CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-0198

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.

    Published: 13 Jan 2006
    4.3
    Medium

    CVE-2006-0193

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.

    Published: 13 Jan 2006
    7.5
    High

    CVE-2006-0189

    Last Modified: 16 Apr 2026

    Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.

    Published: 13 Jan 2006
    4.3
    Medium

    CVE-2006-0194

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.

    Published: 13 Jan 2006
    7.5
    High

    CVE-2006-0192

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp.

    Published: 13 Jan 2006
    4.9
    Medium

    CVE-2006-0191

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.

    Published: 13 Jan 2006
    7.2
    High

    CVE-2006-0190

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.

    Published: 13 Jan 2006
    4.9
    Medium

    CVE-2007-2030

    Last Modified: 23 Apr 2026

    lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.

    Published: 13 Jan 2006
    7.5
    High

    CVE-2006-0182

    Last Modified: 16 Apr 2026

    login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".

    Published: 12 Jan 2006
    4.3
    Medium

    CVE-2006-0180

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the Title field on the "Adding New Event" page, and possibly other vectors, involving iframe tags.

    Published: 12 Jan 2006
    5.1
    Medium

    CVE-2006-0187

    Last Modified: 16 Apr 2026

    By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.

    Published: 12 Jan 2006
    Unknown

    CVE-2006-0186

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4500. Reason: This candidate is a duplicate of CVE-2005-4500. Notes: All CVE users should reference CVE-2005-4500 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Jan 2006
    6.5
    Medium

    CVE-2006-0183

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in edit.php in ACal Calendar Project 2.2.5 allows authenticated users to execute arbitrary PHP code via (1) the edit=header value, which modifies header.php, or (2) the edit=footer value, which modifies footer.php. NOTE: this issue might be resultant from the poor authentication as identified by CVE-2006-0182. Since the design of the product allows the administrator to edit the code, perhaps this issue should not be included in CVE, except as a consequence of CVE-2006-0182.

    Published: 12 Jan 2006
    5
    Medium

    CVE-2006-0185

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.

    Published: 12 Jan 2006
    7.5
    High

    CVE-2006-0184

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in AspTopSites allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to goto.asp or (2) password parameter to includeloginuser.asp.

    Published: 12 Jan 2006
    7.2
    High

    CVE-2006-0181

    Last Modified: 16 Apr 2026

    Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.1.3 has an undocumented administrative account with a default password, which allows local users to gain privileges via the expert command.

    Published: 12 Jan 2006
    2.6
    Low

    CVE-2006-0208

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are included in the resulting error message.

    Published: 12 Jan 2006
    5
    Medium

    CVE-2006-0179

    Last Modified: 16 Apr 2026

    The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.

    Published: 11 Jan 2006
    7.5
    High

    CVE-2006-0166

    Last Modified: 16 Apr 2026

    Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products.

    Published: 11 Jan 2006
    4
    Medium

    CVE-2006-0173

    Last Modified: 16 Apr 2026

    Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.

    Published: 11 Jan 2006
    3.5
    Low

    CVE-2006-0172

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.

    Published: 11 Jan 2006
    4.3
    Medium

    CVE-2006-0168

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in MyPhPim 01.05 allows remote attackers to inject arbitrary web script or HTML via the description field on the "Create New todo" page.

    Published: 11 Jan 2006
    7.5
    High

    CVE-2006-0167

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.

    Published: 11 Jan 2006
    4.3
    Medium

    CVE-2006-0165

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form.

    Published: 11 Jan 2006
    2.1
    Low

    CVE-2006-0055

    Last Modified: 16 Apr 2026

    The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.

    Published: 11 Jan 2006
    5.3
    Medium

    CVE-2006-0054

    Last Modified: 16 Apr 2026

    The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an access of an uninitialized pointer.

    Published: 11 Jan 2006
    7.5
    High

    CVE-2006-0163

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field. NOTE: This is a different vulnerability than CVE-2005-3792.

    Published: 11 Jan 2006
    4.9
    Medium

    CVE-2006-0035

    Last Modified: 16 Apr 2026

    The netlink_rcv_skb function in af_netlink.c in Linux kernel 2.6.14 and 2.6.15 allows local users to cause a denial of service (infinite loop) via a nlmsg_len field of 0.

    Published: 11 Jan 2006
    7.5
    High

    CVE-2006-0164

    Last Modified: 16 Apr 2026

    phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.

    Published: 11 Jan 2006
    7.5
    High

    CVE-2006-0169

    Last Modified: 16 Apr 2026

    addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.

    Published: 11 Jan 2006
    7.5
    High

    CVE-2006-0171

    Last Modified: 16 Apr 2026

    PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.

    Published: 11 Jan 2006
    Unknown

    CVE-2006-0170

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-0035. Reason: This candidate is a duplicate of CVE-2006-0035. Notes: All CVE users should reference CVE-2006-0035 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Jan 2006
    4.3
    Medium

    CVE-2006-0175

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 11 Jan 2006
    7.2
    High

    CVE-2006-0176

    Last Modified: 16 Apr 2026

    Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.

    Published: 11 Jan 2006
    7.2
    High

    CVE-2006-0177

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.

    Published: 11 Jan 2006
    7.2
    High

    CVE-2006-0178

    Last Modified: 16 Apr 2026

    Format string vulnerability in /bin/ftp in UNICOS 9.0.2.2 allows local users to have an unknown impact via format string specifiers in the quote command. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

    Published: 11 Jan 2006
    4
    Medium

    CVE-2006-0174

    Last Modified: 16 Apr 2026

    Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.

    Published: 11 Jan 2006
    9.3
    Critical

    CVE-2006-0010

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0002

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.

    Published: 10 Jan 2006
    9.3
    Critical

    CVE-2006-0020

    Last Modified: 16 Apr 2026

    An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."

    Published: 10 Jan 2006
    5
    Medium

    CVE-2006-0105

    Last Modified: 16 Apr 2026

    PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit and no new connections) via a large number of simultaneous connection requests.

    Published: 10 Jan 2006
    4.6
    Medium

    CVE-2006-0161

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0162

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files.

    Published: 10 Jan 2006
    4.3
    Medium

    CVE-2006-0152

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) in search_result.php in phpChamber 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the needle parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0153

    Last Modified: 16 Apr 2026

    427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0154

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.

    Published: 10 Jan 2006
    4.3
    Medium

    CVE-2006-0155

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in posts.php in 427BB 2.2 and 2.2.1 allows remote attackers to inject arbitrary Javascript via a new message with a url bbcode tag containing a javascript URI.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0160

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0158

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in CyberDoc SiteSuite CMS allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 10 Jan 2006
    7.5
    High

    CVE-2006-0159

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in escribir.php in Foro Domus 2.10 allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown, although it may be based on post-disclosure analysis of CVE-2006-0110; the details are obtained solely from third party information.

    Published: 10 Jan 2006