CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-0593

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via the (1) shout_name field in shoutbox_panel.php and the (2) comments field in comments_include.php.

    Published: 8 Feb 2006
    5
    Medium

    CVE-2006-0585

    Last Modified: 16 Apr 2026

    jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.

    Published: 8 Feb 2006
    2.1
    Low

    CVE-2006-0582

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in rshd in Heimdal 0.6.x before 0.6.6 and 0.7.x before 0.7.2, when storing forwarded credentials, allows attackers to overwrite arbitrary files and change file ownership via unknown vectors.

    Published: 8 Feb 2006
    6.5
    Medium

    CVE-2006-0581

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.

    Published: 8 Feb 2006
    5
    Medium

    CVE-2006-0580

    Last Modified: 16 Apr 2026

    IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).

    Published: 8 Feb 2006
    7.5
    High

    CVE-2006-0578

    Last Modified: 16 Apr 2026

    Blue Coat Proxy Security Gateway OS (SGOS) 4.1.2.1 does not enforce CONNECT rules when using Deep Content Inspection, which allows remote attackers to bypass connection filters.

    Published: 8 Feb 2006
    2.1
    Low

    CVE-2006-2120

    Last Modified: 16 Apr 2026

    The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers to cause a denial of service (crash) via a crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values, which triggers an out-of-bounds read.

    Published: 8 Feb 2006
    7.2
    High

    CVE-2006-0577

    Last Modified: 16 Apr 2026

    Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the "Appearance" dialog and selecting the "Additional styles (skins) are available on the Lexmark web site" option, which launches a web browser that is running with SYSTEM privileges.

    Published: 8 Feb 2006
    5
    Medium

    CVE-2006-0575

    Last Modified: 16 Apr 2026

    convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via ".." sequences and a symlink attack on the temporary file that is used during conversion.

    Published: 7 Feb 2006
    4.3
    Medium

    CVE-2006-0568

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in throw.main in Outblaze allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Published: 7 Feb 2006
    5
    Medium

    CVE-2006-0454

    Last Modified: 16 Apr 2026

    Linux kernel before 2.6.15.3 down to 2.6.12, while constructing an ICMP response in icmp_send, does not properly handle when the ip_options_echo function in icmp.c fails, which allows remote attackers to cause a denial of service (crash) via vectors such as (1) record-route and (2) timestamp IP options with the needaddr bit set and a truncated value.

    Published: 7 Feb 2006
    7.5
    High

    CVE-2006-0570

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface.

    Published: 7 Feb 2006
    4.3
    Medium

    CVE-2006-0571

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface.

    Published: 7 Feb 2006
    7.5
    High

    CVE-2006-0572

    Last Modified: 16 Apr 2026

    phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication.

    Published: 7 Feb 2006
    4.3
    Medium

    CVE-2006-0574

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in mime/handle.html in cPanel 10 allows remote attackers to inject arbitrary web script or HTML via the (1) file extension or (2) mime-type.

    Published: 7 Feb 2006
    5
    Medium

    CVE-2006-0567

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences.

    Published: 7 Feb 2006
    4.3
    Medium

    CVE-2006-0569

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in user_class.php in Papoo 2.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the username field during the registration of a new account. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Feb 2006
    4.3
    Medium

    CVE-2006-0573

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilies in cPanel 10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to (a) editquota.html or (b) dodelpop.html; (2) showtree parameter to (c) diskusage.html; or the (3) mon, (4) year, (5) target, or (6) domain parameter to (d) stats/detailbw.html.

    Published: 7 Feb 2006
    1.2
    Low

    CVE-2006-0591

    Last Modified: 16 Apr 2026

    The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions.

    Published: 7 Feb 2006
    7.2
    High

    CVE-2006-0576

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs. NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using sudo. In such a context, this is a vulnerability.

    Published: 7 Feb 2006
    4.3
    Medium

    CVE-2006-0562

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in problem.php in PluggedOut Blog 1.9.9c allows remote attackers to inject arbitrary web script or HTML via the data parameter.

    Published: 6 Feb 2006
    7.5
    High

    CVE-2006-0563

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in exec.php in PluggedOut Blog 1.9.9c allows remote attackers to execute arbitrary SQL commands via the entryid parameter in a comment_add action.

    Published: 6 Feb 2006
    7.5
    High

    CVE-2006-0564

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.

    Published: 6 Feb 2006
    7.5
    High

    CVE-2006-0565

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the $GLOBALS[path] parameter.

    Published: 6 Feb 2006
    5
    Medium

    CVE-2006-0513

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 6 Feb 2006
    5
    Medium

    CVE-2006-0566

    Last Modified: 16 Apr 2026

    The LDAP component in CommuniGate Pro Core Server 5.0.7 allows remote attackers to cause a denial of service (application crash) via LDAP messages that contain Distinguished Names (DN) fields with a large number of elements.

    Published: 6 Feb 2006
    4.3
    Medium

    CVE-2006-0437

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.

    Published: 6 Feb 2006
    5
    Medium

    CVE-2006-0438

    Last Modified: 16 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in phpBB 2.0.19, when Link to off-site Avatar or bbcode (IMG) are enabled, allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag in a user profile, as demonstrated using links to (1) admin/admin_users.php and (2) modcp.php.

    Published: 6 Feb 2006
    5
    Medium

    CVE-2006-0670

    Last Modified: 16 Apr 2026

    Buffer overflow in l2cap.c in hcidump 1.29 allows remote attackers to cause a denial of service (crash) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet.

    Published: 5 Feb 2006
    7.5
    High

    CVE-2006-0552

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0540

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Feb 2006
    4.3
    Medium

    CVE-2006-0541

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "posting new messages."

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0542

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0545

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0544

    Last Modified: 16 Apr 2026

    urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a BGSOUND element with its SRC attribute set to "file://" followed by a large number of "-" (dash of hyphen) characters.

    Published: 4 Feb 2006
    4.6
    Medium

    CVE-2006-0539

    Last Modified: 16 Apr 2026

    The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument, which causes Linux glibc to report heap memory corruption, possibly because a strcpy in the strdup2 function can "overwrite some data."

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0546

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in index.php in a certain application available from /v1/tr/portfoy.php on www.egeinternet.com allows remote attackers to execute arbitrary code via "evilcode" in the key parameter, possibly a PHP remote file include vulnerability in which the attack vector is a URL in the key parameter. NOTE: it is not clear whether this vulnerability is associated with an online service or application service provider. If so, then it should not be included in CVE.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0547

    Last Modified: 16 Apr 2026

    Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent Network Substrate (TNS) protocol. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB18 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0265.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0548

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB15 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0549

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB05 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260. However, there are some inconsistencies that make this unclear, and there is also a possibility that this is related to DB06, which is subsumed by CVE-2006-0259.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0551

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB06 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0259 or, if it is DB05, subsumed by CVE-2006-0260.

    Published: 4 Feb 2006
    5
    Medium

    CVE-2006-0543

    Last Modified: 16 Apr 2026

    Cerulean Trillian 3.1.0.120 allows remote attackers to cause a denial of service (client crash) via an AIM message containing the Mac encoded Rich Text Format (RTF) escape sequences (1) \'d1, (2) \'d2, (3) \'d3, (4) \'d4, and (5) \'d5. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0550

    Last Modified: 16 Apr 2026

    Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DBC02 from the January 2006 CPU, in which case this would be a duplicate of CVE-2006-0283. However, there are enough inconsistencies that the mapping can not be made authoritatively.

    Published: 4 Feb 2006
    7.2
    High

    CVE-2006-0531

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.

    Published: 4 Feb 2006
    4.3
    Medium

    CVE-2006-0532

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary web script or HTML via a strSok parameter containing a javascript: URI in an IMG SRC attribute.

    Published: 4 Feb 2006
    4.3
    Medium

    CVE-2006-0533

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in webmailaging.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via the numdays parameter.

    Published: 4 Feb 2006
    7.5
    High

    CVE-2006-0537

    Last Modified: 16 Apr 2026

    Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument.

    Published: 4 Feb 2006
    2.6
    Low

    CVE-2006-0538

    Last Modified: 16 Apr 2026

    CipherTrust IronMail 5.0.1, when "Denial of Service Protection" is enabled, allows remote attackers to cause a denial of service (possibly CPU consumption) via a SYN flood with malformed TCP packets from multiple connections.

    Published: 4 Feb 2006
    4.3
    Medium

    CVE-2006-0534

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attackers to inject arbitrary web script or HTML via the (1) ortak or (2) kat parameter.

    Published: 4 Feb 2006
    4.3
    Medium

    CVE-2006-0536

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort".

    Published: 4 Feb 2006