CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2006-1043

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln).

    Published: 7 Mar 2006
    10
    Critical

    CVE-2006-1038

    Last Modified: 16 Apr 2026

    Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX 3.0.4 and earlier allows remote attackers to have an unknown impact when a Unicode string is converted to a "narrow" string.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1040

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1041

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Gregarius 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_query parameter to search.php or (2) tag parameter to tags.php.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1049

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in the Admin functionality in Joomla! 1.0.7 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via unknown attack vectors.

    Published: 7 Mar 2006
    1.7
    Low

    CVE-2006-0554

    Last Modified: 16 Apr 2026

    Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-0883

    Last Modified: 16 Apr 2026

    OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.

    Published: 7 Mar 2006
    9.3
    Critical

    CVE-2006-1017

    Last Modified: 16 Apr 2026

    The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1026

    Last Modified: 16 Apr 2026

    JFacets before 0.2 allows remote attackers to gain privileges as any account via a GET request with a modified account profileID.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1019

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which reference a source URL that appears to be for an unrelated issue.

    Published: 7 Mar 2006
    6.4
    Medium

    CVE-2006-1015

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

    Published: 7 Mar 2006
    3.2
    Low

    CVE-2006-1014

    Last Modified: 16 Apr 2026

    Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

    Published: 7 Mar 2006
    6.8
    Medium

    CVE-2006-1025

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inject arbitrary web script or HTML via the ShipMethod parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1018

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action.

    Published: 7 Mar 2006
    2.1
    Low

    CVE-2006-0456

    Last Modified: 16 Apr 2026

    The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1020

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1021

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable).

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1022

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to include and execute arbitrary PHP code via a URL in the uye_klasor parameter, along with a misafir[] parameter that is set to UYE_SEVIYE.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1023

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1024

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MgrLogin.asp in Addsoft StoreBot 2005 Professional allows remote attackers to execute arbitrary SQL commands via the Pwd parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1027

    Last Modified: 16 Apr 2026

    feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via a "/" (slash) in the feed parameter to index.php, which reveals the path in an error message.

    Published: 7 Mar 2006
    7.8
    High

    CVE-2006-1028

    Last Modified: 16 Apr 2026

    feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of service (stressed file cache) by creating many files via filenames in the feed parameter to index.php.

    Published: 7 Mar 2006
    4.3
    Medium

    CVE-2006-1029

    Last Modified: 16 Apr 2026

    The cross-site scripting (XSS) countermeasures in class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause a denial of service via a crafted mosmsg parameter to index.php with a malformed sequence of multiple tags, as demonstrated using "<<>AAA<><>", possibly due to nested or empty tags.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-1030

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive information via an unspecified attack vector that reveals the path.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1016

    Last Modified: 16 Apr 2026

    Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.

    Published: 7 Mar 2006
    7.5
    High

    CVE-2006-1013

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.

    Published: 7 Mar 2006
    5
    Medium

    CVE-2006-0815

    Last Modified: 16 Apr 2026

    NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension.

    Published: 6 Mar 2006
    5
    Medium

    CVE-2006-0458

    Last Modified: 16 Apr 2026

    The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributions, allows remote attackers to cause a denial of service (application crash) via certain crafted arguments in a DCC command.

    Published: 6 Mar 2006
    6.4
    Medium

    CVE-2006-1010

    Last Modified: 16 Apr 2026

    Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (segmentation fault) and possibly execute code by sending the server a large request.

    Published: 6 Mar 2006
    7.5
    High

    CVE-2006-1012

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execute arbitrary SQL commands via the User-Agent field in an HTTP header for a comment.

    Published: 6 Mar 2006
    5
    Medium

    CVE-2006-0814

    Last Modified: 16 Apr 2026

    response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.

    Published: 6 Mar 2006
    5
    Medium

    CVE-2006-0949

    Last Modified: 16 Apr 2026

    RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters.

    Published: 6 Mar 2006
    2.1
    Low

    CVE-2006-1011

    Last Modified: 16 Apr 2026

    LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Mar 2006
    7.5
    High

    CVE-2006-1006

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in sendcard.php in sendcard before 3.3.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 6 Mar 2006
    4.3
    Medium

    CVE-2006-1004

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in agencyprofile.asp in Parodia 6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the AG_ID parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 6 Mar 2006
    10
    Critical

    CVE-2006-1002

    Last Modified: 16 Apr 2026

    NETGEAR WGT624 Wireless DSL router has a default account of super_username "Gearguy" and super_passwd "Geardog", which allows remote attackers to modify the configuration. NOTE: followup posts have suggested that this might not occur with all WGT624 routers.

    Published: 6 Mar 2006
    10
    Critical

    CVE-2006-1000

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.

    Published: 6 Mar 2006
    Unknown

    CVE-2006-0390

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4504. Reason: This candidate is a duplicate of CVE-2005-4504. Notes: All CVE users should reference CVE-2005-4504 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Mar 2006
    6.4
    Medium

    CVE-2006-1005

    Last Modified: 16 Apr 2026

    agencyprofile.asp in Parodia 6.2 and earlier might allow remote attackers to obtain sensitive information by triggering an SQL error via an invalid AG_ID parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 6 Mar 2006
    6.4
    Medium

    CVE-2006-0387

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.

    Published: 6 Mar 2006
    5
    Medium

    CVE-2006-1001

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary SQL commands via the fid parameter.

    Published: 6 Mar 2006
    7.5
    High

    CVE-2006-1007

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) dir and (2) page_id parameter to index.php.

    Published: 6 Mar 2006
    5.8
    Medium

    CVE-2006-1008

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir and (2) page_id parameter to (a) index.php and (3) userid parameter to (b) mailto.php. NOTE: it is possible that issues 1 and 2 are resultant from SQL injection.

    Published: 6 Mar 2006
    4.6
    Medium

    CVE-2006-1009

    Last Modified: 16 Apr 2026

    M4 Project enigma-suite before 0.73.3 (Windows) has a default password of "nominal" for the "enigma-client" account, which allows local users to gain access.

    Published: 6 Mar 2006
    5
    Medium

    CVE-2006-1003

    Last Modified: 16 Apr 2026

    The backup configuration option in NETGEAR WGT624 Wireless Firewall Router stores sensitive information in cleartext, which allows remote attackers to obtain passwords and gain privileges.

    Published: 6 Mar 2006
    7.8
    High

    CVE-2006-7197

    Last Modified: 23 Apr 2026

    The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

    Published: 5 Mar 2006
    2.1
    Low

    CVE-2006-1343

    Last Modified: 16 Apr 2026

    net/ipv4/netfilter/ip_conntrack_core.c in Linux kernel 2.4 and 2.6, and possibly net/ipv4/netfilter/nf_conntrack_l3proto_ipv4.c in 2.6, does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the getsockopt function with SO_ORIGINAL_DST, which allows local users to obtain portions of potentially sensitive memory.

    Published: 4 Mar 2006
    2.1
    Low

    CVE-2006-1342

    Last Modified: 16 Apr 2026

    net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory.

    Published: 4 Mar 2006
    1.7
    Low

    CVE-2006-0386

    Last Modified: 16 Apr 2026

    FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.

    Published: 3 Mar 2006
    2.6
    Low

    CVE-2006-0388

    Last Modified: 16 Apr 2026

    Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.

    Published: 3 Mar 2006