CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-5409

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the wireless IDS management interface for Highwall Enterprise and Highwall Endpoint 4.0.2.11045 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 20 Oct 2006
    7.5
    High

    CVE-2006-5411

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier, allows remote attackers to upload and execute arbitrary PHP programs.

    Published: 20 Oct 2006
    5.1
    Medium

    CVE-2006-5410

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter. NOTE: it is possible that this issue overlaps CVE-2006-4189.

    Published: 20 Oct 2006
    2.6
    Low

    CVE-2006-5404

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via unspecified vectors.

    Published: 19 Oct 2006
    6.2
    Medium

    CVE-2006-5405

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Toshiba Bluetooth wireless device driver 3.x and 4 through 4.00.35, as used in multiple products, allows physically proximate attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via crafted Bluetooth packets.

    Published: 19 Oct 2006
    3.6
    Low

    CVE-2006-5406

    Last Modified: 23 Apr 2026

    Passgo Defender 5.2 creates the application directory with insecure permissions (Everyone/Full Control), which allows local users to read and modify sensitive files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 19 Oct 2006
    7.5
    High

    CVE-2006-5407

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.

    Published: 19 Oct 2006
    5.1
    Medium

    CVE-2006-5403

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 19 Oct 2006
    7.5
    High

    CVE-2006-5398

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in Simplog 0.9.3.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5399

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the g_rb_basedir parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5401

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter.

    Published: 18 Oct 2006
    5.1
    Medium

    CVE-2006-5400

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5402

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path, (2) javascript_path, and (3) include_path parameters in (a) cart.php; the (4) class_path parameter in (b) index.php; the (5) javascript_path parameter in (c) edit.php; the (6) include_path parameter in (d) circ.php; unspecified parameters in (e) select.php; and unspecified parameters in other files.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5385

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5386

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5387

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5388

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.

    Published: 18 Oct 2006
    5
    Medium

    CVE-2006-5389

    Last Modified: 23 Apr 2026

    tools/tellhim.php in PHP-Wyana allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the path in an error message.

    Published: 18 Oct 2006
    6.8
    Medium

    CVE-2006-5390

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 18 Oct 2006
    5
    Medium

    CVE-2006-5391

    Last Modified: 23 Apr 2026

    Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string to UDP port 25777.

    Published: 18 Oct 2006
    4.9
    Medium

    CVE-2006-5396

    Last Modified: 23 Apr 2026

    The tcp_fuse_rcv_drain function in the Sun Solaris 10 kernel before 20061017, when TCP Fusion is enabled, allows local users to cause a denial of service (system crash) via a TCP loopback connection with both endpoints on the same system.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5384

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AGE parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5392

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in sw/lib_cart/; (7) comment.php, (8) find_comment.php, and (9) lib_comment.php in sw/lib_comment/; (10) sw/lib_find/find.php; and other unspecified PHP scripts.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5395

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long string. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 18 Oct 2006
    5.5
    Medium

    CVE-2006-5393

    Last Modified: 23 Apr 2026

    Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pages that were written during another user's SSL VPN session.

    Published: 18 Oct 2006
    2.1
    Low

    CVE-2006-5394

    Last Modified: 23 Apr 2026

    The default configuration of Cisco Secure Desktop (CSD) has an unchecked "Disable printing" box in Secure Desktop Settings, which might allow local users to read data that was sent to a printer during another user's SSL VPN session.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5383

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comadd.php in Def-Blog 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5379

    Last Modified: 23 Apr 2026

    The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762, and probably on other operating systems, allows local and remote attackers to execute arbitrary code via a large width value in a font glyph, which can be used to overwrite arbitrary memory locations.

    Published: 18 Oct 2006
    7.5
    High

    CVE-2006-5380

    Last Modified: 23 Apr 2026

    Remote file inclusion vulnerability in Contenido CMS allows remote attackers to execute arbitrary PHP code via a URL in the contenido_path parameter to (1) cms/dbfs.php or (2) cms/front_content.php. NOTE: CVE disputes this issue for version 4.6.15, because $contenido_path is set to a static value

    Published: 18 Oct 2006
    5
    Medium

    CVE-2006-5381

    Last Modified: 23 Apr 2026

    Contenido CMS stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain database credentials and other information via a direct request to (1) db_msql.inc, (2) db_mssql.inc, (3) db_mysqli.inc, (4) db_oci8.inc, (5) db_odbc.inc, (6) db_oracle.inc, (7) db_pgsql.inc, or (8) db_sybase.inc in the conlib/ directory.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5358

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Forms component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2 has unknown impact and remote attack vectors, aka Vuln# FORM01.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5367

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.7 up to 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS03 in Oracle Applications Framework, (2) APPS04 in Oracle Applications Technology Stack, and (3) APPS05 in Oracle Balanced Scorecard, (4) APPS09 in Oracle Scripting, and (5) APPS10 in Oracle Trading Community.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5366

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and remote attack vectors related to (1) Oracle Containers for J2EE, aka Vuln# OC4J01, and (2) Oracle Process Mgmt & Notification, aka OPMN01.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5347

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle Collaboration Suite 9.0.4.2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS04.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5375

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in PeopleTools component in Oracle PeopleSoft Enterprise 8.46 GA, 8.47 GA, 8.48 GA, 8.46.15, 8.47.09, and 8.48.03 have unknown impact and remote attack vectors, aka Vuln# (1) PSE01, (2) PSE02, and (3) PSE03.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5377

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PeopleSoft component in Oracle PeopleSoft Enterprise 8.80 GA, 8.90 GA, 8.8 Bundle 11, and 8.9 Bundle 4 has unknown impact and remote authenticated attack vectors, aka Vuln# PSE05.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5372

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10 up to 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS11 for Oracle Universal Work Queue and (2) APPS12 for Oracle Application Object Library.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5370

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS06 for Oracle CRM Gateway for Mobile Devices and (2) APPS08 for Oracle iStore.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5360

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Forms component in Oracle Application Server 9.0.4.2 has unknown impact and remote attack vectors, aka Vuln# FORM03.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5355

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.1.0, Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# SSO01.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5354

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5351

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4) APEX05, (5) APEX06, (6) APEX07, (7) APEX08, (8) APEX09, (9) APEX10, (10) APEX11, (11) APEX12, (12) APEX13, (13) APEX14, (14) APEX15, (15) APEX16, (16) APEX17, (17) APEX18, (18) APEX19, (19) APEX22, (20) APEX23, (21) APEX24, (22) APEX25, (23) APEX26, (24) APEX27, (25) APEX28, (26) APEX29, (27) APEX30, (28) APEX31, (29) APEX32, (30) APEX33, (31) APEX34, and (32) APEX35. NOTE: as of 20061027, it is likely that some of these identifiers are associated with cross-site scripting (XSS) in WWV_FLOW_ITEM_HELP and NOTIFICATION_MSG, but these have been provided separate identifiers.

    Published: 18 Oct 2006
    7.6
    High

    CVE-2006-5346

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4.2 and Oracle E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors related to htdigest, aka Vuln# OHS02.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5345

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_geom, aka Vuln# DB22. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB22 is related to "length checking" in the RELATE function before MD2.RELATE is called.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5344

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_3gl, aka Vuln# DB20, and (2) mdsys.sdo_cs, aka DB21. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB20 is a buffer overflow in GEOM_OPERATION, and DB21 is related to a buffer overflow and SQL injection in TRANSFORM_LAYER.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5339

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_geom, aka Vuln# DB11. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB11 is related to "length checking" in the RELATE function before MD2.RELATE is called.

    Published: 18 Oct 2006
    7.1
    High

    CVE-2006-5333

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact and remote authenticated attack vectors related to "create session" privileges, aka Vuln# DB02. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB02 is for SQL injection in the SDO_DROP_USER_BEFORE package using a Trigger for a DROP USER statement in an anonymous PL/SQL block.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5376

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in PeopleTools component in Oracle PeopleSoft Enterprise 8.22 GA, 8.46 GA, 8.47 GA, 8.48 GA, 8.22.11, 8.46.15, 8.47.09, and 8.48.03 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) PSE04, (2) PSE06, (3) PSE07, and (4) PSE08.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5359

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Reports Developer component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Oracle E-Business Suite and Applications 11.5.10CU2, have unknown impact and remote attack vectors, aka Vuln# (1) REP01 and (2) REP02. NOTE: as of 20061027, Oracle has not disputed reports from a reliable researcher that these issues are related to (a) showenv and (b) parsequery for REP01, and (c) cellwrapper and (d) delimiter for REP02.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5353

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors related to the Mod_rewrite Module, aka Vuln# OHS01.

    Published: 18 Oct 2006