CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5627

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/include/; (4) photogallery/headerscripts.php; and (5) footerhome.php, (6) footermain.php, (7) headermain.php, (8) sitemapfooter.php, and (9) sitemapheader.php in templates/.

    Published: 31 Oct 2006
    7.2
    High

    CVE-2006-4248

    Last Modified: 23 Apr 2026

    thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5606

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BytesFall Explorer (bfExplorer) 0.0.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the username ($User variable) to login/doLogin.php and other unspecified vectors.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5613

    Last Modified: 23 Apr 2026

    PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5615

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.

    Published: 31 Oct 2006
    10
    Critical

    CVE-2006-5616

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.

    Published: 31 Oct 2006
    2.6
    Low

    CVE-2006-5614

    Last Modified: 23 Apr 2026

    Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5617

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter.

    Published: 31 Oct 2006
    5
    Medium

    CVE-2006-5618

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the ad_direct parameter.

    Published: 31 Oct 2006
    7.5
    High

    CVE-2006-5612

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the aide parameter.

    Published: 31 Oct 2006
    10
    Critical

    CVE-2006-5611

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related to CVE-2006-5405.

    Published: 31 Oct 2006
    9.8
    Critical

    CVE-2006-5610

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in player/includes/common.php in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 31 Oct 2006
    2.1
    Low

    CVE-2006-5619

    Last Modified: 23 Apr 2026

    The seqfile handling (ip6fl_get_n function in ip6_flowlabel.c) in Linux kernel 2.6 up to 2.6.18-stable allows local users to cause a denial of service (hang or oops) via unspecified manipulations that trigger an infinite loop while searching for flowlabels.

    Published: 31 Oct 2006
    5
    Medium

    CVE-2006-5607

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in /cgi-bin/webcm in INCA IM-204 allows remote attackers to read arbitrary files via a "/./." (modified dot dot) sequences in the getpage parameter.

    Published: 30 Oct 2006
    7.5
    High

    CVE-2006-5608

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Extended Tracker (xtracker) 4.7 before 1.5.2.1 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "parameters from URLs."

    Published: 30 Oct 2006
    5
    Medium

    CVE-2006-5609

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.

    Published: 30 Oct 2006
    Unknown

    CVE-2006-5470

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-5740. Reason: This candidate is a duplicate of CVE-2006-5740 due to a typo. Notes: All CVE users should reference CVE-2006-5740 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Oct 2006
    6.8
    Medium

    CVE-2006-5605

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpcards.footer.php in phpCards 1.3 allow remote attackers to inject arbitrary web script or HTML via the CardFontFace parameter and other unspecified parameters.

    Published: 30 Oct 2006
    9.8
    Critical

    CVE-2006-5603

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 30 Oct 2006
    7.5
    High

    CVE-2006-5604

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in phpcards.header.php in phpCards 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CardLanguageFile parameter.

    Published: 30 Oct 2006
    5.5
    Medium

    CVE-2008-2544

    Last Modified: 21 Nov 2024

    Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.

    Published: 30 Oct 2006
    5.6
    Medium

    CVE-2012-3510

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.

    Published: 30 Oct 2006
    5.4
    Medium

    CVE-2006-5466

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages.

    Published: 29 Oct 2006
    2.1
    Low

    CVE-2006-5600

    Last Modified: 23 Apr 2026

    Axalto Protiva 1.1, possibly only non-commercial versions, stores passwords in plaintext in files with insecure permissions, which allows local users to gain privileges by reading the passwords from (1) KeyTool\keytool.config or (2) webapps\protiva\WEB-INF\classes\authserver.config.

    Published: 28 Oct 2006
    9
    Critical

    CVE-2006-5601

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 28 Oct 2006
    4.3
    Medium

    CVE-2006-5598

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.

    Published: 28 Oct 2006
    4.3
    Medium

    CVE-2006-5599

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Oracle Application Express (formerly HTML DB) before 2.2.1 allows remote attackers to inject arbitrary HTML or web script via the WWV_FLOW_ITEM_HELP package. NOTE: it is likely that this issue overlaps one of the Oracle VulnIDs covered by CVE-2006-5351. Oracle has not publicly disputed claims by a reliable researcher that this has been fixed by the October 2006 CPU.

    Published: 28 Oct 2006
    4
    Medium

    CVE-2006-5602

    Last Modified: 23 Apr 2026

    Multiple memory leaks in xsupplicant before 1.2.6, and possibly other versions, allow attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 28 Oct 2006
    7.5
    High

    CVE-2006-5596

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

    Published: 28 Oct 2006
    5
    Medium

    CVE-2006-5469

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WBXML dissector in Wireshark (formerly Ethereal) 0.10.11 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger a null dereference.

    Published: 28 Oct 2006
    5
    Medium

    CVE-2006-5595

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the AirPcap support in Wireshark (formerly Ethereal) 0.99.3 has unspecified attack vectors related to WEP key parsing.

    Published: 28 Oct 2006
    4.7
    Medium

    CVE-2007-4133

    Last Modified: 23 Apr 2026

    The (1) hugetlb_vmtruncate_list and (2) hugetlb_vmtruncate functions in fs/hugetlbfs/inode.c in the Linux kernel before 2.6.19-rc4 perform certain prio_tree calculations using HPAGE_SIZE instead of PAGE_SIZE units, which allows local users to cause a denial of service (panic) via unspecified vectors.

    Published: 28 Oct 2006
    5.1
    Medium

    CVE-2006-4513

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.

    Published: 28 Oct 2006
    7.5
    High

    CVE-2006-4574

    Last Modified: 23 Apr 2026

    Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 through 0.99.3 allows remote attackers to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.

    Published: 28 Oct 2006
    7.5
    High

    CVE-2006-5597

    Last Modified: 23 Apr 2026

    join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.

    Published: 28 Oct 2006
    5
    Medium

    CVE-2006-5468

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-4805

    Last Modified: 23 Apr 2026

    epan/dissectors/packet-xot.c in the XOT dissector (dissect_xot_pdu) in Wireshark (formerly Ethereal) 0.9.8 through 0.99.3 allows remote attackers to cause a denial of service (memory consumption and crash) via an encoded XOT packet that produces a zero length value when it is decoded.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5740

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the LDAP dissector in Wireshark (formerly Ethereal) 0.99.3 allows remote attackers to cause a denial of service (crash) via a crafted LDAP packet.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5587

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers to execute arbitrary PHP code via a URL in the chemin_appli parameter in (1) admin/inc/organisations/form_org.inc.php and (2) admin/inc/organisations/country_insert.php.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5588

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and magic_quotes_gpc are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter to (1) includes/rss-reader.php or (2) admin/config.php, different vectors than CVE-2006-3185.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5591

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Admin/check.asp in PacPoll 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5592

    Last Modified: 23 Apr 2026

    Admin/adpoll.asp in PacPoll 4.0 and earlier allows remote attackers to bypass authentication by setting the polllog cookie value to "xx".

    Published: 27 Oct 2006
    6.5
    Medium

    CVE-2006-5593

    Last Modified: 23 Apr 2026

    Buffer overflow in Desknet's (niokeru) before 5.0J R1.0 might allow remote authenticated users to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5590

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5594

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in University of British Columbia iPeer 2.0, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: it is possible that this issue is related to CakePHP.

    Published: 27 Oct 2006
    7.5
    High

    CVE-2006-5589

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in LedgerSMB (LSMB) 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (1) OE.pm, (2) AM.pm, and (3) Form.pm.

    Published: 27 Oct 2006
    4.6
    Medium

    CVE-2006-5557

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

    Published: 27 Oct 2006
    10
    Critical

    CVE-2006-5558

    Last Modified: 23 Apr 2026

    Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

    Published: 27 Oct 2006
    4.3
    Medium

    CVE-2006-5560

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE: some of these details are obtained from third party information.

    Published: 27 Oct 2006
    5
    Medium

    CVE-2006-5568

    Last Modified: 23 Apr 2026

    FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command.

    Published: 27 Oct 2006