CVE Feed

    Dashboard / CVE

    4.9
    Medium

    CVE-2008-2944

    Last Modified: 23 Apr 2026

    Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB testsuite, a different vulnerability than CVE-2008-2365.

    Published: 18 Sept 2006
    3.5
    Low

    CVE-2006-7232

    Last Modified: 23 Apr 2026

    sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.

    Published: 16 Sept 2006
    7.5
    High

    CVE-2006-4823

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter.

    Published: 15 Sept 2006
    4.3
    Medium

    CVE-2006-4825

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) ti, (2) bi, or (3) cbgi parameters.

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4826

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Published: 15 Sept 2006
    5.1
    Medium

    CVE-2006-4827

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.

    Published: 15 Sept 2006
    10
    Critical

    CVE-2006-4831

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IP over DNS is now easy (iodine) before 0.3.2 has unknown impact and attack vectors, related to "potential security problems."

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4832

    Last Modified: 16 Apr 2026

    Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via a long username.

    Published: 15 Sept 2006
    7.8
    High

    CVE-2006-4833

    Last Modified: 16 Apr 2026

    Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allow remote attackers to cause a denial of service (hang or reboot) via an ICMP packet with the same destination and source address and port, aka the "Land" vulnerability.

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4834

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter.

    Published: 15 Sept 2006
    5
    Medium

    CVE-2006-4835

    Last Modified: 16 Apr 2026

    Bluview Blue Magic Board (BMB) (aka BMForum) 5.5 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) db_mysql_error.php, (4) langlist.php, (5) sendmail.php, or (6) style.php, which reveals the path in various error messages.

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4824

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.

    Published: 15 Sept 2006
    6.8
    Medium

    CVE-2006-4829

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name parameter in a blog post.

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4837

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.

    Published: 15 Sept 2006
    4.3
    Medium

    CVE-2006-4821

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Userreview module before 1.19 2006/09/12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Sept 2006
    4.3
    Medium

    CVE-2006-4822

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in eMuSOFT emuCMS 0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query or (2) page parameters.

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4828

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.

    Published: 15 Sept 2006
    10
    Critical

    CVE-2006-4830

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in EditBlogTemplatesPlugin.java in David Czarnecki Blojsom 2.30 allows remote attackers to have an unknown impact by sending an HTTP request with a certain value of blogTemplate.

    Published: 15 Sept 2006
    4.3
    Medium

    CVE-2006-4838

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version parameters in (a) admin/inc/footer.inc.php, and the root_url, (3) page_top_name, (4) page_name, and (5) page_options parameters in (b) admin/inc/header.inc.php.

    Published: 15 Sept 2006
    5.1
    Medium

    CVE-2006-4836

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.php vector is already covered by CVE-2005-4227.

    Published: 15 Sept 2006
    2.1
    Low

    CVE-2006-4820

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in X.25 on HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.

    Published: 15 Sept 2006
    4.3
    Medium

    CVE-2006-4568

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

    Published: 15 Sept 2006
    4
    Medium

    CVE-2006-4340

    Last Modified: 16 Apr 2026

    Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.

    Published: 15 Sept 2006
    10
    Critical

    CVE-2006-4571

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data.

    Published: 15 Sept 2006
    9.3
    Critical

    CVE-2006-4565

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."

    Published: 15 Sept 2006
    5
    Medium

    CVE-2006-4566

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character set ("[\\"), which leads to a buffer over-read.

    Published: 15 Sept 2006
    2.6
    Low

    CVE-2006-4567

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update.

    Published: 15 Sept 2006
    2.6
    Low

    CVE-2006-4570

    Last Modified: 16 Apr 2026

    Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or replies to the original message.

    Published: 15 Sept 2006
    2.6
    Low

    CVE-2006-4569

    Last Modified: 16 Apr 2026

    The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.

    Published: 15 Sept 2006
    7.5
    High

    CVE-2006-4437

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.

    Published: 14 Sept 2006
    6.2
    Medium

    CVE-2006-4801

    Last Modified: 16 Apr 2026

    Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary files, including dejavu_manual.rb, which are executed with raised privileges.

    Published: 14 Sept 2006
    4.6
    Medium

    CVE-2006-4802

    Last Modified: 16 Apr 2026

    Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notification messages, a different vector than CVE-2006-3454, a "second format string vulnerability" as found by the vendor.

    Published: 14 Sept 2006
    7.2
    High

    CVE-2006-4803

    Last Modified: 16 Apr 2026

    The Fan-Out Linux and UNIX receiver scripts in Novell Identity Manager (IDM) 3.0.1 allows local users to execute arbitrary commands via unspecified vectors involving certain environment variables and "code injection."

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4800

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4) sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10) shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.

    Published: 14 Sept 2006
    4.6
    Medium

    CVE-2006-4795

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.

    Published: 14 Sept 2006
    4.3
    Medium

    CVE-2006-4796

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).

    Published: 14 Sept 2006
    5
    Medium

    CVE-2006-4798

    Last Modified: 16 Apr 2026

    SQL-Ledger before 2.4.4 stores a password in a query string, which might allow context-dependent attackers to obtain the password via a Referer field or browser history.

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4793

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL commands, as demonstrated by the icerikno parameter.

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4799

    Last Modified: 16 Apr 2026

    Buffer overflow in ffmpeg for xine-lib before 1.1.2 might allow context-dependent attackers to execute arbitrary code via a crafted AVI file and "bad indexes", a different vulnerability than CVE-2005-4048 and CVE-2006-2802.

    Published: 14 Sept 2006
    4.3
    Medium

    CVE-2006-4794

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (PATH_INFO) in (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php, (7) signup.php, (8) submitnews.php, and (9) user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 14 Sept 2006
    4.3
    Medium

    CVE-2006-4797

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in tag.php in CloudNine Interactive CJ Tag Board 3.0 allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a url BBcode tag in the cjmsg parameter.

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4778

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Creative Commons Tools ccHost before 3.0 allows remote attackers to execute arbitrary SQL commands via a crafted URL, which is used to populate the file ID. NOTE: Some details are obtained from third party information.

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4779

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 14 Sept 2006
    5.1
    Medium

    CVE-2006-4783

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in squads.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the squadID parameter.

    Published: 14 Sept 2006
    4.3
    Medium

    CVE-2006-4784

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4785

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format parameter as stored in the $blogEntry variable, which is not properly handled by the insert_record function, which calls _adodb_column_sql in the adodb layer (lib/adodb/adodb-lib.inc.php), which does not convert the data type to an int.

    Published: 14 Sept 2006
    5
    Medium

    CVE-2006-4786

    Last Modified: 16 Apr 2026

    Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.

    Published: 14 Sept 2006
    2.1
    Low

    CVE-2006-4787

    Last Modified: 16 Apr 2026

    AlphaMail before 1.0.16 allows local users to obtain sensitive information via the logging functionality, which displays unencrypted passwords in an error message. NOTE: some details are obtained from third party information.

    Published: 14 Sept 2006
    7.5
    High

    CVE-2006-4781

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained from third party information.

    Published: 14 Sept 2006
    4.6
    Medium

    CVE-2006-4789

    Last Modified: 16 Apr 2026

    Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or execute arbitrary code via a long project name in an open_movie_editor_project XML tag.

    Published: 14 Sept 2006