CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2006-6436

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages.

    Published: 10 Dec 2006
    4.6
    Medium

    CVE-2006-6441

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6413

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Amateras sns 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6415

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/lib-maintenance.inc.php in phpAdsNew 2.0.4-pr2 allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter, a different component than CVE-2006-3984. NOTE: this issue is disputed by CVE, since phpAds_path is used as a constant

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6420

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in jce.php in the JCE Admin Component in Ryan Demmer Joomla Content Editor (JCE) 1.1.0 beta 2 and earlier for Joomla! (com_jce) allow remote attackers to inject arbitrary web script or HTML via the (1) img, (2) title, (3) w, or (4) h parameter, different vectors than CVE-2006-6166. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6431

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows attackers to modify signatures of e-mail messages via unspecified vectors.

    Published: 10 Dec 2006
    7.8
    High

    CVE-2006-6439

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to download the audit log and obtain potentially sensitive information via unspecified vectors.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6221

    Last Modified: 23 Apr 2026

    2X ThinClientServer Enterprise Edition before 4.0.2248 allows remote attackers to create multiple privileged accounts via a replay attack using the initial account creation request.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6400

    Last Modified: 23 Apr 2026

    Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6401

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter.

    Published: 10 Dec 2006
    7.5
    High

    CVE-2006-6402

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mystats.php in MyStats 1.0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the details parameter.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6403

    Last Modified: 23 Apr 2026

    mystats.php in MyStats 1.0.8 and earlier allows remote attackers to obtain the installation path via (1) details and (2) by array parameters, probably resulting in a path disclosure in an error message.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6407

    Last Modified: 23 Apr 2026

    F-Prot Antivirus for Linux x86 Mail Servers 4.6.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

    Published: 10 Dec 2006
    4.6
    Medium

    CVE-2006-6410

    Last Modified: 23 Apr 2026

    Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb parameter to the Initialize function.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-5874

    Last Modified: 23 Apr 2026

    Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6405

    Last Modified: 23 Apr 2026

    BitDefender Mail Protection for SMB 2.0 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

    Published: 10 Dec 2006
    10
    Critical

    CVE-2006-6409

    Last Modified: 23 Apr 2026

    F-Secure Anti-Virus for Linux Gateways 4.65 allows remote attackers to cause a denial of service (possibly fatal scan error), and possibly bypass virus detection, by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6406

    Last Modified: 23 Apr 2026

    Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

    Published: 10 Dec 2006
    5
    Medium

    CVE-2006-6408

    Last Modified: 23 Apr 2026

    Kaspersky Anti-Virus for Linux Mail Servers 5.5.10 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.

    Published: 10 Dec 2006
    7.8
    High

    CVE-2006-6411

    Last Modified: 23 Apr 2026

    PhoneCtrl.exe in Linksys WIP 330 Wireless-G IP Phone 1.00.06A allows remote attackers to cause a denial of service (crash) via a TCP SYN scan, as demonstrated using TCP ports 1-65535 with nmap.

    Published: 10 Dec 2006
    6.8
    Medium

    CVE-2006-6386

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the CVS management/tracker 4.7.x-1.0, 4.7.x-2.0, and 4.7.0 (before the 20060807 contribution release system) for Drupal allows remote attackers to inject arbitrary web script or HTML via the motivation field in the CVS application page, which is not passed through check_markup on display.

    Published: 8 Dec 2006
    7.5
    High

    CVE-2006-6387

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Dec 2006
    6.8
    Medium

    CVE-2006-6388

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in naprednaPretraga.php in LINK Content Management Server (CMS) allows remote attackers to inject arbitrary web script or HTML via the txtPretraga parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Dec 2006
    6.8
    Medium

    CVE-2006-6389

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ac4p Mobile allow remote attackers to inject arbitrary web script or HTML via the (1) Taaa parameter to (a) up.php, or the (2) pollhtml and (3) Bloks parameters to (b) polls.php, different vectors than CVE-2006-5770.

    Published: 8 Dec 2006
    7.2
    High

    CVE-2006-6385

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Intel PRO 10/100, PRO/1000, and PRO/10GbE PCI, PCI-X, and PCIe network adapter drivers (aka NDIS miniport drivers) before 20061205 allows local users to execute arbitrary code with "kernel-level" privileges via an incorrect function call in certain OID handlers.

    Published: 8 Dec 2006
    6.8
    Medium

    CVE-2006-6393

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jonas Gauffin Publicera 1.0-rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the InputFilter::getString function.

    Published: 8 Dec 2006
    7.5
    High

    CVE-2006-6394

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in certain database classes in Jonas Gauffin Publicera 1.0-rc2 and earlier might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 8 Dec 2006
    5
    Medium

    CVE-2006-6395

    Last Modified: 23 Apr 2026

    Multiple memory leaks in Ulrik Petersen Emdros Database Engine before 1.2.0.pre231 allow local users to cause a denial of service (memory consumption) via unspecified vectors, a different issue than CVE-2005-0415.

    Published: 8 Dec 2006
    7.5
    High

    CVE-2006-6396

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-2006-6199. NOTE: it was later reported that 3.5 is also affected.

    Published: 8 Dec 2006
    7.5
    High

    CVE-2006-6398

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Superfreaker Studios UPublisher 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (a) sendarticle.asp and (b) printarticle.asp, and the ID parameter to (c) index.asp and (d) preferences.asp, different vectors than CVE-2006-5888.

    Published: 8 Dec 2006
    7.5
    High

    CVE-2006-6399

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. NOTE: the provenance of this information is unknown; details are obtained from third party sources.

    Published: 8 Dec 2006
    6.8
    Medium

    CVE-2006-6334

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.

    Published: 8 Dec 2006
    4.4
    Medium

    CVE-2006-6397

    Last Modified: 23 Apr 2026

    Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability

    Published: 8 Dec 2006
    6.8
    Medium

    CVE-2006-6391

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include arbitrary files via a .. (dot dot) in the config[db_type] parameter to (1) actions_admin/other.php and (2) actions_client/gallery.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Dec 2006
    7.5
    High

    CVE-2006-6392

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in plx Web Studio (aka plxWebDev) plx Pay 3.2 and earlier allows remote attackers to include and execute arbitrary local files, or obtain user credentials and other sensitive information, via a .. (dot dot) in the read parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Dec 2006
    6.8
    Medium

    CVE-2006-6390

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Open Solution Quick.Cart 2.0, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the config[db_type] parameter to (1) categories.php, (2) couriers.php, (3) orders.php, and (4) products.php in actions_admin/; and (5) orders.php and (6) products.php in actions_client/; as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by one of these PHP scripts.

    Published: 8 Dec 2006
    4.3
    Medium

    CVE-2006-4249

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PlonePAS in Plone 2.5 and 2.5.1, when anonymous member registration is enabled, allows an attacker to "masquerade as a group."

    Published: 7 Dec 2006
    7.8
    High

    CVE-2006-6384

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in abitwhizzy.php before 20061204 allows remote attackers to read arbitrary files via an absolute pathname in the Filename text window (f parameter), a variant of CVE-2006-6084.

    Published: 7 Dec 2006
    6.8
    Medium

    CVE-2006-6380

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6381

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 7 Dec 2006
    6.8
    Medium

    CVE-2006-6382

    Last Modified: 23 Apr 2026

    The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via a symlink attack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Dec 2006
    6.8
    Medium

    CVE-2006-6371

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in pbguestbook.php in JAB Guest Book allows remote attackers to inject arbitrary web script or HTML via the author parameter.

    Published: 7 Dec 2006
    6.8
    Medium

    CVE-2006-6372

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php in JAB Guest Book 20061205 allow remote attackers to inject arbitrary web script or HTML via the (1) topic or (2) message parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Dec 2006
    5
    Medium

    CVE-2006-6373

    Last Modified: 23 Apr 2026

    PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive information via a direct request for libraries/common.lib.php, which reveals the path in an error message.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6369

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6378

    Last Modified: 23 Apr 2026

    BTSaveMySql 1.2 stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain configuration and save files via direct requests.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6370

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a "SELECT BENCHMARK" statement in the img parameter in a doaddcomment operation in index.php.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6376

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6374

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in PhpMyAdmin 2.7.0-pl2 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a phpMyAdmin cookie in (1) css/phpmyadmin.css.php, (2) db_create.php, (3) index.php, (4) left.php, (5) libraries/session.inc.php, (6) libraries/transformations/overview.php, (7) querywindow.php, (8) server_engines.php, and possibly other files.

    Published: 7 Dec 2006
    7.5
    High

    CVE-2006-6377

    Last Modified: 23 Apr 2026

    Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt.

    Published: 7 Dec 2006