CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2006-4376

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Guder und Koch Netzwerktechnik Eichhorn Portal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) profil_nr and (2) sprache parameters in the main portion of the portal, the (3) suchstring field in suchForm in the main portion of the portal, the (4) GaleryKey and (5) Breadcrumbs parameters in the gallerie module, and the (6) GGBNSaction parameter in the ggbns module.

    Published: 26 Aug 2006
    7.5
    High

    CVE-2006-4365

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/functions_mod_user.php or (2) includes/functions_portal.php.

    Published: 26 Aug 2006
    2.6
    Low

    CVE-2006-4374

    Last Modified: 16 Apr 2026

    IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.

    Published: 26 Aug 2006
    4.9
    Medium

    CVE-2008-2729

    Last Modified: 23 Apr 2026

    arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.

    Published: 26 Aug 2006
    7.5
    High

    CVE-2006-4354

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the check_path parameter.

    Published: 25 Aug 2006
    2.6
    Low

    CVE-2006-4355

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Aug 2006
    4.3
    Medium

    CVE-2006-4358

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay allows remote attackers to inject arbitrary web script or HTML via the read parameter.

    Published: 25 Aug 2006
    5.1
    Medium

    CVE-2006-4359

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to execute arbitrary code via a ZIP archive containing a long filename.

    Published: 25 Aug 2006
    3.5
    Low

    CVE-2006-4360

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Aug 2006
    4.3
    Medium

    CVE-2006-4361

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in jobseekers/forgot.php in Diesel Job Site allow remote attackers to inject arbitrary web script or HTML via the (1) uname or (2) SEmail parameters.

    Published: 25 Aug 2006
    7.5
    High

    CVE-2006-4363

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin.cropcanvas.php in the CropImage component (com_cropimage) 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the cropimagedir parameter.

    Published: 25 Aug 2006
    7.5
    High

    CVE-2006-4357

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in clients/index.php in Diesel Smart Traffic allows remote attackers to execute arbitrary PHP code via a URL in the src parameter.

    Published: 25 Aug 2006
    5
    Medium

    CVE-2006-4364

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via long strings that contain '@' characters in the (1) USER and (2) APOP commands.

    Published: 25 Aug 2006
    7.5
    High

    CVE-2006-4356

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Drupal Easylinks Module (easylinks.module) 4.7 before 1.5.2.1 2006/08/19 12:02:27 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 25 Aug 2006
    4.3
    Medium

    CVE-2006-4362

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid Mail allows remote attackers to inject arbitrary web script or HTML via the ps parameter.

    Published: 25 Aug 2006
    5
    Medium

    CVE-2006-4352

    Last Modified: 16 Apr 2026

    The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attackers to obtain sensitive information.

    Published: 25 Aug 2006
    5
    Medium

    CVE-2006-4353

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Java System Content Delivery Server 4.0, 4.1, and 5.0 allows local and remote attackers to read data from arbitrary files via unspecified vectors.

    Published: 25 Aug 2006
    6.4
    Medium

    CVE-2006-2113

    Last Modified: 16 Apr 2026

    The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote attackers to modify system configuration via crafted requests, including changing the administrator password or causing a denial of service to the print server.

    Published: 25 Aug 2006
    7.5
    High

    CVE-2006-2112

    Last Modified: 16 Apr 2026

    Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy ("FTP bounce") by using arbitrary PORT arguments to connect to systems for which access would be otherwise restricted.

    Published: 25 Aug 2006
    7.5
    High

    CVE-2006-4347

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in user logon authentication request handling in Cool_CoolD.exe in Cool Manager 5.0 (5,60,90,28) and Cool Messenger Office/School Server 5.5 (5,65,12,13) allows remote attackers to execute arbitrary SQL commands via the username field.

    Published: 24 Aug 2006
    6.8
    Medium

    CVE-2006-4351

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4348

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4349

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tcms_administer_site parameter to an unspecified script, probably index.php. NOTE: this issue has been disputed by a third party, who states that $tcms_administer_site is initialized to a constant value within index.php

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4350

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Aug 2006
    5
    Medium

    CVE-2006-4344

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) before 8.3 allows remote attackers to spoof e-mails and inject e-mail headers via unspecified vectors in (1) mail.cgi and (2) query.cgi.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4345

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in channels/chan_mgcp.c in MGCP in Asterisk 1.0 through 1.2.10 allows remote attackers to execute arbitrary code via a crafted audit endpoint (AUEP) response.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4346

    Last Modified: 16 Apr 2026

    Asterisk 1.2.10 supports the use of client-controlled variables to determine filenames in the Record function, which allows remote attackers to (1) execute code via format string specifiers or (2) overwrite files via directory traversals involving unspecified vectors, as demonstrated by the CALLERIDNAME variable.

    Published: 24 Aug 2006
    5
    Medium

    CVE-2006-4332

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the DHCP dissector in Wireshark (formerly Ethereal) 0.10.13 through 0.99.2, when run on Windows, allows remote attackers to cause a denial of service (crash) via unspecified vectors that trigger a bug in Glib.

    Published: 24 Aug 2006
    7.2
    High

    CVE-2006-4319

    Last Modified: 16 Apr 2026

    Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4320

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sef.php in the OpenSEF 2.0.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4321

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4323

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in list.php in CityForFree indexcity 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Published: 24 Aug 2006
    5.1
    Medium

    CVE-2006-4328

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4329

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) core/includes/security.inc.php, (2) core/includes/smarty.inc.php, (3) qcms/includes/smarty.inc.php or (4) qlib/smarty.inc.php.

    Published: 24 Aug 2006
    6.8
    Medium

    CVE-2006-4317

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab Burning Board (WBB) 2.3.5 allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript.

    Published: 24 Aug 2006
    6.8
    Medium

    CVE-2006-4325

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in gbook.php in Doika guestbook 2.5, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4326

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.

    Published: 24 Aug 2006
    6.5
    Medium

    CVE-2006-4318

    Last Modified: 16 Apr 2026

    Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.

    Published: 24 Aug 2006
    6.8
    Medium

    CVE-2006-4327

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.

    Published: 24 Aug 2006
    7.5
    High

    CVE-2006-4322

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 24 Aug 2006
    6.8
    Medium

    CVE-2006-4324

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_url2.php in CityForFree indexcity 1.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 24 Aug 2006
    10
    Critical

    CVE-2006-4304

    Last Modified: 16 Apr 2026

    Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly execute arbitrary code via crafted Link Control Protocol (LCP) packets with an option length that exceeds the overall length, which triggers the overflow in (1) pppoe and (2) ippp. NOTE: this issue was originally incorrectly reported for the ppp driver.

    Published: 24 Aug 2006
    5
    Medium

    CVE-2006-4313

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors.

    Published: 23 Aug 2006
    5
    Medium

    CVE-2006-4314

    Last Modified: 16 Apr 2026

    The manager server in Symantec Enterprise Security Manager (ESM) 6 and 6.5.x allows remote attackers to cause a denial of service (hang) via a malformed ESM agent request.

    Published: 23 Aug 2006
    6.8
    Medium

    CVE-2006-4312

    Last Modified: 16 Apr 2026

    Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable password to be changed to a "non-random value" under certain circumstances, which causes administrators to be locked out and might allow attackers to gain access.

    Published: 23 Aug 2006
    7.2
    High

    CVE-2006-4315

    Last Modified: 16 Apr 2026

    Unquoted Windows search path vulnerability in multiple SSH Tectia products, including Client/Server/Connector 5.0.0 and 5.0.1 and Client/Server before 4.4.5, and Manager 2.12 and earlier, when running on Windows, might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.

    Published: 23 Aug 2006
    7.2
    High

    CVE-2006-4316

    Last Modified: 16 Apr 2026

    SSH Tectia Management Agent 2.1.2 allows local users to gain root privileges by running a program called sshd, which is obtained from a process listing when the "Restart" action is selected from the Management server GUI, which causes the agent to locate the pathname of the user's program and restart it with root privileges.

    Published: 23 Aug 2006
    7.2
    High

    CVE-2006-4307

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.

    Published: 23 Aug 2006
    7.2
    High

    CVE-2006-4306

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 allows local users to execute arbitrary commands via unspecified vectors, involving the default Role-Based Access Control (RBAC) settings in the "File System Management" profile.

    Published: 23 Aug 2006
    4.3
    Medium

    CVE-2006-4308

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML tags when posting to the Discussion Board.

    Published: 23 Aug 2006