CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-5352

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Application Express 1.5 up to 1.6.1 have unknown impact and remote attack vectors, aka Vuln# (1) APEX04, (2) APEX20, and (3) APEX21.

    Published: 18 Oct 2006
    7.1
    High

    CVE-2006-5340

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdo_lrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related to bypassing input validation for SQL injection related to convert_to_lrs_layer and dbms_assert, and DB17 is related to SQL injection in the trigger in the SDO_DROP_USER package.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5338

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact and remote authenticated attack vectors related to sys.dbms_sqltune, aka Vuln# DB10. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB10 is for SQL injection in DROP_SQLSET, DELETE_SQLSET, SELECT_SQLSET, and I_SET_TUNING_PARAMETER. NOTE: some of these vectors might be in DBMS_SQLTUNE_INTERNAL.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5332

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in xdb.dbms_xdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB01 is for PL/SQL injection in the ENABLE_HIERARCHY_INTERNAL procedure.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5343

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5341

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in XMLDB component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors, aka (1) Vuln# DB14 and (2) DB15 related to xdb.dbms_xdbz. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB14 is for SQL injection in the PITRIG_DROP and PITRIG_DROPMETADATA functions in XDB_PITRIG_PKG, and DB15 is for SQL injection in DISABLE_HIERARCHY_INTERNAL in DBMS_XDBZ.

    Published: 18 Oct 2006
    7.1
    High

    CVE-2006-5342

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.3 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_tune, aka Vuln# DB18. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB18 might be related to SQL injection in the EXTENT_OF function.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5348

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5349

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS07.

    Published: 18 Oct 2006
    7.2
    High

    CVE-2006-5350

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and local attack vectors, aka Vuln# OHS08.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5356

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.1.0, and Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J02.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5357

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 10.1.2.0.2, and 10.1.2.1.0 has unknown impact and remote attack vectors related to the PHP Module, aka Vuln# OHS03.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5361

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.1, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J03.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5362

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 10.1.3.0.0 has unknown impact and remote attack vectors, aka Vuln# OC4J04.

    Published: 18 Oct 2006
    2.6
    Low

    CVE-2006-5363

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 10.1.2.0.1 and Collaboration Suite 10.1.2 has unknown impact and remote attack vectors, aka Vuln# SSO02.

    Published: 18 Oct 2006
    2.1
    Low

    CVE-2006-5364

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4.1 and 10.1.2.0.2, and Collaboration Suite 10.1.2, has unknown impact and remote authenticated attack vectors, aka Vuln# OC4J05.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5365

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Forms in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors, aka Vuln# FORM02.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5369

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Object Library in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS02.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5371

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Email Center component in Oracle E-Business Suite 11.5.9 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS07.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5373

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Install Base component in Oracle E-Business Suite 11.5.10CU1 has unknown impact and remote authenticated attack vectors, aka Vuln# APPS13.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5374

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Pharmaceutical Applications 4.5.1 has unknown impact and remote authenticated attack vectors, aka Vuln# PHAR01.

    Published: 18 Oct 2006
    10
    Critical

    CVE-2006-5368

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Exchange component in Oracle E-Business Suite 6.2.4 has unknown impact and remote attack vectors, aka Vuln# APPS01.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5378

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in JD Edwards HTML Server in JD Edwards EnterpriseOne SP23_O2, 8.95.P1, and 8.96.D1 has unknown impact and remote authenticated attack vectors, aka Vuln# JDE01.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5337

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 has unknown impact and remote authenticated attack vectors, aka Vuln# DB09.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5336

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06). NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB05 is for SQL injection in CREATE_CHANGE_TABLE and CHANGE_TABLE_TRIGGER, and DB06 is for PL/SQL injection in the PREPARE_UNBOUNDED_VIEW procedure.

    Published: 18 Oct 2006
    9
    Critical

    CVE-2006-5335

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) Vuln# DB04 and sys.dbms_cdc_impdp in the (a) Change Data Capture (CDC) component; (2) Vuln# DB07, (3) DB08, and (4) DB16 in sys.dbms_cdc_isubscribe in CDC; and (5) mdsys.sdo_geor_int in the (b) Oracle Spatial component, aka DB12. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that these issues are related to SQL injection in the BUMP_SEQUENCE function (DB04), CREATE_SUBSCRIPTION (DB07), EXTEND_WINDOW_LIST (DB08), SUBSCRIBE (DB16), and COMPRESSDATA (DB12).

    Published: 18 Oct 2006
    7.1
    High

    CVE-2006-5334

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and remote authenticated attack vectors related to mdsys.md2, aka Vuln# DB03. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB03 is related to one or more of (1) a buffer overflow in the (a) RELATE function or (2) SQL injection in the (b) TESSELATE_FIXED and (c) TESSELATE function.

    Published: 18 Oct 2006
    2.1
    Low

    CVE-2006-5397

    Last Modified: 23 Apr 2026

    The Xinput module (modules/im/ximcp/imLcIm.c) in X.Org libX11 1.0.2 and 1.0.3 opens a file for reading twice using the same file descriptor, which causes a file descriptor leak that allows local users to read files specified by the XCOMPOSEFILE environment variable via the duplicate file descriptor.

    Published: 18 Oct 2006
    2.1
    Low

    CVE-2006-5173

    Last Modified: 23 Apr 2026

    Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignment Check flag (EFLAGS 0x40000), which triggers a SIGBUS in other processes that have an unaligned access.

    Published: 17 Oct 2006
    5.1
    Medium

    CVE-2006-4819

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Opera 9.0 and 9.01 allows remote attackers to execute arbitrary code via a long URL in a tag (long link address).

    Published: 17 Oct 2006
    7.2
    High

    CVE-2006-5327

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAR_OPTIONS environment variable settings, when gnutar is invoked by OpenBase.

    Published: 17 Oct 2006
    7.2
    High

    CVE-2006-5328

    Last Modified: 23 Apr 2026

    OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to create arbitrary files via a symlink attack on the simulation.sql file.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5324

    Last Modified: 23 Apr 2026

    The Web Services Notification (WSN) security component of IBM WebSphere Application Server before 6.1.0.2 allows attackers to obtain unspecified access without supplying a username and password, aka PK28374.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5326

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang/lang_contact_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5325

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Suite IP Logger in dwingmods for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) mkb.php, (2) iplogger.php, (3) admin_board2.php, or (4) admin_logger.php in includes/, different vectors than CVE-2006-5224.

    Published: 17 Oct 2006
    10
    Critical

    CVE-2006-5323

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server before 6.1.0.2 has unspecified impact and attack vectors, related to a "possible security exposure," aka PK29360.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5317

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5315

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page parameter.

    Published: 17 Oct 2006
    7.8
    High

    CVE-2006-5316

    Last Modified: 23 Apr 2026

    registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for /usuarios.dat.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5318

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an FTP URL in the section parameter.

    Published: 17 Oct 2006
    5
    Medium

    CVE-2006-5319

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter.

    Published: 17 Oct 2006
    5
    Medium

    CVE-2006-5320

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter.

    Published: 17 Oct 2006
    4.3
    Medium

    CVE-2006-5321

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phplist before 2.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5322

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phplist before 2.10.3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5314

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.

    Published: 17 Oct 2006
    6.5
    Medium

    CVE-2006-5313

    Last Modified: 23 Apr 2026

    Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message parameter. NOTE: this crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session. NOTE: this is a different type of issue than CVE-2006-5262.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5309

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5312

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 17 Oct 2006
    7.5
    High

    CVE-2006-5311

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Buzlas 2006-1 Full allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 17 Oct 2006
    6.8
    Medium

    CVE-2006-5310

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.

    Published: 17 Oct 2006