CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2006-1568

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) email, (2) location, or (3) website parameters.

    Published: 1 Apr 2006
    5.8
    Medium

    CVE-2006-1574

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 1 Apr 2006
    5.1
    Medium

    CVE-2006-1553

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in functions/final_functions.php in VSNS Lemon 3.2.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Mar 2006
    2.6
    Low

    CVE-2006-1554

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.

    Published: 31 Mar 2006
    7.5
    High

    CVE-2006-1555

    Last Modified: 16 Apr 2026

    VSNS Lemon 3.2.0 allows remote attackers to bypass authentication and access password-protected articles by setting the vsns[topic_id] cookie to the targeted topic.

    Published: 31 Mar 2006
    6.8
    Medium

    CVE-2006-1556

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) CatName, (2) CaricatierID, or (3) CatID parameter.

    Published: 31 Mar 2006
    7.5
    High

    CVE-2006-1557

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.

    Published: 31 Mar 2006
    6.8
    Medium

    CVE-2006-1558

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHP Script Index allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 31 Mar 2006
    5
    Medium

    CVE-2006-1552

    Last Modified: 16 Apr 2026

    Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".

    Published: 31 Mar 2006
    6.8
    Medium

    CVE-2006-1562

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) autor, (2) www, (3) temat, and (4) tresc parameters.

    Published: 31 Mar 2006
    4.6
    Medium

    CVE-2006-1564

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so modules, which might allow local users to gain privileges by installing malicious libraries in that directory.

    Published: 31 Mar 2006
    4.6
    Medium

    CVE-2006-1565

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.

    Published: 31 Mar 2006
    7.5
    High

    CVE-2006-1560

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts. NOTE: portions of the description details are obtained from third party information.

    Published: 31 Mar 2006
    5.1
    Medium

    CVE-2006-1561

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote attackers to execute arbitrary SQL commands via the x parameter.

    Published: 31 Mar 2006
    7.5
    High

    CVE-2006-1559

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in PHP Script Index allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Mar 2006
    7.6
    High

    CVE-2006-1563

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in config.php in vscripts (aka Kuba Kunkiewicz) [V]Book (aka VBook) 2.0 allows remote administrators to execute arbitrary PHP code into the config file, which is included other [V]Book scripts.

    Published: 31 Mar 2006
    4.6
    Medium

    CVE-2006-1566

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to gain privileges by installing malicious libraries in that directory.

    Published: 31 Mar 2006
    5.5
    Medium

    CVE-2006-7254

    Last Modified: 21 Nov 2024

    The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon.

    Published: 31 Mar 2006
    1.2
    Low

    CVE-2006-1059

    Last Modified: 16 Apr 2026

    The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1533

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1534

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-1535

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1536

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.

    Published: 30 Mar 2006
    7.8
    High

    CVE-2006-1541

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Default.asp in EzASPSite 2.0 RC3 and earlier allows remote attackers to execute arbitrary SQL commands and obtain the SHA1 hash of the admin password via the Scheme parameter.

    Published: 30 Mar 2006
    4.9
    Medium

    CVE-2006-1538

    Last Modified: 16 Apr 2026

    The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-1532

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.

    Published: 30 Mar 2006
    5
    Medium

    CVE-2006-1537

    Last Modified: 16 Apr 2026

    Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1539

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd.

    Published: 30 Mar 2006
    9.3
    Critical

    CVE-2006-1540

    Last Modified: 16 Apr 2026

    MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1543

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-1544

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.

    Published: 30 Mar 2006
    9
    Critical

    CVE-2006-1545

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.

    Published: 30 Mar 2006
    4
    Medium

    CVE-2006-1510

    Last Modified: 16 Apr 2026

    Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.

    Published: 30 Mar 2006
    4.9
    Medium

    CVE-2006-1509

    Last Modified: 16 Apr 2026

    /sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.

    Published: 30 Mar 2006
    5.1
    Medium

    CVE-2006-1503

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_install.php in Virtual War (VWar) 1.5.0 R11 and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the vwar_root parameter. NOTE: this is a different vulnerability than CVE-2006-1636.

    Published: 30 Mar 2006
    6.8
    Medium

    CVE-2006-1507

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHPKIT 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the error parameter to include.php, possibly due to a problem in login/login.php.

    Published: 30 Mar 2006
    5.1
    Medium

    CVE-2006-1511

    Last Modified: 16 Apr 2026

    Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.

    Published: 30 Mar 2006
    5.1
    Medium

    CVE-2006-1504

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-1508

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.

    Published: 30 Mar 2006
    5
    Medium

    CVE-2006-1505

    Last Modified: 16 Apr 2026

    base_maintenance.php in Basic Analysis and Security Engine (BASE) before 1.2.4 (melissa), when running in standalone mode, allows remote attackers to bypass authentication, possibly by setting the standalone parameter to "yes".

    Published: 30 Mar 2006
    7.2
    High

    CVE-2006-1506

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1495

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

    Published: 30 Mar 2006
    5
    Medium

    CVE-2006-1497

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1501

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-0996

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1499

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable).

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-1496

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.

    Published: 30 Mar 2006
    7.5
    High

    CVE-2006-1500

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Tilde CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Mar 2006
    4.3
    Medium

    CVE-2006-1498

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links.

    Published: 30 Mar 2006
    5.1
    Medium

    CVE-2006-1502

    Last Modified: 16 Apr 2026

    Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an AVI file with a crafted wLongsPerEntry or nEntriesInUse value in the indx chunk, which is handled in aviheader.c.

    Published: 30 Mar 2006