CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-0374

    Last Modified: 16 Apr 2026

    Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).

    Published: 22 Jan 2006
    5
    Medium

    CVE-2006-0355

    Last Modified: 16 Apr 2026

    Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.

    Published: 22 Jan 2006
    4.3
    Medium

    CVE-2006-0364

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "&#106&#97&#118&#97&#115&#99&#114&#105&#112&#116".

    Published: 22 Jan 2006
    7.8
    High

    CVE-2006-0368

    Last Modified: 16 Apr 2026

    Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.

    Published: 22 Jan 2006
    2.1
    Low

    CVE-2006-0369

    Last Modified: 16 Apr 2026

    MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access

    Published: 22 Jan 2006
    5
    Medium

    CVE-2006-0370

    Last Modified: 16 Apr 2026

    Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.

    Published: 22 Jan 2006
    7.5
    High

    CVE-2006-0376

    Last Modified: 16 Apr 2026

    The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place.

    Published: 22 Jan 2006
    4.3
    Medium

    CVE-2006-0361

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.

    Published: 22 Jan 2006
    5
    Medium

    CVE-2006-0362

    Last Modified: 16 Apr 2026

    TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote attackers to cause a denial of service (CPU consumption) via an unknown vector, probably involving an HTTP request with a negative number in the Content-Length header.

    Published: 22 Jan 2006
    3.6
    Low

    CVE-2006-0353

    Last Modified: 16 Apr 2026

    unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.

    Published: 22 Jan 2006
    5
    Medium

    CVE-2006-0347

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.

    Published: 21 Jan 2006
    4.3
    Medium

    CVE-2006-0350

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0351

    Last Modified: 16 Apr 2026

    Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.

    Published: 21 Jan 2006
    4.3
    Medium

    CVE-2006-0346

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php.

    Published: 21 Jan 2006
    7.5
    High

    CVE-2006-0345

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0348

    Last Modified: 16 Apr 2026

    Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0352

    Last Modified: 16 Apr 2026

    The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (login credentials) via a direct request. NOTE: It was later reported that 1.1.2 is also affected.

    Published: 21 Jan 2006
    7.5
    High

    CVE-2006-0349

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.

    Published: 21 Jan 2006
    4.3
    Medium

    CVE-2006-0333

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0335

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.

    Published: 21 Jan 2006
    7.5
    High

    CVE-2006-0339

    Last Modified: 16 Apr 2026

    Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.

    Published: 21 Jan 2006
    7.1
    High

    CVE-2006-0340

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.

    Published: 21 Jan 2006
    7.8
    High

    CVE-2006-0342

    Last Modified: 16 Apr 2026

    RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0343

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".

    Published: 21 Jan 2006
    4.6
    Medium

    CVE-2006-0331

    Last Modified: 16 Apr 2026

    Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.

    Published: 21 Jan 2006
    6.4
    Medium

    CVE-2006-0332

    Last Modified: 16 Apr 2026

    Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0327

    Last Modified: 16 Apr 2026

    TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0328

    Last Modified: 16 Apr 2026

    Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.

    Published: 21 Jan 2006
    4.3
    Medium

    CVE-2006-0334

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the original researcher notification shows an XSS manipulation in "Keywords".

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0336

    Last Modified: 16 Apr 2026

    Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".

    Published: 21 Jan 2006
    7.5
    High

    CVE-2006-0337

    Last Modified: 16 Apr 2026

    Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.

    Published: 21 Jan 2006
    5
    Medium

    CVE-2006-0338

    Last Modified: 16 Apr 2026

    Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.

    Published: 21 Jan 2006
    4.3
    Medium

    CVE-2006-0330

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).

    Published: 21 Jan 2006
    7.5
    High

    CVE-2006-0329

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

    Published: 21 Jan 2006
    6.4
    Medium

    CVE-2006-0344

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.

    Published: 21 Jan 2006
    7.2
    High

    CVE-2006-0045

    Last Modified: 16 Apr 2026

    crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.

    Published: 20 Jan 2006
    7.5
    High

    CVE-2006-0325

    Last Modified: 16 Apr 2026

    Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/todo.inc.php, which allows remote attackers to execute arbitrary commands via the "cij" parameter.

    Published: 20 Jan 2006
    7.2
    High

    CVE-2006-2607

    Last Modified: 16 Apr 2026

    do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in /etc/security/limits.conf.

    Published: 20 Jan 2006
    5
    Medium

    CVE-2006-0322

    Last Modified: 16 Apr 2026

    Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links."

    Published: 19 Jan 2006
    7.5
    High

    CVE-2006-0324

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.

    Published: 19 Jan 2006
    7.5
    High

    CVE-2006-0019

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.

    Published: 19 Jan 2006
    5
    Medium

    CVE-2006-0312

    Last Modified: 16 Apr 2026

    create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.

    Published: 19 Jan 2006
    7.5
    High

    CVE-2006-0313

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php, (11) index.php, (12) group.php, or (13) anniv.php.

    Published: 19 Jan 2006
    7.5
    High

    CVE-2006-0314

    Last Modified: 16 Apr 2026

    PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.

    Published: 19 Jan 2006
    5.8
    Medium

    CVE-2006-0315

    Last Modified: 16 Apr 2026

    index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.

    Published: 19 Jan 2006
    5
    Medium

    CVE-2006-0319

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.

    Published: 19 Jan 2006
    7.5
    High

    CVE-2006-0320

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.

    Published: 19 Jan 2006
    4
    Medium

    CVE-2006-0309

    Last Modified: 16 Apr 2026

    Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.

    Published: 19 Jan 2006
    4.3
    Medium

    CVE-2006-0317

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

    Published: 19 Jan 2006
    7.5
    High

    CVE-2006-0318

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.

    Published: 19 Jan 2006