CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2006-1250

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Webmail module in Winmail before 4.3 has unknown impact and unknown remote attack vectors.

    Published: 19 Mar 2006
    10
    Critical

    CVE-2006-1254

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in BorderWare MXtreme 5.0 and 6.0 allows remote attackers to have an unknown impact via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Mar 2006
    4.3
    Medium

    CVE-2006-1258

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.

    Published: 19 Mar 2006
    5
    Medium

    CVE-2006-1251

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in greylistclean.cron in sa-exim 4.2 allows remote attackers to delete arbitrary files via an email with a To field that contains a filename separated by whitespace, which is not quoted when greylistclean.cron provides the argument to the rm command.

    Published: 19 Mar 2006
    4.6
    Medium

    CVE-2006-1248

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.

    Published: 17 Mar 2006
    7.2
    High

    CVE-2006-1246

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in mklvcopy in BOS.RTE.LVM in IBM AIX 5.3 allows local users to execute arbitrary commands when mklvcopy calls external commands, possibly due to an untrusted search path vulnerability.

    Published: 17 Mar 2006
    7.5
    High

    CVE-2006-1245

    Last Modified: 16 Apr 2026

    Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."

    Published: 17 Mar 2006
    2.6
    Low

    CVE-2006-1182

    Last Modified: 16 Apr 2026

    Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command.

    Published: 16 Mar 2006
    7.6
    High

    CVE-2006-1244

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.

    Published: 15 Mar 2006
    4.6
    Medium

    CVE-2006-1240

    Last Modified: 16 Apr 2026

    Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.

    Published: 15 Mar 2006
    7.5
    High

    CVE-2006-1243

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.

    Published: 15 Mar 2006
    4.6
    Medium

    CVE-2006-1241

    Last Modified: 16 Apr 2026

    Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.

    Published: 15 Mar 2006
    7.5
    High

    CVE-2006-1237

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.

    Published: 15 Mar 2006
    5.1
    Medium

    CVE-2006-1238

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

    Published: 15 Mar 2006
    4.3
    Medium

    CVE-2006-1239

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Mar 2006
    5.1
    Medium

    CVE-2006-0009

    Last Modified: 16 Apr 2026

    Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E in attacks against PowerPoint.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-0031

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-0028

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-0029

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-0030

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.

    Published: 14 Mar 2006
    5
    Medium

    CVE-2006-1235

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin/deleteuser.php in HitHost 1.0.0 might allow remote attackers to delete directories (possibly only empty directories) via the $deleteuser variable. NOTE: the initial disclosure for this issue indicated that the researcher was unable to prove this issue; however, this might have been due to certain behaviors of rmdir.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1226

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-1228

    Last Modified: 16 Apr 2026

    Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to click on a URL that fixes the session identifier.

    Published: 14 Mar 2006
    1.2
    Low

    CVE-2006-1231

    Last Modified: 16 Apr 2026

    CAPI4HylaFAX 1.3, when compiled with GENERATE_DEBUGSFFDATAFILE set, allows local users to modify arbitrary files via a symlink attack on the c2faxrecv_dbgdatafile.sff temporary file.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1230

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1233

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.

    Published: 14 Mar 2006
    5
    Medium

    CVE-2006-1225

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail messages and use Drupal as a spam proxy.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-1234

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

    Published: 14 Mar 2006
    4.6
    Medium

    CVE-2006-1227

    Last Modified: 16 Apr 2026

    Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8, when menu.module is used to create a menu item, does not implement access control for the page that is referenced, which might allow remote attackers to access administrator pages.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-1229

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-1232

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-0397

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.

    Published: 14 Mar 2006
    5.1
    Medium

    CVE-2006-0396

    Last Modified: 16 Apr 2026

    Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.

    Published: 14 Mar 2006
    6.2
    Medium

    CVE-2006-1221

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm's own folders before other folders that are specified in a user's PATH, which might allow local users to execute code as SYSTEM by placing malicious DLLs into a folder that has insecure permissions, but is searched before ZoneAlarm's folder. NOTE: since this issue is dependent on the existence of a vulnerability in a separate product (weak permissions of executables or libraries, or the execution of malicious code), perhaps it should not be included in CVE.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-0399

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-0400

    Last Modified: 16 Apr 2026

    CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1222

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-0398

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears to be a safe file type. NOTE: due to the lack of specific information in the vendor advisory, it is not clear how CVE-2006-0397, CVE-2006-0398, and CVE-2006-0399 are different.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1223

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.

    Published: 14 Mar 2006
    2.6
    Low

    CVE-2006-1224

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1216

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-1217

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in DSPoll 1.1 allows remote attackers to execute arbitrary SQL commands via the pollid parameter to (1) results.php, (2) topolls.php, (3) pollit.php.

    Published: 14 Mar 2006
    5
    Medium

    CVE-2006-1218

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the HTTP proxy in Novell BorderManager 3.8 and earlier allows remote attackers to cause a denial of service (CPU consumption and ABEND) via unknown attack vectors related to "media streaming over HTTP 1.1".

    Published: 14 Mar 2006
    5
    Medium

    CVE-2006-1219

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1215

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.

    Published: 14 Mar 2006
    4.6
    Medium

    CVE-2006-1220

    Last Modified: 16 Apr 2026

    Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.

    Published: 14 Mar 2006
    3.7
    Low

    CVE-2006-1198

    Last Modified: 16 Apr 2026

    Comvigo IM Lock 2006 uses a simple substitution cipher to encrypt a password stored in the msnvs\prc registry value, for which all users have Read permission, which allows local users to bypass the product's blocking functionality by decrypting the password.

    Published: 14 Mar 2006
    4.3
    Medium

    CVE-2006-1199

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter.

    Published: 14 Mar 2006
    7.5
    High

    CVE-2006-1208

    Last Modified: 16 Apr 2026

    Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.

    Published: 14 Mar 2006
    5
    Medium

    CVE-2006-1209

    Last Modified: 16 Apr 2026

    PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.

    Published: 14 Mar 2006