CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2006-2444

    Last Modified: 16 Apr 2026

    The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.

    Published: 20 May 2006
    6.4
    Medium

    CVE-2006-2483

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-2487

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[main_path] parameter in (1) functions.php, (2) template.php, (3) news.php, (4) help.php, (5) mail.php, (6) Admin/admin_cats.php, (8) Admin/admin_edit.php, (9) Admin/admin_import.php, and (10) Admin/admin_templates.php. NOTE: this might be resultant from a variable overwrite issue.

    Published: 19 May 2006
    4.3
    Medium

    CVE-2006-2488

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS (WOS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) del_folder, (2) nick, or (3) action parameters to (a) notes/index.php, (4) curr parameter to (b) ipod/get_ipod.php, and in (c) login.php.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-2489

    Last Modified: 16 Apr 2026

    Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x before 2.3.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a content length (Content-Length) HTTP header. NOTE: this is a different vulnerability than CVE-2006-2162.

    Published: 19 May 2006
    4.3
    Medium

    CVE-2006-2490

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.

    Published: 19 May 2006
    4.3
    Medium

    CVE-2006-2484

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.html in IceWarp WebMail 5.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-2485

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter.

    Published: 19 May 2006
    6.4
    Medium

    CVE-2006-2486

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in find.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary SQL commands via the userID parameter.

    Published: 19 May 2006
    6.8
    Medium

    CVE-2006-2491

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.

    Published: 19 May 2006
    2.6
    Low

    CVE-2006-2312

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-0059

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-2474

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary SQL commands via the artnum parameter.

    Published: 19 May 2006
    7.8
    High

    CVE-2006-2475

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2479

    Last Modified: 16 Apr 2026

    The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2476

    Last Modified: 16 Apr 2026

    Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.

    Published: 19 May 2006
    4.3
    Medium

    CVE-2006-2473

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites.

    Published: 19 May 2006
    4.9
    Medium

    CVE-2006-2477

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2478

    Last Modified: 16 Apr 2026

    Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has been referred to as "cross-site scripting," but that is inconsistent with the common use of the term.

    Published: 19 May 2006
    6.4
    Medium

    CVE-2006-2459

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2463

    Last Modified: 16 Apr 2026

    view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter.

    Published: 19 May 2006
    4.6
    Medium

    CVE-2006-2464

    Last Modified: 16 Apr 2026

    stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrator password to stdout when executed, which allows local users to obtain the password by viewing a local display.

    Published: 19 May 2006
    5.1
    Medium

    CVE-2006-2465

    Last Modified: 16 Apr 2026

    Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if mp3info is not installed setuid or setgid in any reasonable context, then this issue might not be a vulnerability.

    Published: 19 May 2006
    2.6
    Low

    CVE-2006-2466

    Last Modified: 16 Apr 2026

    BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability."

    Published: 19 May 2006
    4
    Medium

    CVE-2006-2467

    Last Modified: 16 Apr 2026

    BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 displays the internal IP address of the WebLogic server in the WebLogic Server Administration Console, which allows remote authenticated administrators to determine the address.

    Published: 19 May 2006
    4.9
    Medium

    CVE-2006-2472

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2461

    Last Modified: 16 Apr 2026

    BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2471

    Last Modified: 16 Apr 2026

    Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers, including (1) DNS and IP addresses to address to T3 clients, (2) internal sensitive information using GetIORServlet, (3) certain "server details" in exceptions when invalid XML is provided, and (4) a stack trace in a SOAP fault.

    Published: 19 May 2006
    5
    Medium

    CVE-2006-2462

    Last Modified: 16 Apr 2026

    BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potentially sensitive network traffic.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-2469

    Last Modified: 16 Apr 2026

    The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges.

    Published: 19 May 2006
    7.5
    High

    CVE-2006-2470

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies.

    Published: 19 May 2006
    6.4
    Medium

    CVE-2006-2460

    Last Modified: 16 Apr 2026

    Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.

    Published: 19 May 2006
    4
    Medium

    CVE-2006-2468

    Last Modified: 16 Apr 2026

    The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain name in the Console login form, which allows remote attackers to obtain sensitive information.

    Published: 19 May 2006
    9
    Critical

    CVE-2006-1857

    Last Modified: 16 Apr 2026

    Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed HB-ACK chunk.

    Published: 19 May 2006
    7.8
    High

    CVE-2006-1858

    Last Modified: 16 Apr 2026

    SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.

    Published: 19 May 2006
    4
    Medium

    CVE-2006-2458

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).

    Published: 18 May 2006
    4.6
    Medium

    CVE-2006-2443

    Last Modified: 16 Apr 2026

    The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database.

    Published: 18 May 2006
    5
    Medium

    CVE-2006-2441

    Last Modified: 16 Apr 2026

    Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create a new game.

    Published: 18 May 2006
    4.6
    Medium

    CVE-2006-2442

    Last Modified: 16 Apr 2026

    kphone 4.2 creates .qt/kphonerc with world-readable permissions, which allows local users to read usernames and SIP passwords.

    Published: 18 May 2006
    2.1
    Low

    CVE-2006-1855

    Last Modified: 16 Apr 2026

    choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process.

    Published: 18 May 2006
    4.9
    Medium

    CVE-2006-1862

    Last Modified: 16 Apr 2026

    The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load.

    Published: 18 May 2006
    7.8
    High

    CVE-2006-1953

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Caucho Resin 3.0.17 and 3.0.18 for Windows allows remote attackers to read arbitrary files via a "C:%5C" (encoded drive letter) in a URL.

    Published: 17 May 2006
    5
    Medium

    CVE-2006-2422

    Last Modified: 16 Apr 2026

    phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, which allows remote authenticated users to read messages for other users by adding the sender's e-mail address as an "additional contact".

    Published: 17 May 2006
    4.3
    Medium

    CVE-2006-2423

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter.

    Published: 17 May 2006
    5.1
    Medium

    CVE-2006-2424

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php.

    Published: 17 May 2006
    7.5
    High

    CVE-2006-2428

    Last Modified: 16 Apr 2026

    add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague.

    Published: 17 May 2006
    10
    Critical

    CVE-2006-2429

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers".

    Published: 17 May 2006
    4.3
    Medium

    CVE-2006-2431

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.

    Published: 17 May 2006
    7.5
    High

    CVE-2006-2436

    Last Modified: 16 Apr 2026

    WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.

    Published: 17 May 2006
    5
    Medium

    CVE-2006-2437

    Last Modified: 16 Apr 2026

    The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.

    Published: 17 May 2006