CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5886

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5887

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CampusNewsDetails.asp in Dynamic Dataworx NuSchool 1.0 allows remote attackers to execute arbitrary SQL commands via the NewsID parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5888

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5889

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5893

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in iWonder Designs Storystream 0.4.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter to (1) mysql.php and (2) mysqli.php in include/classes/pear/DB/.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5895

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5891

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in Superfreaker Studios UStore 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5885

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Products.asp in NuStore 1.0 allows remote attackers to execute arbitrary SQL commands via the SubCatagoryID parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5892

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Nov 2006
    6.8
    Medium

    CVE-2006-5894

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.

    Published: 14 Nov 2006
    5
    Medium

    CVE-2006-4689

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5890

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.asp in Superfreaker Studios USupport 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Nov 2006
    5.1
    Medium

    CVE-2006-4687

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

    Published: 14 Nov 2006
    4
    Medium

    CVE-2006-5198

    Last Modified: 23 Apr 2026

    The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-3445

    Last Modified: 23 Apr 2026

    Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results in a heap-based buffer overflow.

    Published: 14 Nov 2006
    10
    Critical

    CVE-2006-4691

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5884

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in DirectAnimation ActiveX controls for Microsoft Internet Explorer 5.01 through 6 have unknown impact and remote attack vectors, possibly related to (1) Danim.dll and (2) Lmrt.dll, a different set of vulnerabilities than CVE-2006-4446 and CVE-2006-4777.

    Published: 14 Nov 2006
    5
    Medium

    CVE-2006-4252

    Last Modified: 23 Apr 2026

    PowerDNS Recursor 3.1.3 and earlier allows remote attackers to cause a denial of service (resource exhaustion and application crash) via a CNAME record with a zero TTL, which triggers an infinite loop.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-4251

    Last Modified: 23 Apr 2026

    Buffer overflow in PowerDNS Recursor 3.1.3 and earlier might allow remote attackers to execute arbitrary code via a malformed TCP DNS query that prevents Recursor from properly calculating the TCP DNS query length.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5878

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5879

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default1.asp in ASPPortal 4.0.0 beta and earlier allows remote attackers to execute arbitrary SQL commands via the Poll_ID parameter, a different vector than CVE-2006-1353.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5880

    Last Modified: 23 Apr 2026

    SQL injection vulnerability on the subMenu page in switch.asp in Munch Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 14 Nov 2006
    7.5
    High

    CVE-2006-5881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.

    Published: 14 Nov 2006
    3.5
    Low

    CVE-2006-5883

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote authenticated users to inject arbitrary web script or HTML via the (1) dir parameter in (a) seldir.html, and the (2) user and (3) dir parameters in (b) newuser.html.

    Published: 14 Nov 2006
    8.3
    High

    CVE-2006-5882

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field.

    Published: 14 Nov 2006
    2.6
    Low

    CVE-2006-5793

    Last Modified: 23 Apr 2026

    The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that trigger an out-of-bounds read.

    Published: 14 Nov 2006
    4.9
    Medium

    CVE-2006-6056

    Last Modified: 23 Apr 2026

    Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.

    Published: 14 Nov 2006
    5
    Medium

    CVE-2007-0720

    Last Modified: 23 Apr 2026

    The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.

    Published: 13 Nov 2006
    5
    Medium

    CVE-2006-5989

    Last Modified: 23 Apr 2026

    Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote attackers to cause a denial of service (crash) via a crafted Kerberos message that triggers a heap-based buffer overflow in the component array.

    Published: 13 Nov 2006
    4
    Medium

    CVE-2006-6054

    Last Modified: 23 Apr 2026

    The ext2 file system code in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via an ext2 stream with malformed data structures that triggers an error in the ext2_check_page due to a length that is smaller than the minimum.

    Published: 12 Nov 2006
    4.6
    Medium

    CVE-2006-5862

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the session mechanism of the web interface for Network Administration Visualized (NAV) before 3.1.1 allows attackers with filesystem write access to have an unknown impact via unknown attack vectors.

    Published: 11 Nov 2006
    7.5
    High

    CVE-2006-5863

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/session.php for LetterIt 2 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

    Published: 11 Nov 2006
    6.4
    Medium

    CVE-2006-5866

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mdoc/view-sourcecode.php for phpManta 1.0.2 and earlier allows remote attackers to read and include arbitrary files via ".." sequences in the file parameter.

    Published: 11 Nov 2006
    5.1
    Medium

    CVE-2006-5864

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.

    Published: 11 Nov 2006
    7.5
    High

    CVE-2006-5865

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language.inc.php in MyAlbum 3.02 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the langs_dir parameter.

    Published: 11 Nov 2006
    7.5
    High

    CVE-2006-5821

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the IMA_SECURE_DecryptData1 function in ImaSystem.dll for Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to execute arbitrary code via requests to the Independent Management Architecture (IMA) service (ImaSrv.exe) with invalid size values that trigger the overflow during decryption.

    Published: 10 Nov 2006
    5
    Medium

    CVE-2006-5861

    Last Modified: 23 Apr 2026

    The Independent Management Architecture (IMA) service (ImaSrv.exe) in Citrix MetaFrame XP 1.0 and 2.0, and Presentation Server 3.0 and 4.0, allows remote attackers to cause a denial of service (service exit) via a crafted packet that causes the service to access an unmapped memory address and triggers an unhandled exception.

    Published: 10 Nov 2006
    10
    Critical

    CVE-2006-5487

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Marshal MailMarshal SMTP 5.x, 6.x, and 2006, and MailMarshal for Exchange 5.x, allows remote attackers to write arbitrary files via ".." sequences in filenames in an ARJ compressed archive.

    Published: 10 Nov 2006
    6.8
    Medium

    CVE-2006-5843

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Speedywiki 2.0 allows remote attackers to inject arbitrary web script or HTML via the showRevisions parameter.

    Published: 10 Nov 2006
    6.5
    Medium

    CVE-2006-5845

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by setting the upload parameter to 1.

    Published: 10 Nov 2006
    6.4
    Medium

    CVE-2006-5846

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773.

    Published: 10 Nov 2006
    Unknown

    CVE-2006-5848

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-5878. Reason: This candidate is a duplicate of CVE-2006-5878. Notes: All CVE users should reference CVE-2006-5878 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Nov 2006
    4.6
    Medium

    CVE-2006-5852

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via a modified PATH that references a malicious helper binary, as demonstrated by (1) cp, (2) rm, and (3) killall, different vectors than CVE-2006-5327.

    Published: 10 Nov 2006
    6.8
    Medium

    CVE-2006-5853

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in logon.aspx in Immediacy CMS (Immediacy .NET CMS) 5.2 allows remote attackers to inject arbitrary web script or HTML via the lang parameter, which is returned to the client in a lang cookie.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5850

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request. NOTE: some of these details are obtained from third party information.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5840

    Last Modified: 13 Mar 2026

    Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current version only creates static pages, and that slistl.php/slid never existed in any version

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5841

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dodosmail_header_file or (2) dodosmail_footer_file parameters.

    Published: 10 Nov 2006
    2.1
    Low

    CVE-2006-5842

    Last Modified: 23 Apr 2026

    The keystore file in Unicore Client before 5.6 build 5, when running on Unix systems, has insecure default permissions, which allows local users to obtain sensitive information.

    Published: 10 Nov 2006
    5
    Medium

    CVE-2006-5844

    Last Modified: 23 Apr 2026

    Speedywiki 2.0 allows remote attackers to obtain the full path of the web server via the (1) showRevisions[] and (2) searchText[] parameters in (a) index.php, and (b) a direct request to upload.php without any parameters.

    Published: 10 Nov 2006
    6.1
    Medium

    CVE-2006-5847

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 10 Nov 2006