CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2006-5075

    Last Modified: 23 Apr 2026

    The Kernel SSL Proxy service (svc:/network/ssl/proxy) in Sun Solaris 10 before 20060926 allows remote attackers to cause a denial of service (system crash) via unspecified vectors related to an SSL client.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5076

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.

    Published: 29 Sept 2006
    5.1
    Medium

    CVE-2006-5077

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5078

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5082

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) before 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, and unspecified attack vectors.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5085

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected into include/variables.php.

    Published: 29 Sept 2006
    4.3
    Medium

    CVE-2006-5080

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5084

    Last Modified: 23 Apr 2026

    Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally reported to involve a null dereference.

    Published: 29 Sept 2006
    6.4
    Medium

    CVE-2006-5086

    Last Modified: 23 Apr 2026

    Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

    Published: 29 Sept 2006
    5.1
    Medium

    CVE-2006-5456

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5079

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5081

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in acc.php in QuickBlogger (QB) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 29 Sept 2006
    9.3
    Critical

    CVE-2006-5868

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.

    Published: 29 Sept 2006
    5
    Medium

    CVE-2006-4925

    Last Modified: 23 Apr 2026

    packet.c in ssh in OpenSSH allows remote attackers to cause a denial of service (crash) by sending an invalid protocol sequence with USERAUTH_SUCCESS before NEWKEYS, which causes newkeys[mode] to be NULL.

    Published: 29 Sept 2006
    7.5
    High

    CVE-2006-5053

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content_page parameter.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5060

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Jamroom 3.0.16 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the forgot parameter in the forgot mode.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5061

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5057

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5059

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WWWthreads 5.4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the Cat parameter to (1) dosearch.php, (2) postlist.php, (3) showmembers.php, (4) faq_english.php, (5) online.php, (6) login.php, (7) newuser.php, (8) wwwthreads.php, (9) search.php, or (10) postlist.php.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5065

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5066

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5067

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in loader.php in PHP System Administration Toolkit (PHPSaTK) allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config] parameter. NOTE: this issue is disputed by CVE; analysis shows that the GLOBALS[config] variable is initialized before being used

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5068

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.

    Published: 28 Sept 2006
    2.6
    Low

    CVE-2006-5069

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5056

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web script or HTML via the destination parameter in the Login view.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5058

    Last Modified: 23 Apr 2026

    Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute arbitrary code via a long map argument to the "callvote map" command.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5062

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.

    Published: 28 Sept 2006
    4.3
    Medium

    CVE-2006-5071

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before 0.9.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) eyeNav and (2) system/baixar.php.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5158

    Last Modified: 23 Apr 2026

    The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and a deadlock.

    Published: 28 Sept 2006
    7.8
    High

    CVE-2006-2940

    Last Modified: 23 Apr 2026

    OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.

    Published: 28 Sept 2006
    10
    Critical

    CVE-2006-3738

    Last Modified: 23 Apr 2026

    Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.

    Published: 28 Sept 2006
    4.3
    Medium

    CVE-2006-4343

    Last Modified: 23 Apr 2026

    The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5055

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5063

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote attackers to inject arbitrary web script or HTML by editing log entries in HTML mode.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5064

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 28 Sept 2006
    5.1
    Medium

    CVE-2006-5070

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fsinit][objpath] parameter.

    Published: 28 Sept 2006
    7.8
    High

    CVE-2006-2937

    Last Modified: 23 Apr 2026

    OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5054

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter.

    Published: 28 Sept 2006
    2.1
    Low

    CVE-2006-5174

    Last Modified: 23 Apr 2026

    The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.

    Published: 28 Sept 2006
    7.5
    High

    CVE-2006-5017

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/all_users.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to execute arbitrary SQL commands via the from parameter.

    Published: 27 Sept 2006
    4
    Medium

    CVE-2006-5018

    Last Modified: 23 Apr 2026

    ContentKeeper 123.25 and earlier places passwords in cleartext in an INPUT element in cgi-bin/ck/changepw.cgi, which allows remote authenticated users to obtain passwords via this URI.

    Published: 27 Sept 2006
    5
    Medium

    CVE-2006-5019

    Last Modified: 23 Apr 2026

    Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message.

    Published: 27 Sept 2006
    10
    Critical

    CVE-2006-5026

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.3 have unknown impact and attack vectors.

    Published: 27 Sept 2006
    7.5
    High

    CVE-2006-5032

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter.

    Published: 27 Sept 2006
    5
    Medium

    CVE-2006-5033

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a denial of service via the session parameter, possibly related to format string specifiers or malformed URL encoding.

    Published: 27 Sept 2006
    5
    Medium

    CVE-2006-5034

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 27 Sept 2006
    4.3
    Medium

    CVE-2006-5035

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Paul Smith Computer Services vCAP 1.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the statusmsg parameter in RegisterPage.cgi or (2) a URI corresponding to a nonexistent file. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 27 Sept 2006
    6.8
    Medium

    CVE-2006-5036

    Last Modified: 23 Apr 2026

    MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider this a vulnerability.

    Published: 27 Sept 2006
    7.5
    High

    CVE-2006-5039

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Events 1.3 beta module (com_events) for Joomla! has unspecified impact and attack vectors.

    Published: 27 Sept 2006
    7.5
    High

    CVE-2006-5040

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SEF404x (com_sef) for Joomla! has unspecified impact and attack vectors.

    Published: 27 Sept 2006