CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-4017

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search module in Inter Network Marketing (INM) CMS G3 allows remote attackers to inject arbitrary web script or HTML via the search_string parameter.

    Published: 7 Aug 2006
    4.3
    Medium

    CVE-2006-4016

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS stable 1.0.3 and earlier, and unstable 1.1 and earlier, allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 7 Aug 2006
    2.1
    Low

    CVE-2006-3123

    Last Modified: 16 Apr 2026

    Multiple integer overflows in the (1) dodecrypt and (2) doencrypt functions in cfs_fh.c in cfsd in Matt Blaze Cryptographic File System (CFS) 1.4.1 before Debian GNU/Linux package 1.4.1-17 allow local users to cause a denial of service (daemon crash) by appending data to a file that is larger than 2 Gb.

    Published: 7 Aug 2006
    4.3
    Medium

    CVE-2006-4002

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 before 4.6.9, and 4.7 before 4.7.3, allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: portions of these details are obtained from third party information.

    Published: 7 Aug 2006
    5
    Medium

    CVE-2006-4003

    Last Modified: 16 Apr 2026

    The config method in Henrik Storner Hobbit monitor before 4.1.2p2 permits access to files outside of the intended configuration directory, which allows remote attackers to obtain sensitive information via requests to the hobbitd daemon on port 1984/tcp.

    Published: 7 Aug 2006
    7.5
    High

    CVE-2006-4007

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.

    Published: 7 Aug 2006
    7.5
    High

    CVE-2006-4008

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter.

    Published: 7 Aug 2006
    4.3
    Medium

    CVE-2006-4009

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 7 Aug 2006
    7.5
    High

    CVE-2006-4010

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vectors are covered by CVE-2006-3139.

    Published: 7 Aug 2006
    2.6
    Low

    CVE-2006-4011

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.

    Published: 7 Aug 2006
    5
    Medium

    CVE-2006-4015

    Last Modified: 16 Apr 2026

    Hewlett-Packard (HP) ProCurve 3500yl, 6200yl, and 5400zl switches with software before K.11.33 allow remote attackers to cause a denial of service (possibly memory leak or system crash) via unknown vectors.

    Published: 7 Aug 2006
    4.6
    Medium

    CVE-2006-3999

    Last Modified: 16 Apr 2026

    ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE library, which allows local users to subvert BlackICE by replacing pamversion.dll. NOTE: in most cases, the attack would not cross privilege boundaries because replacing pamversion.dll requires administrative privileges. However, this issue is a vulnerability because BlackICE is intended to protect against certain rogue privileged actions.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3997

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in hsList.php in WoWRoster (aka World of Warcraft Roster) 1.5.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.

    Published: 5 Aug 2006
    5.1
    Medium

    CVE-2006-0395

    Last Modified: 16 Apr 2026

    The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.

    Published: 5 Aug 2006
    4
    Medium

    CVE-2006-4000

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-4001

    Last Modified: 16 Apr 2026

    Login.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 contains a hard-coded password for the guest account, which allows remote attackers to read sensitive information such as e-mail logs, and possibly e-mail contents and the admin password.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3998

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.

    Published: 5 Aug 2006
    6.5
    Medium

    CVE-2006-3996

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters.

    Published: 5 Aug 2006
    5.1
    Medium

    CVE-2006-3988

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter.

    Published: 5 Aug 2006
    6.8
    Medium

    CVE-2006-3995

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 5 Aug 2006
    5.1
    Medium

    CVE-2006-3992

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3991

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3990

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) Savant2_Plugin_stylesheet.php, (2) Savant2_Compiler_basic.php, (3) Savant2_Error_pear.php, (4) Savant2_Error_stack.php, (5) Savant2_Filter_colorizeCode.php, (6) Savant2_Filter_trimwhitespace.php, (7) Savant2_Plugin_ahref.php, (8) Savant2_Plugin_ahrefcontact.php, (9) Savant2_Plugin_ahreflisting.php, (10) Savant2_Plugin_ahreflistingimage.php, (11) Savant2_Plugin_ahrefmap.php, (12) Savant2_Plugin_ahrefownerlisting.php, (13) Savant2_Plugin_ahrefprint.php, (14) Savant2_Plugin_ahrefrating.php, (15) Savant2_Plugin_ahrefrecommend.php, (16) Savant2_Plugin_ahrefreport.php, (17) Savant2_Plugin_ahrefreview.php, (18) Savant2_Plugin_ahrefvisit.php, (19) Savant2_Plugin_checkbox.php, (20) Savant2_Plugin_cycle.php, (21) Savant2_Plugin_dateformat.php, (22) Savant2_Plugin_editor.php, (23) Savant2_Plugin_form.php, (24) Savant2_Plugin_image.php, (25) Savant2_Plugin_input.php, (26) Savant2_Plugin_javascript.php, (27) Savant2_Plugin_listalpha.php, (28) Savant2_Plugin_listingname.php, (29) Savant2_Plugin_modify.php, (30) Savant2_Plugin_mtpath.php, (31) Savant2_Plugin_options.php, (32) Savant2_Plugin_radios.php, (33) Savant2_Plugin_rating.php, or (34) Savant2_Plugin_textarea.php.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3981

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in about.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 5 Aug 2006
    2.1
    Low

    CVE-2006-3457

    Last Modified: 16 Apr 2026

    Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the Virtual Desktop module in Symantec On-Demand Protection (SODP) before 2.6 Build 2233, do not properly encrypt files that are subject to policy-based automatic encryption, which might allow local users to read sensitive data via an unspecified decryption method.

    Published: 5 Aug 2006
    5.1
    Medium

    CVE-2006-3989

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.

    Published: 5 Aug 2006
    9.3
    Critical

    CVE-2006-3985

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in DZIPS32.DLL 6.0.0.4 in ConeXware PowerArchiver 9.62.03 allows user-assisted attackers to execute arbitrary code by adding a new file to a crafted ZIP archive that already contains a file with a long name.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3983

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3984

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3986

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter.

    Published: 5 Aug 2006
    5.1
    Medium

    CVE-2006-3987

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3982

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH parameter.

    Published: 5 Aug 2006
    5.1
    Medium

    CVE-2006-3993

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter.

    Published: 5 Aug 2006
    7.5
    High

    CVE-2006-3994

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.

    Published: 5 Aug 2006
    6.8
    Medium

    CVE-2006-3980

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 5 Aug 2006
    9.3
    Critical

    CVE-2006-3977

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 has unknown impact and remote attackers related to "improper processing of outdated WebScan components."

    Published: 4 Aug 2006
    7.5
    High

    CVE-2006-3975

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CA eTrust Antivirus WebScan allows remote attackers to execute arbitrary code due to "improper bounds checking when processing certain user input."

    Published: 4 Aug 2006
    4.9
    Medium

    CVE-2006-3634

    Last Modified: 16 Apr 2026

    The (1) __futex_atomic_op and (2) futex_atomic_cmpxchg_inatomic functions in Linux kernel 2.6.17-rc4 to 2.6.18-rc2 perform the atomic futex operation in the kernel address space instead of the user address space, which allows local users to cause a denial of service (crash).

    Published: 4 Aug 2006
    9.3
    Critical

    CVE-2006-3976

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CA eTrust Antivirus WebScan before 1.1.0.1048 allows remote attackers to install arbitrary files.

    Published: 4 Aug 2006
    4.6
    Medium

    CVE-2006-4020

    Last Modified: 16 Apr 2026

    scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments an index past the end of an array and triggers a buffer over-read.

    Published: 4 Aug 2006
    5.1
    Medium

    CVE-2006-3501

    Last Modified: 16 Apr 2026

    Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Radiance image.

    Published: 3 Aug 2006
    5.1
    Medium

    CVE-2006-3502

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled.

    Published: 3 Aug 2006
    5.1
    Medium

    CVE-2006-3503

    Last Modified: 16 Apr 2026

    Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF image.

    Published: 3 Aug 2006
    5.1
    Medium

    CVE-2006-3504

    Last Modified: 16 Apr 2026

    The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.

    Published: 3 Aug 2006
    7.5
    High

    CVE-2006-3505

    Last Modified: 16 Apr 2026

    WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated.

    Published: 3 Aug 2006
    5.1
    Medium

    CVE-2006-0392

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.

    Published: 3 Aug 2006
    2.1
    Low

    CVE-2006-3499

    Last Modified: 16 Apr 2026

    The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications.

    Published: 3 Aug 2006
    4
    Medium

    CVE-2006-0393

    Last Modified: 16 Apr 2026

    OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.

    Published: 3 Aug 2006
    7.2
    High

    CVE-2006-3500

    Last Modified: 16 Apr 2026

    The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," probably related to an untrusted search path vulnerability.

    Published: 3 Aug 2006
    6.8
    Medium

    CVE-2006-3971

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in visitor/livesupport/chat.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to inject arbitrary web script or HTML via the userid parameter.

    Published: 2 Aug 2006