CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2006-3403

    Last Modified: 16 Apr 2026

    The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.

    Published: 10 Jul 2006
    7.5
    High

    CVE-2006-1176

    Last Modified: 16 Apr 2026

    Buffer overflow in eBay Enhanced Picture Services (aka EPUImageControl Class) in EUPWALcontrol.dll before 1.0.3.48, as used in Sell Your Item (SYI), Setup & Test eBay Enhanced Picture Services, Picture Manager Enhanced Uploader, and CARad.com Add Vehicle, allows remote attackers to execute arbitrary code via a crafted HTML document.

    Published: 8 Jul 2006
    2.1
    Low

    CVE-2006-3458

    Last Modified: 16 Apr 2026

    Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3431

    Last Modified: 16 Apr 2026

    Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls. NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.

    Published: 7 Jul 2006
    6.4
    Medium

    CVE-2006-3407

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3408

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3409

    Last Modified: 16 Apr 2026

    Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3410

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unspecified statistical attacks.

    Published: 7 Jul 2006
    6.4
    Medium

    CVE-2006-3411

    Last Modified: 16 Apr 2026

    TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.

    Published: 7 Jul 2006
    6.4
    Medium

    CVE-2006-3412

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.

    Published: 7 Jul 2006
    6.4
    Medium

    CVE-2006-3417

    Last Modified: 16 Apr 2026

    Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard" (is_guard) systems by directory authorities.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3418

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3419

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes, and seeds the entropy value at start-up with 160-bit chunks without reseeding, which makes it easier for attackers to conduct brute force guessing attacks.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3425

    Last Modified: 16 Apr 2026

    FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3426

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.

    Published: 7 Jul 2006
    5.8
    Medium

    CVE-2006-3405

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3424

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in WebEx Downloader ActiveX Control, possibly in versions before November 2005, allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 7 Jul 2006
    6.4
    Medium

    CVE-2006-3406

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3414

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.

    Published: 7 Jul 2006
    6.4
    Medium

    CVE-2006-3415

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3416

    Last Modified: 16 Apr 2026

    Tor before 0.1.1.20 kills the circuit when it receives an unrecognized relay command, which causes network circuits to be disbanded. NOTE: while this item is listed under the "Security fixes" section of the developer changelog, the developer clarified on 20060707 that this is only a self-DoS. Therefore this issue should not be included in CVE

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3420

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Jul 2006
    5.1
    Medium

    CVE-2006-3421

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3422

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via the config[template_path] parameter in user_bottom.php, as used by multiple templates including (1) rwb (template/rwb/user_bottom.php), (2) gwb (template/rwb/user_bottom.php, (3) blues, (4) bluwhi, and (5) grns.

    Published: 7 Jul 2006
    9.3
    Critical

    CVE-2006-3423

    Last Modified: 16 Apr 2026

    WebEx Downloader ActiveX Control and WebEx Downloader Java before 2.1.0.0 do not validate downloaded components, which allows remote attackers to execute arbitrary code via a website that activates the GpcUrlRoot and GpcIniFileName ActiveX controls to cause the client to download a DLL file.

    Published: 7 Jul 2006
    4.3
    Medium

    CVE-2006-3428

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the year parameter in (1) loan.php and (2) mortgage.php.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3430

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3413

    Last Modified: 16 Apr 2026

    The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.

    Published: 7 Jul 2006
    5
    Medium

    CVE-2006-3427

    Last Modified: 16 Apr 2026

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.

    Published: 7 Jul 2006
    4.3
    Medium

    CVE-2006-3429

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows remote attackers to inject arbitrary web script or HTML via the currency parameter in (1) loan.php and (2) mortgage.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Jul 2006
    7.5
    High

    CVE-2006-3355

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.

    Published: 6 Jul 2006
    2.6
    Low

    CVE-2006-3356

    Last Modified: 16 Apr 2026

    The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue than CVE-2006-1469.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3357

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3361

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDIP parameter in studip-htdocs/archiv_assi.php.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3363

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to execute arbitrary PHP code via a URL in the pa parameter.

    Published: 6 Jul 2006
    7.5
    High

    CVE-2006-3364

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3368

    Last Modified: 16 Apr 2026

    Efone 20000723 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3369

    Last Modified: 16 Apr 2026

    Kamikaze-QSCM 0.1 stores config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3370

    Last Modified: 16 Apr 2026

    Blueboy 1.0.3 stores bb_news_config.inc under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3371

    Last Modified: 16 Apr 2026

    Eupla Foros 1.0 stores the inc/config.inc file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information, including the database configuration.

    Published: 6 Jul 2006
    4
    Medium

    CVE-2006-3377

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlier, allows remote attackers to inject arbitrary web script or HTML via the (1) Keyword parameter in search.php and the (2) Username parameter in main.cgi.

    Published: 6 Jul 2006
    7.2
    High

    CVE-2006-3378

    Last Modified: 16 Apr 2026

    passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3379

    Last Modified: 16 Apr 2026

    Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.

    Published: 6 Jul 2006
    4.3
    Medium

    CVE-2006-3382

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in mAds 1.0 allows remote attackers to inject arbitrary web script or HTML via the "search string".

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3384

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) texte parameters.

    Published: 6 Jul 2006
    5.8
    Medium

    CVE-2006-3385

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.

    Published: 6 Jul 2006
    5
    Medium

    CVE-2006-3386

    Last Modified: 16 Apr 2026

    index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation path, via a mail[] parameter with invalid values.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3387

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil_config parameter, which can be used to execute PHP code that has been injected into a log file.

    Published: 6 Jul 2006
    5.1
    Medium

    CVE-2006-3391

    Last Modified: 16 Apr 2026

    The Execute function in iMBCContents ActiveX Control before 2.0.0.59 allows remote attackers to execute arbitrary files via the file URI handler.

    Published: 6 Jul 2006
    7.8
    High

    CVE-2006-3393

    Last Modified: 16 Apr 2026

    Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket.

    Published: 6 Jul 2006