CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-0735

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.

    Published: 16 Feb 2006
    5
    Medium

    CVE-2006-0730

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Dovecot before 1.0beta3 allow remote attackers to cause a denial of service (application crash or hang) via unspecified vectors involving (1) "potential hangs" in the APPEND command and "potential crashes" in (2) dovecot-auth and (3) imap/pop3-login. NOTE: vector 2 might be related to a double free vulnerability.

    Published: 16 Feb 2006
    4
    Medium

    CVE-2006-0734

    Last Modified: 16 Apr 2026

    The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015.

    Published: 16 Feb 2006
    1.2
    Low

    CVE-2006-5214

    Last Modified: 23 Apr 2026

    Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.

    Published: 16 Feb 2006
    2.6
    Low

    CVE-2006-5215

    Last Modified: 23 Apr 2026

    The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.

    Published: 16 Feb 2006
    7.5
    High

    CVE-2006-0719

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0718

    Last Modified: 16 Apr 2026

    The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0688

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in application.php in nicecoder.com indexu 5.0.0 and 5.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0689

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Registration Form in TTS Time Tracking Software 3.0 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0690

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0691

    Last Modified: 16 Apr 2026

    edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0693

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in rb_auth.php in Roberto Butti CALimba 0.99.2 beta and earlier allow remote attackers to execute arbitrary SQL commands and bypass login authentication via the (1) login and (2) password parameters.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0694

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the loaders (load_*.php) in Ansilove before 1.03 allows remote attackers to read arbitrary files via unspecified vectors involving "converting files accessible by the webserver".

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0695

    Last Modified: 16 Apr 2026

    Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code by uploading arbitrary files with dangerous extensions, then accessing them directly in the upload directory.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0696

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0700

    Last Modified: 16 Apr 2026

    imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0701

    Last Modified: 16 Apr 2026

    readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0703

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0710

    Last Modified: 16 Apr 2026

    Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0712

    Last Modified: 16 Apr 2026

    mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0717

    Last Modified: 16 Apr 2026

    IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.

    Published: 15 Feb 2006
    4.9
    Medium

    CVE-2006-0666

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the (1) unix_mp and (2) unix_64 kernels in IBM AIX 5.3 VRMF 5.3.0.30 through 5.3.0.33 allows local users to cause a denial of service (system crash) via unknown vectors related to EMULATE_VMX.

    Published: 15 Feb 2006
    10
    Critical

    CVE-2006-0698

    Last Modified: 16 Apr 2026

    Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vectors related to "other attempted exploits" other than SQL injection.

    Published: 15 Feb 2006
    6.5
    Medium

    CVE-2006-0705

    Last Modified: 16 Apr 2026

    Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0713

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4) install/third_stage_install.php, and (5) install/forth_stage_install.php. NOTE: direct static code injection is resultant from this issue, as demonstrated by inserting PHP code into the username, which is inserted into linpha.log, which is accessible from the directory traversal.

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0715

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0699

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0706

    Last Modified: 16 Apr 2026

    Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the URL, which is used in the homepage parameter.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0707

    Last Modified: 16 Apr 2026

    PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.

    Published: 15 Feb 2006
    9.3
    Critical

    CVE-2006-0708

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0714

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0716

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0692

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.

    Published: 15 Feb 2006
    10
    Critical

    CVE-2006-0697

    Last Modified: 16 Apr 2026

    Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, probably direct requests.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0702

    Last Modified: 16 Apr 2026

    admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.

    Published: 15 Feb 2006
    2.6
    Low

    CVE-2006-0704

    Last Modified: 16 Apr 2026

    iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0711

    Last Modified: 16 Apr 2026

    The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0680

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL.

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0681

    Last Modified: 16 Apr 2026

    Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.

    Published: 15 Feb 2006
    10
    Critical

    CVE-2006-0685

    Last Modified: 16 Apr 2026

    The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.

    Published: 15 Feb 2006
    10
    Critical

    CVE-2006-0686

    Last Modified: 16 Apr 2026

    add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0687

    Last Modified: 16 Apr 2026

    process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.

    Published: 15 Feb 2006
    5
    Medium

    CVE-2006-0377

    Last Modified: 16 Apr 2026

    CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0683

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.

    Published: 15 Feb 2006
    4.6
    Medium

    CVE-2006-0455

    Last Modified: 16 Apr 2026

    gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".

    Published: 15 Feb 2006
    7.5
    High

    CVE-2006-0684

    Last Modified: 16 Apr 2026

    change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.

    Published: 15 Feb 2006
    4.3
    Medium

    CVE-2006-0682

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in bbcodes system in e107 before 0.7.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 15 Feb 2006
    9.3
    Critical

    CVE-2006-0006

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.

    Published: 14 Feb 2006
    5
    Medium

    CVE-2006-0451

    Last Modified: 16 Apr 2026

    Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.

    Published: 14 Feb 2006
    2.1
    Low

    CVE-2006-0382

    Last Modified: 16 Apr 2026

    Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.

    Published: 14 Feb 2006