CVE Feed

    Dashboard / CVE

    5.7
    Medium

    CVE-2006-6292

    Last Modified: 23 Apr 2026

    Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-related impact via certain beacon frames.

    Published: 5 Dec 2006
    7.5
    High

    CVE-2006-6293

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file. NOTE: this issue has at least a partial overlap with CVE-2006-6294.

    Published: 5 Dec 2006
    6.5
    Medium

    CVE-2006-6290

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.30 and 2.0 through 2.33 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a long argument to the (1) EXAMINE or (2) SELECT command.

    Published: 5 Dec 2006
    6.8
    Medium

    CVE-2006-6289

    Last Modified: 23 Apr 2026

    Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the wbb_userid parameter to the top-level URI. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in wBB Lite.

    Published: 5 Dec 2006
    1.2
    Low

    CVE-2006-6306

    Last Modified: 23 Apr 2026

    Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.

    Published: 5 Dec 2006
    10
    Critical

    CVE-2006-6299

    Last Modified: 23 Apr 2026

    Integer overflow in Msg.dll in Novell ZENworks 7 Asset Management (ZAM) before SP1 IR11 and the Collection client allows remote attackers to execute arbitrary code via crafted packets, which trigger a heap-based buffer overflow.

    Published: 5 Dec 2006
    4.3
    Medium

    CVE-2006-6300

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.

    Published: 5 Dec 2006
    6.8
    Medium

    CVE-2006-6295

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 5 Dec 2006
    5
    Medium

    CVE-2006-6297

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, allows remote attackers to cause a denial of service (stack consumption) via a crafted EXIF section in a JPEG file, which results in an infinite recursion.

    Published: 5 Dec 2006
    7.5
    High

    CVE-2006-6298

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in uye_giris_islem.asp in Metyus Okul Yonetim Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) kullanici_ismi and (2) sifre parameters.

    Published: 5 Dec 2006
    5
    Medium

    CVE-2006-6307

    Last Modified: 23 Apr 2026

    srvloc.sys in Novell Client for Windows before 4.91 SP3 allows remote attackers to cause an unspecified denial of service via a crafted packet to port 427 that triggers an access of pageable or invalid addresses using a higher interrupt request level (IRQL) than necessary.

    Published: 5 Dec 2006
    6.8
    Medium

    CVE-2006-6291

    Last Modified: 23 Apr 2026

    Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.

    Published: 5 Dec 2006
    7.5
    High

    CVE-2006-6294

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in FRISK Software F-Prot Antivirus before 4.6.7 have unspecified impact and attack vectors. NOTE: this might be related to CVE-2006-6293, but it is not clear due to the vagueness of the report.

    Published: 5 Dec 2006
    6.1
    Medium

    CVE-2006-6296

    Last Modified: 23 Apr 2026

    The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.

    Published: 5 Dec 2006
    10
    Critical

    CVE-2006-3893

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML document.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6244

    Last Modified: 23 Apr 2026

    Coalescent Systems freePBX (formerly Asterisk Management Portal) before 2.2.0rc1 allows attackers to execute arbitrary commands via shell metacharacters in (1) CALLERID(name) or (2) CALLERID(number).

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6245

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Photo Organizer (PO) 2.32b and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Dec 2006
    4.3
    Medium

    CVE-2006-6252

    Last Modified: 23 Apr 2026

    Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.

    Published: 4 Dec 2006
    5
    Medium

    CVE-2006-6253

    Last Modified: 23 Apr 2026

    Cahier de texte 2.0 stores sensitive information under the web root, possibly with insufficient access control, which might allow remote attackers to obtain all users' passwords via a direct request for administration/dump.sql.

    Published: 4 Dec 2006
    7.8
    High

    CVE-2006-6250

    Last Modified: 23 Apr 2026

    Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist file containing extended ASCII, which causes the Unicode converter to be invoked.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6251

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.

    Published: 4 Dec 2006
    9.3
    Critical

    CVE-2006-6258

    Last Modified: 23 Apr 2026

    The phpmyadmin subsystem in AlternC 0.9.5 and earlier transmits the SQL password in cleartext in a cookie, which might allow remote attackers to obtain the password by sniffing or by conducting a cross-site scripting (XSS) attack.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6260

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in Redbinaria Sistema Integrado de Administracion de Portales (SIAP) allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 4 Dec 2006
    6.4
    Medium

    CVE-2006-6262

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mboard.php in PHPJunkYard (aka Klemen Stirn) MBoard 1.22 and earlier allows remote attackers to create arbitrary empty files via a .. (dot dot) in the orig_id parameter.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6266

    Last Modified: 23 Apr 2026

    Teredo clients, when following item 6 of RFC4380 section 5.2.3, start direct IPv6 connectivity tests (aka ping tests) in response to packets from non-Teredo source addresses, which might allow remote attackers to induce Teredo clients to send packets to third parties.

    Published: 4 Dec 2006
    7.8
    High

    CVE-2006-6267

    Last Modified: 23 Apr 2026

    PostNuke 0.7.5.0, and certain minor versions, allows remote attackers to obtain sensitive information via a non-numeric value of the stop parameter, which reveals the path in an error message.

    Published: 4 Dec 2006
    10
    Critical

    CVE-2006-6268

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL commands via a url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by a double-encoded NULL and ' (apostrophe) (%2500%2527).

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6269

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Infinitytechs Restaurants CM allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in rating.asp, (2) the mealid parameter in meal_rest.asp, and (3) the resid parameter in res_details.asp.

    Published: 4 Dec 2006
    4.7
    Medium

    CVE-2006-6275

    Last Modified: 23 Apr 2026

    Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function and SIGKILL and /proc PCAGENT signals.

    Published: 4 Dec 2006
    5
    Medium

    CVE-2006-6277

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter, a different vector than CVE-2005-3086.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6278

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in @lex Guestbook 4.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.

    Published: 4 Dec 2006
    9.3
    Critical

    CVE-2006-6282

    Last Modified: 23 Apr 2026

    members.php in Vikingboard 0.1.2 allows remote attackers to trigger a forced SQL error via an invalid s parameter, a different vector than CVE-2006-4709. NOTE: might only be an exposure if display_errors is enabled, but due to lack of details, even this is not clear.

    Published: 4 Dec 2006
    4.3
    Medium

    CVE-2006-6283

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the subject field of (1) a private message (PM) or (2) a bulletin board post.

    Published: 4 Dec 2006
    9
    Critical

    CVE-2006-6284

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in Vikingboard 0.1.2 allows remote authenticated administrators to include arbitrary files via a .. (dot dot) sequence in the act parameter.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6285

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Kai Blankenhorn Bitfolge simple and nice index file (aka snif) 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the externalConfig parameter. NOTE: CVE and other third parties dispute this vulnerability because $externalConfig is defined before use

    Published: 4 Dec 2006
    1.7
    Low

    CVE-2006-6286

    Last Modified: 23 Apr 2026

    Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6249

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Chama Cargo 4.36 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Dec 2006
    4.3
    Medium

    CVE-2006-6254

    Last Modified: 23 Apr 2026

    administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6256

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the file manager in admin/bro_main.php in AlternC 0.9.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a folder name.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6264

    Last Modified: 23 Apr 2026

    Teredo creates trusted peer entries for arbitrary incoming source Teredo addresses, even if the low 32 bits represent an intranet address, which might allow remote attackers to send IPv4 traffic to intranet hosts that use non-RFC1918 addresses, bypassing IPv4 ingress filtering.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6272

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sp_index.php in Simple PHP Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6274

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for News Manager, but there is strong evidence that the correct product is Publisher.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6243

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.asp in FipsSHOP allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter.

    Published: 4 Dec 2006
    7.5
    High

    CVE-2006-6246

    Last Modified: 23 Apr 2026

    Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6257

    Last Modified: 23 Apr 2026

    The file manager in AlternC 0.9.5 and earlier, when warnings are enabled in PHP, allows remote attackers to obtain sensitive information via certain folder names such as ones composed of JavaScript code, which reveal the path in a warning message.

    Published: 4 Dec 2006
    10
    Critical

    CVE-2006-6259

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in (a) class/functions.php and (b) class/m_bro.php in AlternC 0.9.5 and earlier allow remote attackers to (1) create arbitrary files and directories via a .. (dot dot) in the "create name" field and (2) read arbitrary files via a .. (dot dot) in the "web root" field when configuring a subdomain.

    Published: 4 Dec 2006
    9.3
    Critical

    CVE-2006-6261

    Last Modified: 23 Apr 2026

    Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a) NumberofEntries, (b) Length (aka Length1), (c) Filename (aka File1), (d) Title (aka Title1) field, or other unspecified fields.

    Published: 4 Dec 2006
    5.8
    Medium

    CVE-2006-6265

    Last Modified: 23 Apr 2026

    Teredo clients, when located behind a restricted NAT, allow remote attackers to establish an inbound connection without the guessing required to find a port mapping for a traditional restricted NAT client, by (1) using the client port number contained in the Teredo address or (2) following the bubble-to-open procedure.

    Published: 4 Dec 2006
    10
    Critical

    CVE-2006-6270

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via (1) the soruid parameter in forum2.asp, (2) the ak parameter in kullanicilistesi.asp, (3) the kelimeler parameter in aramayap.asp, and (4) the kullaniciadi parameter in giris.asp; and allow remote authenticated users to execute arbitrary SQL commands via (5) the mesajno parameter in mesajkutum.asp. NOTE: the harf parameter in kullanicilistesi.asp and the baslik parameter in forum.asp are already covered by CVE-2005-4141.

    Published: 4 Dec 2006
    6.8
    Medium

    CVE-2006-6271

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPOLL 0.96 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) index.php, (2) info.php; and (3) index.php, (4) votanti.php, (5) risultati_config.php, (6) modifica_band.php, (7) band_editor.php, and (8) config_editor.php in admin/.

    Published: 4 Dec 2006