    The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6644

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6649

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.

    Published: 20 Dec 2006
    6.8
    Medium

    CVE-2006-6500

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting the CSS cursor to certain images that cause an incorrect size calculation when converting to a Windows bitmap.

    Published: 20 Dec 2006
    4.3
    Medium

    CVE-2006-6506

    Last Modified: 23 Apr 2026

    The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits.

    Published: 20 Dec 2006
    4.3
    Medium

    CVE-2006-6507

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.

    Published: 20 Dec 2006
    4.3
    Medium

    CVE-2006-6499

    Last Modified: 23 Apr 2026

    The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.

    Published: 20 Dec 2006
    7.5
    High

    CVE-2006-6641

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

    Published: 20 Dec 2006
    5
    Medium

    CVE-2008-0128

    Last Modified: 23 Apr 2026

    The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

    Published: 20 Dec 2006
    5
    Medium

    CVE-2006-6638

    Last Modified: 23 Apr 2026

    IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvrequest function in DB2ENGN.DLL, a different issue than CVE-2006-4257.

    Published: 19 Dec 2006
    6.8
    Medium

    CVE-2006-6640

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.

    Published: 19 Dec 2006
    10
    Critical

    CVE-2006-6636

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.

    Published: 19 Dec 2006
    5
    Medium

    CVE-2006-6637

    Last Modified: 23 Apr 2026

    The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled, allows remote attackers to obtain JSP source code and other sensitive information via "specific requests."

    Published: 19 Dec 2006
    4.6
    Medium

    CVE-2006-6639

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line.

    Published: 19 Dec 2006
    6.8
    Medium

    CVE-2006-6505

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message modies with long Content-Type headers or (2) long RFC2047-encoded (MIME non-ASCII) headers.

    Published: 19 Dec 2006
    4.9
    Medium

    CVE-2006-3896

    Last Modified: 23 Apr 2026

    The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX.

    Published: 19 Dec 2006
    6.8
    Medium

    CVE-2006-6501

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.

    Published: 19 Dec 2006