CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2006-1412

    Last Modified: 16 Apr 2026

    TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.

    Published: 28 Mar 2006
    7.5
    High

    CVE-2006-1402

    Last Modified: 16 Apr 2026

    Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute arbitrary code via a long string sent when joining a match or a long chat message to the SV_BroadcastPrintf function.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1400

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyTasks/PersonalTaskEdit.asp in Metisware Instructor 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Task parameter.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1409

    Last Modified: 16 Apr 2026

    Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1410

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1411

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1398

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestbook.php in G-Book 1.0 allows remote attackers to inject arbitrary web script or HTML via the g_message parameter.

    Published: 28 Mar 2006
    5.8
    Medium

    CVE-2006-1405

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.aspx in SweetSuite.NET Content Management System (ssCMS) 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Published: 28 Mar 2006
    4.3
    Medium

    CVE-2006-1397

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form.

    Published: 28 Mar 2006
    5
    Medium

    CVE-2006-1490

    Last Modified: 16 Apr 2026

    PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

    Published: 28 Mar 2006
    7.1
    High

    CVE-2006-0991

    Last Modified: 16 Apr 2026

    Buffer overflow in the NetBackup Sharepoint Services server daemon (bpspsserver) on NetBackup 6.0 for Windows allows remote attackers to execute arbitrary code via crafted "Request Service" packets to the vnetd service (TCP port 13724).

    Published: 28 Mar 2006
    9
    Critical

    CVE-2006-0990

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the NetBackup Catalog daemon (bpdbm) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.

    Published: 28 Mar 2006
    9
    Critical

    CVE-2006-0989

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the volume manager daemon (vmd) in Veritas NetBackup Enterprise Server 5.0 through 6.0 and DataCenter and BusinesServer 4.5FP and 4.5MP allows attackers to execute arbitrary code via unknown vectors.

    Published: 28 Mar 2006
    1.2
    Low

    CVE-2006-1066

    Last Modified: 16 Apr 2026

    Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.

    Published: 27 Mar 2006
    4.3
    Medium

    CVE-2006-1393

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the mod_pubcookie Apache application server module in University of Washington Pubcookie 1.x, 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.

    Published: 26 Mar 2006
    4.3
    Medium

    CVE-2006-1392

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified inputs.

    Published: 26 Mar 2006
    4.3
    Medium

    CVE-2006-1396

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 26 Mar 2006
    7.5
    High

    CVE-2006-1395

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 26 Mar 2006
    4.3
    Medium

    CVE-2006-1394

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.

    Published: 26 Mar 2006
    4
    Medium

    CVE-2006-1387

    Last Modified: 16 Apr 2026

    TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself.

    Published: 26 Mar 2006
    7.5
    High

    CVE-2006-1386

    Last Modified: 16 Apr 2026

    The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics.

    Published: 26 Mar 2006
    5
    Medium

    CVE-2006-1391

    Last Modified: 16 Apr 2026

    The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.

    Published: 25 Mar 2006
    4.3
    Medium

    CVE-2007-5378

    Last Modified: 23 Apr 2026

    Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.

    Published: 25 Mar 2006
    4.6
    Medium

    CVE-2006-1390

    Last Modified: 16 Apr 2026

    The configuration of NetHack 3.4.3-r1 and earlier, Falcon's Eye 1.9.4a and earlier, and Slash'EM 0.0.760 and earlier on Gentoo Linux allows local users in the games group to modify saved games files to execute arbitrary code via buffer overflows and overwrite arbitrary files via symlink attacks.

    Published: 25 Mar 2006
    7.8
    High

    CVE-2006-1389

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 25 Mar 2006
    7.5
    High

    CVE-2006-1388

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.

    Published: 24 Mar 2006
    4
    Medium

    CVE-2006-1383

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not.

    Published: 24 Mar 2006
    4.3
    Medium

    CVE-2006-1384

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in apwc_win_main.jsp in the web console in IBM Tivoli Business Systems Manager (TBSM) before 3.1.0.1 allows remote attackers to inject arbitrary web script or HTML via the skin parameter.

    Published: 24 Mar 2006
    5.1
    Medium

    CVE-2006-1385

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.

    Published: 24 Mar 2006
    5
    Medium

    CVE-2006-0816

    Last Modified: 16 Apr 2026

    Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL.

    Published: 24 Mar 2006
    7.2
    High

    CVE-2006-1379

    Last Modified: 16 Apr 2026

    Trend Micro PC-cillin Internet Security 2006 14.00.1485 and 14.10.0.1023, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying executable programs such as (1) tmntsrv.exe and (2) tmproxy.exe.

    Published: 24 Mar 2006
    7.2
    High

    CVE-2006-1380

    Last Modified: 16 Apr 2026

    ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.

    Published: 24 Mar 2006
    10
    Critical

    CVE-2006-1381

    Last Modified: 16 Apr 2026

    Trend Micro OfficeScan 5.5, and probably other versions before 6.5, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying tmlisten.exe.

    Published: 24 Mar 2006
    7.5
    High

    CVE-2006-1382

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath parameter.

    Published: 24 Mar 2006
    4.9
    Medium

    CVE-2006-1378

    Last Modified: 16 Apr 2026

    PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack.

    Published: 24 Mar 2006
    4.3
    Medium

    CVE-2006-1377

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.

    Published: 24 Mar 2006
    2.1
    Low

    CVE-2006-1376

    Last Modified: 16 Apr 2026

    The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service (disk consumption).

    Published: 24 Mar 2006
    5
    Medium

    CVE-2006-1375

    Last Modified: 16 Apr 2026

    AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php.

    Published: 24 Mar 2006
    7.5
    High

    CVE-2006-1374

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter.

    Published: 24 Mar 2006
    4.3
    Medium

    CVE-2006-1373

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter.

    Published: 24 Mar 2006
    5
    Medium

    CVE-2006-1372

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in 1WebCalendar 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) EventID parameter in viewEvent.cfm, (2) NewsID parameter in newsView.cfm, or (3) ThisDate parameter in mainCal.cfm.

    Published: 24 Mar 2006
    6.8
    Medium

    CVE-2006-1369

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances.

    Published: 23 Mar 2006
    10
    Critical

    CVE-2006-1368

    Last Modified: 16 Apr 2026

    Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (kmalloc'd memory corruption) via a remote NDIS response to OID_GEN_SUPPORTED_LIST, which causes memory to be allocated for the reply data but not the reply structure.

    Published: 23 Mar 2006
    6.8
    Medium

    CVE-2006-1367

    Last Modified: 16 Apr 2026

    The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and view phonebook entries and saved SMS messages by connecting on Bluetooth channel 3 and tricking the user into pressing Grant, aka a "Blueline" attack. NOTE: while user-assisted, the attack is made more feasible because of a GUI misrepresentation issue that allows a default message to be replaced by an attacker-specified one.

    Published: 23 Mar 2006
    7.8
    High

    CVE-2006-1366

    Last Modified: 16 Apr 2026

    Buffer overflow in the Motorola PEBL U6 08.83.76R, and possibly other Motorola P2K-based phones, allows remote attackers to cause a denial of service (device shutdown), and possibly execute arbitrary code, via a long OBEX setpath to the OBEX File Transfer (aka FTP) service on Bluetooth channel 9.

    Published: 23 Mar 2006
    9.3
    Critical

    CVE-2006-1370

    Last Modified: 16 Apr 2026

    Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.

    Published: 23 Mar 2006
    9
    Critical

    CVE-2006-1371

    Last Modified: 16 Apr 2026

    Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea FileManager plugin to upload and execute arbitrary PHP files using (1) manager.php, (2) standalonemanager.php, and (3) images.php.

    Published: 23 Mar 2006
    5
    Medium

    CVE-2006-1365

    Last Modified: 16 Apr 2026

    The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the target device, by initiating and interrupting an OBEX Push Profile that pretends to send a vCard, aka a "HeloMoto" attack.

    Published: 23 Mar 2006
    7.2
    High

    CVE-2006-1283

    Last Modified: 16 Apr 2026

    opiepasswd in One-Time Passwords in Everything (OPIE) in FreeBSD 4.10-RELEASE-p22 through 6.1-STABLE before 20060322 uses the getlogin function to determine the invoking user account, which might allow local users to configure OPIE access to the root account and possibly gain root privileges if a root shell is permitted by the configuration of the wheel group or sshd.

    Published: 23 Mar 2006
    7.5
    High

    CVE-2006-1364

    Last Modified: 16 Apr 2026

    Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.

    Published: 23 Mar 2006