CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-0535

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Feb 2006
    7.1
    High

    CVE-2006-0457

    Last Modified: 16 Apr 2026

    Race condition in the (1) add_key, (2) request_key, and (3) keyctl functions in Linux kernel 2.6.x allows local users to cause a denial of service (crash) or read sensitive kernel memory by modifying the length of a string argument between the time that the kernel calculates the length and when it copies the data into kernel memory.

    Published: 3 Feb 2006
    6.4
    Medium

    CVE-2006-0299

    Last Modified: 16 Apr 2026

    The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.

    Published: 2 Feb 2006
    5.1
    Medium

    CVE-2006-0297

    Last Modified: 16 Apr 2026

    Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.

    Published: 2 Feb 2006
    5.8
    Medium

    CVE-2006-0298

    Last Modified: 16 Apr 2026

    The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0294

    Last Modified: 16 Apr 2026

    Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

    Published: 2 Feb 2006
    5.1
    Medium

    CVE-2006-0295

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0530

    Last Modified: 16 Apr 2026

    Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via spoofed CAM control messages.

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0529

    Last Modified: 16 Apr 2026

    Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via a crafted message to TCP port 4105.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0293

    Last Modified: 16 Apr 2026

    The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.

    Published: 2 Feb 2006
    2.1
    Low

    CVE-2006-0516

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.

    Published: 2 Feb 2006
    4.3
    Medium

    CVE-2006-0518

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0522

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0523

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.

    Published: 2 Feb 2006
    4.3
    Medium

    CVE-2006-0524

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 2 Feb 2006
    7.2
    High

    CVE-2006-0526

    Last Modified: 16 Apr 2026

    The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file name, which might allow local users to gain privileges via a Trojan horse program.

    Published: 2 Feb 2006
    2.1
    Low

    CVE-2006-0512

    Last Modified: 16 Apr 2026

    PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migrate_all_netinfo_online.sh, (4) migrate_all_netinfo_offline.sh, (5) migrate_all_nis_online.sh, (6) migrate_all_nis_offline.sh, (7) migrate_all_nisplus_online.sh, and (8) migrate_all_nisplus_offline.sh.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0520

    Last Modified: 16 Apr 2026

    SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0517

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to "session handling"; and (5) when posting "petitions".

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0519

    Last Modified: 16 Apr 2026

    SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.

    Published: 2 Feb 2006
    4.3
    Medium

    CVE-2006-0521

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in results.php in BrowserCRM allows remote attackers to inject arbitrary web script or HTML via certain manipulations of the query parameter, as demonstrated using an IMG SRC tag.

    Published: 2 Feb 2006
    4.6
    Medium

    CVE-2006-0525

    Last Modified: 16 Apr 2026

    Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs.

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0528

    Last Modified: 16 Apr 2026

    The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0433

    Last Modified: 16 Apr 2026

    Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does not properly handle an incoming selective acknowledgement when there is insufficient memory, which might allow remote attackers to cause a denial of service (infinite loop).

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0527

    Last Modified: 16 Apr 2026

    BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache corruption" attack.

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0296

    Last Modified: 16 Apr 2026

    The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

    Published: 2 Feb 2006
    7.5
    High

    CVE-2006-0292

    Last Modified: 16 Apr 2026

    The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.

    Published: 2 Feb 2006
    5
    Medium

    CVE-2006-0505

    Last Modified: 16 Apr 2026

    zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0506

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Nuked-klaN 1.7 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0507

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Easy CMS allow remote attackers to inject arbitrary web script or HTML via (1) unknown attack vectors in the administrative interface and (2) input fields of the contact form.

    Published: 1 Feb 2006
    5
    Medium

    CVE-2006-0508

    Last Modified: 16 Apr 2026

    Easy CMS stores the images directory under the web document root with insufficient access control and browsing enabled, which allows remote attackers to list and possibly read images that are stored in that directory.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0509

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.

    Published: 1 Feb 2006
    7.5
    High

    CVE-2006-0510

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in userlogin.jsp in Daffodil CRM 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified parameters in a login action.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0511

    Last Modified: 16 Apr 2026

    Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their Kerberos authentication single sign-on application and not a vulnerability in the Blackboard product.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0499

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Feb 2006
    7.5
    High

    CVE-2006-0502

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter.

    Published: 1 Feb 2006
    5
    Medium

    CVE-2006-0504

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in MailEnable Enterprise Edition before 1.2 allows remote attackers to cause a denial of service (CPU utilization) by viewing "formatted quoted-printable emails" via webmail.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0501

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user.

    Published: 1 Feb 2006
    7.5
    High

    CVE-2006-0500

    Last Modified: 16 Apr 2026

    MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL.

    Published: 1 Feb 2006
    5
    Medium

    CVE-2006-0503

    Last Modified: 16 Apr 2026

    IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.

    Published: 1 Feb 2006
    7.5
    High

    CVE-2006-0497

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary SQL commands via unknown attack vectors.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0498

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP GEN before 1.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 1 Feb 2006
    2.1
    Low

    CVE-2006-0488

    Last Modified: 16 Apr 2026

    The VDM (Virtual DOS Machine) emulation environment for MS-DOS applications in Windows 2000, Windows XP SP2, and Windows Server 2003 allows local users to read the first megabyte of memory and possibly obtain sensitive information, as demonstrated by dumper.asm.

    Published: 1 Feb 2006
    7.5
    High

    CVE-2006-0490

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field.

    Published: 1 Feb 2006
    7.5
    High

    CVE-2006-0491

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 1 Feb 2006
    5
    Medium

    CVE-2006-0487

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message under "extremely heavy loads" and (2) cause an "increased number of missed spam" during "spam outbreaks."

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0495

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable).

    Published: 1 Feb 2006
    4.6
    Medium

    CVE-2006-0485

    Last Modified: 16 Apr 2026

    The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh73049.

    Published: 1 Feb 2006
    4.3
    Medium

    CVE-2006-0493

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MG2 (formerly known as Minigal) 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field in a comment associated with a picture.

    Published: 1 Feb 2006
    4.6
    Medium

    CVE-2006-0486

    Last Modified: 16 Apr 2026

    Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or bypass AAA command authorization checks, aka Bug ID CSCef77770.

    Published: 1 Feb 2006