CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-3055

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in VBZooM 1.02 allow remote attackers to execute arbitrary SQL commands via the (1) QuranID, (2) ShowByQuranID, or (3) Action parameters to meaning.php.

    Published: 16 Jun 2006
    5
    Medium

    CVE-2006-3057

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption.

    Published: 16 Jun 2006
    4.9
    Medium

    CVE-2006-4145

    Last Modified: 16 Apr 2026

    The Universal Disk Format (UDF) filesystem driver in Linux kernel 2.6.17 and earlier allows local users to cause a denial of service (hang and crash) via certain operations involving truncated files, as demonstrated via the dd command.

    Published: 16 Jun 2006
    6.8
    Medium

    CVE-2006-2195

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.

    Published: 15 Jun 2006
    7.8
    High

    CVE-2006-2916

    Last Modified: 16 Apr 2026

    artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

    Published: 15 Jun 2006
    6.8
    Medium

    CVE-2006-3022

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3024

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EvGenius Counter 3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the page parameter in (1) monthly.php and (2) daily.php.

    Published: 15 Jun 2006
    6.8
    Medium

    CVE-2006-3025

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3026

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery 5.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in gallery.asp and (2) parentcurrentpage parameter in view_gallery.asp.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3029

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3031

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.asp in fipsCMS 4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) w, (2) phcat, (3) dayid, and (4) calw parameters.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3033

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyScrapbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input box in singlepage.php when submitting scrapbook pages.

    Published: 15 Jun 2006
    2.6
    Low

    CVE-2006-3037

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ST AdManager Lite allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, (3) article, (4) bio, and (5) name parameters.

    Published: 15 Jun 2006
    2.6
    Low

    CVE-2006-3038

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed."

    Published: 15 Jun 2006
    2.6
    Low

    CVE-2006-3039

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed."

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3040

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in talkbox.php in Amr Talkbox allows remote attackers to execute arbitrary PHP code via a URL in the direct parameter. NOTE: this issue has been disputed by CVE, since the $direct variable is set to a static value just before the include statement

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3041

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Ltwcalendar/calendar.php in Codewalkers Ltwcalendar 4.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the ltw_config[include_dir] parameter. NOTE: CVE disputes this claim, since the $ltw_config[include_dir] variable is defined as a static value in an include file before it is referenced in an include() statement

    Published: 15 Jun 2006
    6.8
    Medium

    CVE-2006-3020

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate parameters.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3030

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping Cart 1.1.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ToCategory and (2) FromCategory parameters to (a) ProductDetailsForm.asp and (3) UserName and (4) Password parameters to (b) LogIn/VerifyUserLog.asp.

    Published: 15 Jun 2006
    6.5
    Medium

    CVE-2006-2197

    Last Modified: 16 Apr 2026

    Integer overflow in wv2 before 0.2.3 might allow context-dependent attackers to execute arbitrary code via a crafted Microsoft Word document.

    Published: 15 Jun 2006
    6.8
    Medium

    CVE-2006-3021

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar i-Gallery 4.1 PLUS and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) n and (2) d parameters in (a) login.asp and the d parameter in (b) igallery.asp.

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3028

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3032

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.

    Published: 15 Jun 2006
    5
    Medium

    CVE-2006-3034

    Last Modified: 16 Apr 2026

    MyScrapbook 3.1 allows remote attackers to obtain sensitive information via a direct request to files in the txt-db-api directory such as txt-db-api/sql.php, which reveals the path in an error message.

    Published: 15 Jun 2006
    5.8
    Medium

    CVE-2006-3035

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in addwords.php in MyScrapbook 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) comment parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 15 Jun 2006
    5.8
    Medium

    CVE-2006-3036

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3042

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher "reviewed the installation tarball that is not identical with the resulting system after installtion. The file, where the $go_info array is declared ... is created by the installer.

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3019

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.

    Published: 15 Jun 2006
    4.3
    Medium

    CVE-2006-3023

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp in Uapplication Uphotogallery 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) block parameters.

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3027

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp.

    Published: 15 Jun 2006
    7.5
    High

    CVE-2006-3018

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption.

    Published: 14 Jun 2006
    7.1
    High

    CVE-2006-3015

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.

    Published: 14 Jun 2006
    4
    Medium

    CVE-2006-2449

    Last Modified: 16 Apr 2026

    KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.

    Published: 14 Jun 2006
    9.3
    Critical

    CVE-2006-3017

    Last Modified: 16 Apr 2026

    zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x before 5.1.3 can cause zend_hash_del to delete the wrong element, which prevents a variable from being unset even when the PHP unset function is called, which might cause the variable's value to be used in security-relevant operations.

    Published: 14 Jun 2006
    4
    Medium

    CVE-2006-3081

    Last Modified: 16 Apr 2026

    mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.

    Published: 14 Jun 2006
    5.8
    Medium

    CVE-2006-3009

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-3010

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to execute arbitrary SQL commands via the (1) new_order and (2) order_dir parameters to (a) index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php, and the (3) entity and (4) tf_dateafter parameter to company/company_index.php.

    Published: 13 Jun 2006
    9.3
    Critical

    CVE-2006-0025

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.

    Published: 13 Jun 2006
    10
    Critical

    CVE-2006-2373

    Last Modified: 16 Apr 2026

    The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."

    Published: 13 Jun 2006
    4.3
    Medium

    CVE-2006-2380

    Last Modified: 16 Apr 2026

    Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."

    Published: 13 Jun 2006
    9.3
    Critical

    CVE-2006-2383

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.

    Published: 13 Jun 2006
    2.6
    Low

    CVE-2006-1193

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."

    Published: 13 Jun 2006
    5.5
    Medium

    CVE-2006-2374

    Last Modified: 16 Apr 2026

    The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."

    Published: 13 Jun 2006
    7.6
    High

    CVE-2006-2385

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.

    Published: 13 Jun 2006
    7.6
    High

    CVE-2006-0022

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.

    Published: 13 Jun 2006
    9.3
    Critical

    CVE-2006-1303

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.

    Published: 13 Jun 2006
    6.8
    Medium

    CVE-2006-1313

    Last Modified: 16 Apr 2026

    Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.

    Published: 13 Jun 2006
    7.5
    High

    CVE-2006-2371

    Last Modified: 16 Apr 2026

    Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."

    Published: 13 Jun 2006
    6.8
    Medium

    CVE-2006-2378

    Last Modified: 16 Apr 2026

    Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.

    Published: 13 Jun 2006
    9.3
    Critical

    CVE-2006-2379

    Last Modified: 16 Apr 2026

    Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.

    Published: 13 Jun 2006