CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2006-2434

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.

    Published: 17 May 2006
    10
    Critical

    CVE-2006-2433

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".

    Published: 17 May 2006
    7.2
    High

    CVE-2006-2427

    Last Modified: 16 Apr 2026

    freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file.

    Published: 17 May 2006
    10
    Critical

    CVE-2006-2430

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges.

    Published: 17 May 2006
    7.5
    High

    CVE-2006-2432

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.

    Published: 17 May 2006
    7.5
    High

    CVE-2006-2421

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows remote attackers to execute arbitrary code via long SSH_MSG_KEXINIT messages, which may cause an overflow when being logged. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 May 2006
    4.3
    Medium

    CVE-2006-2425

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields.

    Published: 17 May 2006
    6.4
    Medium

    CVE-2006-2435

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."

    Published: 17 May 2006
    5
    Medium

    CVE-2006-2438

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter. NOTE: this issue can produce resultant path disclosure when the parameter is invalid.

    Published: 17 May 2006
    5
    Medium

    CVE-2006-2413

    Last Modified: 16 Apr 2026

    GNUnet before SVN revision 2781 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an empty UDP datagram, possibly involving FIONREAD errors.

    Published: 16 May 2006
    6.8
    Medium

    CVE-2006-2405

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to unb_lib/abbc.css.php.

    Published: 16 May 2006
    4.6
    Medium

    CVE-2006-2409

    Last Modified: 16 Apr 2026

    Format string vulnerability in the raydium_log function in console.c in Raydium before SVN revision 310 allows local users to execute arbitrary code via format string specifiers in the format parameter, which are not properly handled in a call to raydium_console_line_add.

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2410

    Last Modified: 16 Apr 2026

    raydium_network_netcall_exec function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a packet of type 0xFF, which causes a null dereference.

    Published: 16 May 2006
    6.8
    Medium

    CVE-2006-2418

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in certain versions of phpMyAdmin before 2.8.0.4 allow remote attackers to inject arbitrary web script or HTML via the db parameter in unknown scripts.

    Published: 16 May 2006
    2.6
    Low

    CVE-2006-2406

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter.

    Published: 16 May 2006
    7.5
    High

    CVE-2006-2407

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.

    Published: 16 May 2006
    7.5
    High

    CVE-2006-2411

    Last Modified: 16 Apr 2026

    Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary code by sending packets with long global variables to the client.

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2412

    Last Modified: 16 Apr 2026

    The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a large ID, which causes an invalid memory access (buffer over-read).

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2414

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows remote attackers to list files and directories under the mbox parent directory and obtain mailbox names via ".." sequences in the (1) LIST or (2) DELETE IMAP command.

    Published: 16 May 2006
    4.3
    Medium

    CVE-2006-2419

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Directory Listing Script allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Published: 16 May 2006
    4.3
    Medium

    CVE-2006-2420

    Last Modified: 16 Apr 2026

    Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows remote attackers to conduct cross-site scripting (XSS) attacks via a title element with HTML encoded sequences such as ">", which are automatically decoded by some RSS readers. NOTE: this issue is not in Bugzilla itself, but rather due to design or documentation inconsistencies within RSS, or implementation vulnerabilities in RSS readers. While this issue normally would not be included in CVE, it is being identified since the Bugzilla developers have addressed it.

    Published: 16 May 2006
    7.5
    High

    CVE-2006-2408

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Raydium before SVN revision 310 allow remote attackers to execute arbitrary code via a large packet when logged via (1) the raydium_log function in log.c or (2) the raydium_console_line_add function in console.c, possibly from a long player name.

    Published: 16 May 2006
    5.8
    Medium

    CVE-2006-2415

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) CFTOKEN parameter in (a) index.cfm and (3) CFTOKEN and (4) CFID parameter in (b) chat.cfm.

    Published: 16 May 2006
    5.1
    Medium

    CVE-2006-2416

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in class2.php in e107 0.7.2 and earlier allows remote attackers to execute arbitrary SQL commands via a cookie as defined in $pref['cookie_name'].

    Published: 16 May 2006
    4.3
    Medium

    CVE-2006-2417

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before 2.8.0.4 allows remote attackers to inject arbitrary web script or HTML via the theme parameter in unknown scripts. NOTE: the lang parameter is already covered by CVE-2006-2031.

    Published: 16 May 2006
    5.8
    Medium

    CVE-2006-2390

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality.

    Published: 16 May 2006
    7.5
    High

    CVE-2006-2391

    Last Modified: 16 Apr 2026

    Buffer overflow in EMC Retrospect Client 5.1 through 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet to port 497.

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2398

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rep parameter.

    Published: 16 May 2006
    7.5
    High

    CVE-2006-2403

    Last Modified: 16 Apr 2026

    Buffer overflow in FileZilla before 2.2.23 allows remote attackers to execute arbitrary commands via unknown attack vectors.

    Published: 16 May 2006
    6.4
    Medium

    CVE-2006-2404

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in popup.php in RadScripts RadLance Gold 7.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2402

    Last Modified: 16 Apr 2026

    Buffer overflow in the changeRegistration function in servernet.cpp for Outgun 1.0.3 bot 2 and earlier allows remote attackers to change the registration information of other players via a long string.

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2395

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has notified CVE that "PopPhoto is NOT a product of Pixaria. It was a product of PopSoft Digital and is only hosted by Pixaria as a courtesy... The vulnerability listed was patched by the previous vendor and all previous users have received this update."

    Published: 16 May 2006
    5.8
    Medium

    CVE-2006-2396

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter.

    Published: 16 May 2006
    5.8
    Medium

    CVE-2006-2397

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal.

    Published: 16 May 2006
    7.5
    High

    CVE-2006-2399

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the ServerNetworking::incoming_client_data function in servnet.cpp in Outgun 1.0.3 bot 2 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a data_file_request command with a long (1) type or (2) name string.

    Published: 16 May 2006
    7.8
    High

    CVE-2006-2401

    Last Modified: 16 Apr 2026

    The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (application crash) via packets with incorrect message sizes, which triggers a buffer over-read.

    Published: 16 May 2006
    6.4
    Medium

    CVE-2006-2392

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.

    Published: 16 May 2006
    5
    Medium

    CVE-2006-2393

    Last Modified: 16 Apr 2026

    The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.

    Published: 16 May 2006
    5.8
    Medium

    CVE-2006-2394

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in chat.php in PHP Live Helper allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.

    Published: 16 May 2006
    7.8
    High

    CVE-2006-2400

    Last Modified: 16 Apr 2026

    The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (game interruption) via large packets, which cause an exception to be thrown.

    Published: 16 May 2006
    4.7
    Medium

    CVE-2006-0039

    Last Modified: 16 Apr 2026

    Race condition in the do_add_counters function in netfilter for Linux kernel 2.6.16 allows local users with CAP_NET_ADMIN capabilities to read kernel memory by triggering the race condition in a way that produces a size value that is inconsistent with allocated memory, which leads to a buffer over-read in IPT_ENTRY_ITERATE.

    Published: 16 May 2006
    4.3
    Medium

    CVE-2006-2359

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.

    Published: 15 May 2006
    5.8
    Medium

    CVE-2006-2365

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 15 May 2006
    2.6
    Low

    CVE-2006-2366

    Last Modified: 16 Apr 2026

    ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r option, does not prompt the user when overwriting files, which allows user-assisted remote attackers to overwrite dangerous files via an arbitrary destination file name in an OBEX File Transfer session.

    Published: 15 May 2006
    4.3
    Medium

    CVE-2006-2367

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the func parameter in a search function.

    Published: 15 May 2006
    5.1
    Medium

    CVE-2006-2363

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 15 May 2006
    7.5
    High

    CVE-2006-2361

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Published: 15 May 2006
    7.3
    High

    CVE-2006-2362

    Last Modified: 16 Apr 2026

    Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

    Published: 15 May 2006
    5.8
    Medium

    CVE-2006-2364

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which is not sanitized before being presented in an error message.

    Published: 15 May 2006
    7.5
    High

    CVE-2006-2369

    Last Modified: 16 Apr 2026

    RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

    Published: 15 May 2006