CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-6470

    Last Modified: 23 Apr 2026

    The SNMP Agent in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 returns no error for a non-writable object, which has unknown impact and attack vectors. NOTE: due to the vagueness of the advisory, it is not clear whether this is a vulnerability, or a bug in a security feature.

    Published: 11 Dec 2006
    10
    Critical

    CVE-2006-6471

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 use weak permissions for certain files, which allows unspecified file access.

    Published: 11 Dec 2006
    10
    Critical

    CVE-2006-6472

    Last Modified: 23 Apr 2026

    The httpd.conf file in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 configures port 443 to be always active, which has unknown impact and remote attack vectors.

    Published: 11 Dec 2006
    5.8
    Medium

    CVE-2006-6468

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates.

    Published: 11 Dec 2006
    10
    Critical

    CVE-2006-6473

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an IIO failure when a Held Job is deleted, and (3) an On Demand Image Overwrite failure when the overwrite is greater than 2 Gb.

    Published: 11 Dec 2006
    7.5
    High

    CVE-2006-6462

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execute arbitrary PHP code via a URL in the addpath parameter.

    Published: 11 Dec 2006
    5.8
    Medium

    CVE-2006-6467

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not properly restrict access to SMB file resources, which allows remote attackers to gain unspecified file or directory access via vectors related to (1) visibility of the SMB "Homes" share and (2) SMB file system browsing.

    Published: 11 Dec 2006
    5.8
    Medium

    CVE-2006-6469

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL daemon.

    Published: 11 Dec 2006
    9.3
    Critical

    CVE-2006-6456

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.

    Published: 11 Dec 2006
    5
    Medium

    CVE-2006-6457

    Last Modified: 23 Apr 2026

    tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message.

    Published: 11 Dec 2006
    6.8
    Medium

    CVE-2006-6459

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the (1) Name and (2) Information fields when adding a new site (toplistnew action).

    Published: 11 Dec 2006
    10
    Critical

    CVE-2006-6460

    Last Modified: 23 Apr 2026

    Yourfreeworld.com Short Url & Url Tracker Script allows remote attackers to obtain sensitive information via an invalid id parameter to login.php, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2509.

    Published: 11 Dec 2006
    7.8
    High

    CVE-2006-6458

    Last Modified: 23 Apr 2026

    The Trend Micro scan engine before 8.320 for Windows and before 8.150 on HP-UX and AIX, as used in Trend Micro PC Cillin - Internet Security 2006, Office Scan 7.3, and Server Protect 5.58, allows remote attackers to cause a denial of service (CPU consumption and system hang) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero, which triggers an infinite loop.

    Published: 11 Dec 2006
    7.8
    High

    CVE-2006-6461

    Last Modified: 23 Apr 2026

    tr1.php in Yourfreeworld Stylish Text Ads Script allows remote attackers to obtain the installation path via an invalid id parameter, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2508.

    Published: 11 Dec 2006
    6.8
    Medium

    CVE-2006-6447

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6448

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Vt-Forum Lite 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the user parameter to vf_memberdetail.asp, and other unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    6.4
    Medium

    CVE-2006-6449

    Last Modified: 23 Apr 2026

    Vt-Forum Lite 1.3 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6450

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in dagent/downloadreport.asp in Novell ZENworks Patch Management (ZPM) before 6.3.2.700 allow remote attackers to execute arbitrary SQL commands via the (1) agentid and (2) pass parameters.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6451

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SWsoft Plesk 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) get_password.php or (2) login_up.php3.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6455

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/default.asp in DUware DUdirectory 3.1, and possibly DUdirectory Pro and Pro SQL 3.x, allow remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password parameter. NOTE: some of these details are obtained from third party information.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6445

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6446

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the D parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    6.5
    Medium

    CVE-2006-6453

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to execute arbitrary PHP code via a URL in the link parameter.

    Published: 10 Dec 2006
    10
    Critical

    CVE-2006-6454

    Last Modified: 23 Apr 2026

    execInBackground.php in J-OWAMP Web Interface 2.1b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters to the (1) exe and (2) args parameters, which are used in an exec function call. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6444

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Nostra DivX Player 2.1, 2.2.00.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long string in an M3U file. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6452

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the MyArticles module before 0.6 beta 1, for RunCMS, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) topics.php, (2) submit.php, and (3) class/calendar.class.php.

    Published: 10 Dec 2006
    10
    Critical

    CVE-2006-6443

    Last Modified: 23 Apr 2026

    Buffer overflow in the Novell Distributed Print Services (NDPS) Print Provider for Windows component (NDPPNT.DLL) in Novell Client 4.91 has unknown impact and remote attack vectors.

    Published: 10 Dec 2006
    4.6
    Medium

    CVE-2006-6383

    Last Modified: 23 Apr 2026

    PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed by an allowed path, which causes a parsing inconsistency in which PHP validates the allowed path but sets session.save_path to the malicious path.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6379

    Last Modified: 23 Apr 2026

    Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCserve Backup r11.5 SP1 and earlier, ARCserve Backup 9.01 up to 11.1, Enterprise Backup 10.5, and CA Server Protection Suite r2, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6332

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions.

    Published: 10 Dec 2006
    7.2
    High

    CVE-2006-6418

    Last Modified: 23 Apr 2026

    Buffer overflow in the POSIX Threads library (libpthread) on HP Tru64 UNIX 4.0F PK8, 4.0G PK4, and 5.1A PK6 allows local users to gain root privileges via a long PTHREAD_CONFIG environment variable.

    Published: 10 Dec 2006
    6
    Medium

    CVE-2006-6421

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6426

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in design/thinkedit/render.php in ThinkEdit 1.9.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the template_file parameter.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6428

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allow remote attackers to gain access via unspecified vectors related to "browser permissions."

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6429

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows attackers to modify certain configuration settings via unspecified vectors involving the "TFTP/BOOTP auto configuration option."

    Published: 10 Dec 2006
    7.8
    High

    CVE-2006-6430

    Last Modified: 23 Apr 2026

    Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6435

    Last Modified: 23 Apr 2026

    The SNMP implementation in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 does not generate authentication failure traps, which allows remote attackers to more easily gain system access and obtain sensitive information via a brute force attack.

    Published: 10 Dec 2006
    7.8
    High

    CVE-2006-6437

    Last Modified: 23 Apr 2026

    ops3-dmn in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows attackers to cause a denial of service (application crash and core dump) via a certain PS file.

    Published: 10 Dec 2006
    4.9
    Medium

    CVE-2006-6438

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading the http.log file.

    Published: 10 Dec 2006
    9.3
    Critical

    CVE-2006-6442

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SetClientInfo function in the CDDBControlAOL.CDDBAOLControl ActiveX control (cddbcontrol.dll), as used in America Online (AOL) 7.0 4114.563, 8.0 4129.230, and 9.0 Security Edition 4156.910, and possibly other products, allows remote attackers to execute arbitrary code via a long ClientId argument.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6416

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PhpLeague - Univert PhpLeague 0.81 allow remote attackers to execute arbitrary PHP code via a URL in the cheminmini parameter to (1) consult/miniseul.php or (2) config.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6432

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Scan-to-mailbox feature in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to download certain files via unspecified vectors.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6440

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allow remote attackers to have an unspecified impact via unspecified vectors relating to "HTTP Security issues."

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6414

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in dettaglio.asp in dol storye allow remote attackers to execute arbitrary SQL commands via the (1) id_doc or (2) id_aut parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6417

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6419

    Last Modified: 23 Apr 2026

    jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allows remote attackers to include and possibly execute arbitrary local files via the (1) plugin or (2) file parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6422

    Last Modified: 23 Apr 2026

    Agileco AgileBill 1.4.x and AgileVoice 1.4.x do not properly handle certain proxy requests, which allows remote attackers to disable the application by entering invalid license data on a form, possibly involving modules/core/license.inc.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6427

    Last Modified: 23 Apr 2026

    The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3) certain parameters in the Microsoft Networking configuration. NOTE: vector 1 might be the same as CVE-2006-5290.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6433

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 does not record accurate timestamps, which makes it easier for remote attackers to avoid detection when an audit tries to rely on these timestamps.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6434

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to bypass authentication controls via unknown vectors.

    Published: 10 Dec 2006