CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2006-5851

    Last Modified: 23 Apr 2026

    openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/output file, a different vulnerability than CVE-2006-5328.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5839

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ad_main.php in PHPAdventure 1.1-Alpha and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _mygamefile parameter.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5849

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execute arbitrary PHP code via a URL in the irayodirhack parameter.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5828

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5831

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/code/index.php in All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the load_page parameter.

    Published: 10 Nov 2006
    6.8
    Medium

    CVE-2006-5827

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpComasy CMS 0.7.9pre and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username or (2) password parameters.

    Published: 10 Nov 2006
    7.2
    High

    CVE-2006-5836

    Last Modified: 23 Apr 2026

    The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized file type.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5837

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows remote attackers to inject arbitrary PHP code into chat_log.php via the msg parameter.

    Published: 10 Nov 2006
    5.1
    Medium

    CVE-2006-5838

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/class.Database.php in NewP News Publication System 1.0.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the path parameter.

    Published: 10 Nov 2006
    7.5
    High

    CVE-2006-5833

    Last Modified: 23 Apr 2026

    gbcms_php_files/up_loader.php GreenBeast CMS 1.3 does not require authentication to upload files, which allows remote attackers to cause a denial of service (disk consumption) and execute arbitrary code by uploading arbitrary files, such as executing PHP code via an uploaded PHP file.

    Published: 10 Nov 2006
    5.8
    Medium

    CVE-2006-5826

    Last Modified: 23 Apr 2026

    Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters.

    Published: 10 Nov 2006
    6.8
    Medium

    CVE-2006-5829

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) choosed_language parameter to (a) cp_dpage.php, (b) cp_news.php, (c) cp_forum_view.php, (d) cp_edit_user.php, (e) cp_newsletter.php, (f) cp_links.php, (g) cp_contact_us.php, (h) cp_login.php, and (i) cp_codice_fiscale.php in public/code/; (2) news_category parameter to public/code/cp_news.php; (3) nlmsg_nlcatid parameter to public/code/cp_newsletter.php; (4) links_category parameter to public/code/cp_links.php; (5) product_category_id parameter to public/code/cp_show_ec_products.php; (6) order_field parameter to public/code/cp_show_ec_products.php; (7) firstrow parameter to public/code/cp_users_online.php; and (8) orderdir parameter to public/code/cp_links_search.php.

    Published: 10 Nov 2006
    6.8
    Medium

    CVE-2006-5830

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.007 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topid, (2) forid, and (3) catid parameters to code/cp_forum_view.php; (4) choosed_language parameter to cp_dpage.php; (5) orderdir parameter to cp_links_search.php; (6) order_field parameter to (a) cp_show_ec_products.php and (b) cp_users_online.php; and the (7) signature and (8) fiscal code fields in the user profile.

    Published: 10 Nov 2006
    5
    Medium

    CVE-2006-5832

    Last Modified: 23 Apr 2026

    All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.

    Published: 10 Nov 2006
    5
    Medium

    CVE-2006-5834

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in general.php in OpenSolution Quick.Cms.Lite 0.3 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the sLanguage Cookie parameter.

    Published: 10 Nov 2006
    4.3
    Medium

    CVE-2006-5825

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Kayako SupportSuite 3.00.32 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 10 Nov 2006
    5
    Medium

    CVE-2006-5835

    Last Modified: 23 Apr 2026

    The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.

    Published: 10 Nov 2006
    4.9
    Medium

    CVE-2006-6053

    Last Modified: 23 Apr 2026

    The ext3fs_dirhash function in Linux kernel 2.6.x allows local users to cause a denial of service (crash) via an ext3 stream with malformed data structures.

    Published: 10 Nov 2006
    4.9
    Medium

    CVE-2006-5824

    Last Modified: 23 Apr 2026

    Integer overflow in the ffs_rdextattr function in FreeBSD 6.1 allows local users to cause a denial of service (kernel panic) and trigger a heap-based buffer overflow via a crafted UFS filesystem, a different vulnerability than CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.

    Published: 9 Nov 2006
    7.8
    High

    CVE-2006-5782

    Last Modified: 23 Apr 2026

    radexecd.exe in HP OpenView Client Configuraton Manager (CCM) does not require authentication before executing commands in the installation directory, which allows remote attackers to cause a denial of service (reboot) by calling radbootw.exe or create arbitrary files by calling radcrecv.

    Published: 9 Nov 2006
    5
    Medium

    CVE-2006-5680

    Last Modified: 23 Apr 2026

    The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read more data.

    Published: 9 Nov 2006
    5
    Medium

    CVE-2006-5813

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Novell eDirectory 8.8 allows attackers to cause a denial of service, as demonstrated by vd_novell3.pm, a "Novell eDirectory 8.8 DoS." NOTE: As of 20061108, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5814

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Novell eDirectory allows remote attackers to execute arbitrary code, as demonstrated by vd_novell.pm, a "Novell eDirectory remote exploit." NOTE: As of 20061108, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 8 Nov 2006
    10
    Critical

    CVE-2006-5815

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5816

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko Business Card Web Builder (BCWB) 2.5 allow remote attackers to execute arbitrary PHP code via a URL in the root_path_admin parameter to (1) /include/startup.inc.php, (2) dcontent/default.css.php, or (3) system/default.css.php, different vectors than CVE-2006-4946.

    Published: 8 Nov 2006
    6.8
    Medium

    CVE-2006-5811

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter.

    Published: 8 Nov 2006
    7.2
    High

    CVE-2006-5818

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.

    Published: 8 Nov 2006
    5
    Medium

    CVE-2006-5812

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Kerio MailServer allows attackers to cause a denial of service, as demonstrated by vd_kms4.pm, a "Kerio MailServer DoS." NOTE: As of 20061108, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 8 Nov 2006
    6.8
    Medium

    CVE-2006-5810

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTML via the newdownloadshowdays parameter.

    Published: 8 Nov 2006
    2.1
    Low

    CVE-2006-5817

    Last Modified: 23 Apr 2026

    prl_dhcpd in Parallels Desktop for Mac Build 1940 uses insecure permissions (0666) for /Library/Parallels/.dhcpd_configuration, which allows local users to modify DHCP configuration.

    Published: 8 Nov 2006
    10
    Critical

    CVE-2006-5809

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Jonathon J. Freeman OvBB before 0.13a have unknown impact and attack vectors.

    Published: 8 Nov 2006
    2.1
    Low

    CVE-2006-5806

    Last Modified: 23 Apr 2026

    SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files outside of the vault, which is not cleared after the VPN connection terminates and allows local users to read unencrypted data.

    Published: 8 Nov 2006
    4.6
    Medium

    CVE-2006-5807

    Last Modified: 23 Apr 2026

    Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka "System Policy Evasion".

    Published: 8 Nov 2006
    4.6
    Medium

    CVE-2006-5808

    Last Modified: 23 Apr 2026

    The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka "Local Privilege Escalation".

    Published: 8 Nov 2006
    5
    Medium

    CVE-2006-5805

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to cause a security certificate from a secure web site to appear invalid via a link to res://ieframe.dll/invalidcert.htm with the target site as an argument, which displays the site's URL in the address bar but causes Internet Explorer to report that the certificate is invalid.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5798

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Xenis.creator CMS allows remote attackers to execute arbitrary SQL commands via the contid parameter.

    Published: 8 Nov 2006
    6.8
    Medium

    CVE-2006-5799

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in default.asp in xenis.creator CMS allow remote attackers to inject arbitrary web script or HTML via the (1) contid or (2) search parameters.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5804

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5802

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5795

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the srcdir parameter to (a) billing_process.php, (b) billing_report.php, (c) billing_report_xml.php, and (d) print_billing_report.php in interface/billing/; (e) login.php; (f) interface/batchcom/batchcom.php; (g) interface/login/login.php; (h) main_info.php and (i) main.php in interface/main/; (j) interface/new/new_patient_save.php; (k) interface/practice/ins_search.php; (l) interface/logout.php; (m) custom_report_range.php, (n) players_report.php, and (o) front_receipts_report.php in interface/reports/; (p) facility_admin.php, (q) usergroup_admin.php, and (r) user_info.php in interface/usergroup/; or (s) custom/import_xml.php.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5797

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in Xenis.creator CMS allow remote attackers to execute arbitrary SQL commands via the (1) nav, (2) s, or (3) print parameters.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5803

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/mx_smartor/album.php in the mxBB Smartor Album module 1.02 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5796

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[docroot_path] parameter to (1) includes/shared_functions.php or (2) client_files/shopping_cart/pgm-shopping_css.inc.php.

    Published: 8 Nov 2006
    2.6
    Low

    CVE-2006-5800

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Nov 2006
    5
    Medium

    CVE-2006-5801

    Last Modified: 23 Apr 2026

    The owserver module in owfs and owhttpd 2.5p5 and earlier does not properly check the path type, which allows attackers to cause a denial of service (application crash) related to use of the path in owshell.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5747

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.

    Published: 8 Nov 2006
    7.5
    High

    CVE-2006-5463

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.

    Published: 8 Nov 2006
    6.4
    Medium

    CVE-2006-5462

    Last Modified: 23 Apr 2026

    Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for unpatched product versions that were originally intended to be addressed by CVE-2006-4340.

    Published: 8 Nov 2006
    5
    Medium

    CVE-2006-5748

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger memory corruption.

    Published: 8 Nov 2006
    5
    Medium

    CVE-2006-5464

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.

    Published: 8 Nov 2006