CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2006-1991

    Last Modified: 16 Apr 2026

    The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1951

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1952

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request.

    Published: 24 Apr 2006
    10
    Critical

    CVE-2006-1932

    Last Modified: 16 Apr 2026

    Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1933

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (large or infinite loops) viarafted packets to the (1) UMA and (2) BER dissectors.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1937

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1938

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1939

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Ethereal 0.9.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) an invalid display filter, or the (2) GSM SMS, (3) ASN.1-based, (4) DCERPC NT, (5) PER, (6) RPC, (7) DCERPC, and (8) ASN.1 dissectors.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1940

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Ethereal 0.10.4 up to 0.10.14 allows remote attackers to cause a denial of service (abort) via the SNDCP dissector.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1935

    Last Modified: 16 Apr 2026

    Buffer overflow in Ethereal 0.9.15 up to 0.10.14 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the COPS dissector.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1934

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) ALCAP dissector, (2) Network Instruments file code, or (3) NetXray/Windows Sniffer file code.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1936

    Last Modified: 16 Apr 2026

    Buffer overflow in Ethereal 0.8.5 up to 0.10.14 allows remote attackers to execute arbitrary code via the telnet dissector.

    Published: 24 Apr 2006
    5
    Medium

    CVE-2006-1990

    Last Modified: 16 Apr 2026

    Integer overflow in the wordwrap function in string.c in PHP 4.4.2 and 5.1.2 might allow context-dependent attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, which triggers a heap-based buffer overflow in a memcpy function call, a different vulnerability than CVE-2002-1396.

    Published: 24 Apr 2006
    9.3
    Critical

    CVE-2009-1577

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.

    Published: 22 Apr 2006
    7.5
    High

    CVE-2006-2083

    Last Modified: 16 Apr 2026

    Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.

    Published: 22 Apr 2006
    7.5
    High

    CVE-2006-1865

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing.

    Published: 21 Apr 2006
    5.8
    Medium

    CVE-2006-1977

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in FlexBB 0.5.7 BETA and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) message parameters.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1978

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.

    Published: 21 Apr 2006
    5.8
    Medium

    CVE-2006-1979

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.

    Published: 21 Apr 2006
    2.6
    Low

    CVE-2006-1980

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1986

    Last Modified: 16 Apr 2026

    Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1987

    Last Modified: 16 Apr 2026

    Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1988

    Last Modified: 16 Apr 2026

    The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.

    Published: 21 Apr 2006
    5.1
    Medium

    CVE-2006-1985

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1984

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image that triggers a null dereference.

    Published: 21 Apr 2006
    2.1
    Low

    CVE-2006-1981

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1982

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.

    Published: 21 Apr 2006
    6.4
    Medium

    CVE-2006-1983

    Last Modified: 16 Apr 2026

    Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1954

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1955

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1956

    Last Modified: 16 Apr 2026

    The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1962

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PCPIN Chat 5.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (login parameter) to main.php.

    Published: 21 Apr 2006
    5.5
    Medium

    CVE-2006-1963

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in main.php in PCPIN Chat 5.0.4 and earlier allows remote authenticated users to include and execute arbitrary PHP code via a ".." (dot dot) in a language cookie, as demonstrated by uploading then accessing a smiliefile image that actually contains PHP code.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1964

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Haberler.asp in ASPSitem 1.83 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Apr 2006
    2.6
    Low

    CVE-2006-1969

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 21 Apr 2006
    4.3
    Medium

    CVE-2006-1970

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

    Published: 21 Apr 2006
    4.3
    Medium

    CVE-2006-1971

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 21 Apr 2006
    4.3
    Medium

    CVE-2006-1972

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1973

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Linksys RT31P2 VoIP router allow remote attackers to cause a denial of service via malformed Session Initiation Protocol (SIP) messages.

    Published: 21 Apr 2006
    5.8
    Medium

    CVE-2006-1968

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.

    Published: 21 Apr 2006
    2.6
    Low

    CVE-2006-1976

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.

    Published: 21 Apr 2006
    5
    Medium

    CVE-2006-1957

    Last Modified: 16 Apr 2026

    The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with different values of the feed parameter.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1959

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1974

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.

    Published: 21 Apr 2006
    5.8
    Medium

    CVE-2006-1960

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.

    Published: 21 Apr 2006
    5.8
    Medium

    CVE-2006-1965

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.

    Published: 21 Apr 2006
    2.6
    Low

    CVE-2006-1967

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.

    Published: 21 Apr 2006
    2.6
    Low

    CVE-2006-1975

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestbook_newentry.php in PHP-Gastebuch 1.61 allows remote attackers to inject arbitrary web script or HTML via the Kommentar field.

    Published: 21 Apr 2006
    6.4
    Medium

    CVE-2006-1958

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php.

    Published: 21 Apr 2006
    7.5
    High

    CVE-2006-1961

    Last Modified: 16 Apr 2026

    Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell access via shell metacharacters in arguments to the "show" command in the application's command line interface (CLI), aka bug ID CSCsd21502 (WLSE), CSCsd22861 (URT), and CSCsd22859 (HSE). NOTE: other issues might be addressed by the Cisco advisory.

    Published: 21 Apr 2006