CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-1875

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11. NOTE: Oracle has not disputed reliable researcher claims that this issue is SQL injection in MDSYS.SDO_LRS_TRIG_INS.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1867

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 9.2.0.6 has unknown impact and attack vectors in the Advanced Replication component, aka Vuln# DB02.

    Published: 20 Apr 2006
    9.7
    Critical

    CVE-2006-1866

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, and other versions have unknown impact and attack vectors in the (1) Advanced Replication component, as identified by Vuln# DB01, and (2) Oracle Spatial component, as identified by Vuln# DB10. NOTE: details are unavailable from Oracle, but as of 20060421, they have not publicly disputed a claim by a reliable independent researcher that states that DB01 is an unknown issue in the DBMS_REPUTIL package, and DB10 is SQL injection in the INSERT_CATALOG, UPDATE_CATALOG, and DELETE_CATALOG functions of the SDO_CATALOG package.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1905

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

    Published: 20 Apr 2006
    7.2
    High

    CVE-2006-1877

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, and 9.2.0.7 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB13.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1879

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Email Server component in Oracle Collaboration Suite 9.0.4.2, 10.1.1, 10.1.2.0, and 10.1.2.1 have unknown impact and attack vectors, aka Vuln# (1) OCS01, (2) OCS02, (3) OCS03, and (4) OCS04.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1880

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, as identified by Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS09 in the (b) Oracle Diagnostics Interfaces component; (3) APPS10 in the (c) Oracle General Ledger component; (4) APPS12 and (5) APPS13 in the (d) Oracle Receivables component.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1881

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Financials for Asia/Pacific component in Oracle E-Business Suite and Applications 11.5.9 has unknown impact and attack vectors. component, aka Vuln# APPS02.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1878

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1885

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manager 9.0.1.5 and 9.2.0.7 have unknown impact and attack vectors, aka Vuln# (1) EM01 and (2) EM02.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1887

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Security Server 8.95.J1 has unknown impact and attack vectors, aka Vuln# JDE01.

    Published: 20 Apr 2006
    5.8
    Medium

    CVE-2006-1889

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Search for" item (keyword parameter).

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1886

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka Vuln# PSE01.

    Published: 20 Apr 2006
    6.8
    Medium

    CVE-2006-1893

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 20 Apr 2006
    4.3
    Medium

    CVE-2006-1894

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfuscator reverses the transformation. NOTE: it is not clear whether this is a site-specific issue; however, the claimed codebase relationship with PunBB might be relevant.

    Published: 20 Apr 2006
    6.5
    Medium

    CVE-2006-1895

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in includes/template.php in phpBB allows remote authenticated users with write access to execute arbitrary PHP code by modifying a template in a way that (1) bypasses a loose ".*" regular expression to match BEGIN and END statements in overall_header.tpl, or (2) is used in an eval statement by includes/bbcode.php for bbcode.tpl.

    Published: 20 Apr 2006
    6
    Medium

    CVE-2006-1896

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1897

    Last Modified: 16 Apr 2026

    Webplus (aka talentsoft) Web+Shop 5.3.6, when Redirect URL for "Script Not Found" Error is not configured, allows remote attackers to obtain sensitive information via a quote (') or possibly other invalid value in the storeid parameter in store.wml in webplus.exe, which reveals the path in a "Script Not Found" error message.

    Published: 20 Apr 2006
    5
    Medium

    CVE-2006-1901

    Last Modified: 16 Apr 2026

    Mozilla Camino 1.0 and earlier allow remote attackers to cause a denial of service (null dereference and application crash or hang) via HTML with certain improperly nested elements. NOTE: this might be the same issue as CVE-2006-1724.

    Published: 20 Apr 2006
    2.1
    Low

    CVE-2006-1902

    Last Modified: 16 Apr 2026

    fold_binary in fold-const.c in GNU Compiler Collection (gcc) 4.1 improperly handles pointer overflow when folding a certain expr comparison to a corresponding offset comparison in cases other than EQ_EXPR and NE_EXPR, which might introduce buffer overflow vulnerabilities into applications that could be exploited by context-dependent attackers.NOTE: the vendor states that the essence of the issue is "not correctly interpreting an offset to a pointer as a signed value."

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1903

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila allow remote attackers to inject arbitrary web script or HTML (1) via the referer parameter in sendMail, and via attributes of (2) the A element and certain other HTML elements in web pages edited with the editInBrowser module. NOTE: the msgReader$1 mode attack vector is already covered by CVE-2006-1769.

    Published: 20 Apr 2006
    2.6
    Low

    CVE-2006-1904

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 20 Apr 2006
    9
    Critical

    CVE-2006-1873

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 9.2.0.7, 10.1.0.4, and 10.2.0.1 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB08.

    Published: 20 Apr 2006
    7.5
    High

    CVE-2006-1872

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors in the Oracle Enterprise Manager Intelligent Agent component, aka Vuln# DB07.

    Published: 20 Apr 2006
    6.5
    Medium

    CVE-2006-1871

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Oracle Database Server 9.2.0.7 and 10.1.0.5 allows remote attackers to execute arbitrary SQL commands via the DELETE_FROM_TABLE function in the DBMS_LOGMNR_SESSION (Log Miner) package, aka Vuln# DB06.

    Published: 20 Apr 2006
    10
    Critical

    CVE-2006-1869

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Oracle Database Server 8.1.7.4 and 9.0.1.5 has unknown impact and attack vectors in the Dictionary component, aka Vuln# DB04.

    Published: 20 Apr 2006
    2.1
    Low

    CVE-2006-1863

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864.

    Published: 20 Apr 2006
    3.6
    Low

    CVE-2006-1524

    Last Modified: 16 Apr 2026

    madvise_remove in Linux kernel 2.6.16 up to 2.6.16.6 does not follow file and mmap restrictions, which allows local users to bypass IPC permissions and replace portions of readonly tmpfs files with zeroes, aka the MADV_REMOVE vulnerability. NOTE: this description was originally written in a way that combined two separate issues. The mprotect issue now has a separate name, CVE-2006-2071.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1850

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level, (2) position, (3) id, and (4) action parameters to members_only/index.cgi, and the (5) page parameter to customer_area/index.cgi.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1842

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.

    Published: 19 Apr 2006
    5.1
    Medium

    CVE-2006-1834

    Last Modified: 16 Apr 2026

    Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check. NOTE: a sign extension problem makes the attack easier with shorter strings.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1833

    Last Modified: 16 Apr 2026

    Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the interface.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1854

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BluePay Manager 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML during a login action via the (1) Account Name and (2) Username field. NOTE: the vendor has disputed this vulnerability, saying that "it does not exist currently in the Bluepay 2.0 product," and older versions might not have been affected either. As of 20060512, CVE has not formally investigated this dispute

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1852

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.

    Published: 19 Apr 2006
    5
    Medium

    CVE-2006-1851

    Last Modified: 16 Apr 2026

    xFlow 5.46.11 and earlier allows remote attackers to determine the installation path of the application via the (1) action parameter to members_only/index.cgi and (2) page parameter customer_area/index.cgi, probably due to invalid values.

    Published: 19 Apr 2006
    2.1
    Low

    CVE-2006-1844

    Last Modified: 16 Apr 2026

    The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1843

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1837

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1831

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.

    Published: 19 Apr 2006
    5.1
    Medium

    CVE-2006-1828

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.

    Published: 19 Apr 2006
    6.8
    Medium

    CVE-2006-1836

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1835

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.

    Published: 19 Apr 2006
    3.3
    Low

    CVE-2006-1247

    Last Modified: 16 Apr 2026

    rm_mlcache_file in bos.rte.install in AIX 5.1.0 through 5.3.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 19 Apr 2006
    4
    Medium

    CVE-2006-1829

    Last Modified: 16 Apr 2026

    EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involving (1) connection caches, (2) open password prompts, and (3) stored custom connection profiles.

    Published: 19 Apr 2006
    3.7
    Low

    CVE-2006-1830

    Last Modified: 16 Apr 2026

    Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors.

    Published: 19 Apr 2006
    5
    Medium

    CVE-2006-1832

    Last Modified: 16 Apr 2026

    sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1838

    Last Modified: 16 Apr 2026

    edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.

    Published: 19 Apr 2006
    7.5
    High

    CVE-2006-1839

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.

    Published: 19 Apr 2006
    6.4
    Medium

    CVE-2006-1840

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.

    Published: 19 Apr 2006
    2.6
    Low

    CVE-2006-1841

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.

    Published: 19 Apr 2006