CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-6212

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in centre.php in Site News (site_news) 2.00, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6213

    Last Modified: 23 Apr 2026

    index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6214

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid parameter.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6215

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Wallpaper Website (Wallpaper Complete Website) 1.0.09 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameter to (a) process.php, or the (3) wallpaperid parameter to (b) dlwallpaper.php.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6216

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remote attackers to execute arbitrary SQL commands via the hack_id parameter.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6201

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6200

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the (1) rate_article and (2) rate_complete functions in modules/News/index.php in the News module in Francisco Burzi PHP-Nuke 7.9 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6199

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6195

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6193

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in edit.asp in BasicForum 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6187

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ClickTech Click Gallery allow remote attackers to execute arbitrary SQL commands via the (1) currentpage or (2) gallery_id parameter to (a) view_gallery.asp, the (3) image_id parameter to (b) download_image.asp, the currentpage or (5) orderby parameter to (c) gallery.asp, or the currentpage parameter to (d) view_recent.asp.

    Published: 1 Dec 2006
    5
    Medium

    CVE-2006-6185

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in script.php in Wabbit PHP Gallery 0.9 allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to index.php.

    Published: 1 Dec 2006
    6.8
    Medium

    CVE-2006-6180

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in articles.asp in Expinion.net iNews Publisher (iNP) 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the hl parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Dec 2006
    6.8
    Medium

    CVE-2006-6196

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter).

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6194

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.asp in Ultimate Survey Pro allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter.

    Published: 1 Dec 2006
    5
    Medium

    CVE-2006-6186

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in enomphp 4.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter to (1) config.php, (2) ranklv_inside.php, (3) rankml_inside.php, and (4) admin/Restore/config.php.

    Published: 1 Dec 2006
    10
    Critical

    CVE-2006-6184

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command.

    Published: 1 Dec 2006
    4.3
    Medium

    CVE-2006-6188

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view_search.asp in ClickTech Click Gallery allows remote attackers to inject arbitrary web script or HTML via the txtKeyWord parameter. NOTE: some of these details are obtained from third party information.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6189

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in displayCalendar.asp in ClickTech Click Blog allows remote attackers to execute arbitrary SQL commands via the date parameter.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6190

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in anna.pl in Anna^ IRC Bot before 0.30 (aka caprice) allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: it is possible that there are multiple issues.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6191

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6192

    Last Modified: 23 Apr 2026

    Unspecified scripts in the admin directory in 8pixel.net SimpleBlog 3.0 and earlier do not properly perform authentication, which allows remote attackers to add users and perform certain other unauthorized privileged actions. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Dec 2006
    10
    Critical

    CVE-2006-6183

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command.

    Published: 1 Dec 2006
    2.1
    Low

    CVE-2006-6182

    Last Modified: 23 Apr 2026

    The Gabriele Teotino GNotebook 0.7.0.1 gadget for Google Desktop stores Gmail passwords in plaintext in the %SYSTEMDRIVE%\temp\Gnotebook.txt log file, which allows local users to obtain passwords by reading the file.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6181

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in ClickTech ClickContact allow remote attackers to execute arbitrary SQL commands via the (1) AlphaSort, (2) In, and (3) orderby parameters.

    Published: 1 Dec 2006
    7.5
    High

    CVE-2006-6178

    Last Modified: 23 Apr 2026

    Buffer overflow in PCCSRV\Web_console\RemoteInstallCGI\Wizard.exe for Trend Micro OfficeScan 7.3 before build 7.3.0.1087 allows remote attackers to execute arbitrary code via unknown attack vectors.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-6179

    Last Modified: 23 Apr 2026

    Buffer overflow in PCCSRV\Web_console\RemoteInstallCGI\CgiRemoteInstall.exe for Trend Micro OfficeScan 7.3 before build 7.3.0.1089 allows remote attackers to execute arbitrary code via unknown attack vectors.

    Published: 30 Nov 2006
    4.6
    Medium

    CVE-2006-4396

    Last Modified: 23 Apr 2026

    The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log files, which allows local users to create and modify arbitrary files via unspecified vectors, possibly relating to a symlink attack.

    Published: 30 Nov 2006
    5.1
    Medium

    CVE-2006-4401

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in CFNetwork in Mac OS 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary FTP commands via a crafted FTP URI.

    Published: 30 Nov 2006
    5.1
    Medium

    CVE-2006-4402

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Finder in Apple Mac OS X 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary code by browsing directories containing crafted .DS_Store files.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-4406

    Last Modified: 23 Apr 2026

    Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 30 Nov 2006
    7.2
    High

    CVE-2006-4411

    Last Modified: 23 Apr 2026

    The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, which allows local users to gain privileges via unspecified vectors.

    Published: 30 Nov 2006
    6.8
    Medium

    CVE-2006-4412

    Last Modified: 23 Apr 2026

    WebKit in Apple Mac OS X 10.3.x through 10.3.9 and 10.4 through 10.4.8 allows remote attackers to execute arbitrary code via a crafted HTML file, which accesses previously deallocated objects.

    Published: 30 Nov 2006
    7.2
    High

    CVE-2006-6173

    Last Modified: 23 Apr 2026

    Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the shared_region_make_private_np_args parameter.

    Published: 30 Nov 2006
    4.3
    Medium

    CVE-2006-6174

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in tDiary before 2.0.3 and 2.1.x before 2.1.4.20061126 allows remote attackers to inject arbitrary web script or HTML via the conf parameter in (1) tdiary.rb and (2) skel/conf.rhtml.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-6175

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.

    Published: 30 Nov 2006
    6.8
    Medium

    CVE-2006-6176

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in Blogn before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-6177

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded NULL and ' (apostrophe) (%2500%2527).

    Published: 30 Nov 2006
    4
    Medium

    CVE-2006-4403

    Last Modified: 23 Apr 2026

    The FTP server in Apple Mac OS X 10.4.8 and earlier, when FTP Access is enabled, will crash when a login failure occurs with a valid user name, which allows remote attackers to cause a denial of service (crash) and enumerate valid usernames.

    Published: 30 Nov 2006
    5
    Medium

    CVE-2006-4408

    Last Modified: 23 Apr 2026

    The Security Framework in Apple Mac OS X 10.4 through 10.4.8 allows remote attackers to cause a denial of service (resource consumption) via certain public key values in an X.509 certificate that requires extra resources during signature verification. NOTE: this issue may be similar to CVE-2006-2940.

    Published: 30 Nov 2006
    5.1
    Medium

    CVE-2006-4400

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Apple Type Services (ATS) server in Mac OS 10.4.8 and earlier allow user-assisted attackers to execute arbitrary code via crafted font files.

    Published: 30 Nov 2006
    10
    Critical

    CVE-2006-4404

    Last Modified: 23 Apr 2026

    The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin credentials, does not authenticate the user before installing certain software requiring system privileges.

    Published: 30 Nov 2006
    5
    Medium

    CVE-2006-4409

    Last Modified: 23 Apr 2026

    The Online Certificate Status Protocol (OCSP) service in the Security Framework in Apple Mac OS X 10.4 through 10.4.8 retrieve certificate revocation lists (CRL) when an HTTP proxy is in use, which could cause the system to accept certificates that have been revoked.

    Published: 30 Nov 2006
    7.2
    High

    CVE-2006-4398

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Apple Type Services (ATS) server in Mac OS X 10.4 through 10.4.8 allow local users to execute arbitrary code via crafted service requests.

    Published: 30 Nov 2006
    5
    Medium

    CVE-2006-4407

    Last Modified: 23 Apr 2026

    The Security Framework in Apple Mac OS X 10.3.x up to 10.3.9 does not properly prioritize encryption ciphers when negotiating the strongest shared cipher, which causes Secure Transport to user a weaker cipher that makes it easier for remote attackers to decrypt traffic.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-4410

    Last Modified: 23 Apr 2026

    The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-6170

    Last Modified: 23 Apr 2026

    Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different vulnerability than CVE-2006-5815.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-6172

    Last Modified: 23 Apr 2026

    Buffer overflow in the asmrp_eval function in the RealMedia RTSP stream handler (asmrp.c) for Real Media input plugin, as used in (1) xine/xine-lib, (2) MPlayer 1.0rc1 and earlier, and possibly others, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-6171

    Last Modified: 23 Apr 2026

    ProFTPD 1.3.0a and earlier does not properly set the buffer size limit when CommandBufferSize is specified in the configuration file, which leads to an off-by-two buffer underflow. NOTE: in November 2006, the role of CommandBufferSize was originally associated with CVE-2006-5815, but this was an error stemming from a vague initial disclosure. NOTE: ProFTPD developers dispute this issue, saying that the relevant memory location is overwritten by assignment before further use within the affected function, so this is not a vulnerability

    Published: 30 Nov 2006
    7.5
    High

    CVE-2006-4514

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.

    Published: 30 Nov 2006