4
    Medium

    CVE-2006-2458

    Last Modified: 29 Jul 2016

    Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).

    Source:Luigi Auriemma
    Published:18 May 2006
    4.6
    Medium

    CVE-2006-2451

    Last Modified: 30 Aug 2016

    The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) and possibly gain privileges via the PR_SET_DUMPABLE argument of the prctl function and a program that causes a core dump file to be created in a directory for which the user does not have permissions.

    Source:Marco Ivaldi
    Published:6 Jul 2006
    5.1
    Medium

    CVE-2006-2447

    Last Modified: 6 Mar 2011

    SpamAssassin before 3.1.3, when running with vpopmail and the paranoid (-P) switch, allows remote attackers to execute arbitrary commands via a crafted message that is not properly handled when invoking spamd with the virtual pop username.

    Source:Metasploit
    Published:6 Jun 2006
    7.8
    High

    CVE-2006-2444

    Last Modified: 16 Aug 2016

    The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.

    Source:ECL Labs
    Published:20 May 2006
    7.6
    High

    CVE-2006-2439

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.

    Source:TecR0c
    Published:1 Jun 2006
    5
    Medium

    CVE-2006-2437

    Last Modified: 27 Aug 2013

    The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.

    Source:Joseph Pierini
    Published:17 May 2006
    4.3
    Medium

    CVE-2006-2431

    Last Modified: 14 Nov 2017

    Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page. NOTE: some sources have reported the element as "faultfactor," but this is likely erroneous.

    Source:Nuri Fattah
    Published:17 May 2006
    6.4
    Medium

    CVE-2006-2426

    Last Modified: 26 Aug 2013

    Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.

    Source:Marc Schoenefeld
    Published:14 May 2006
    4.3
    Medium

    CVE-2006-2425

    Last Modified: 27 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields.

    Source:Soot
    Published:17 May 2006
    5.1
    Medium

    CVE-2006-2424

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php.

    Source:OLiBekaS
    Published:17 May 2006
    4.3
    Medium

    CVE-2006-2423

    Last Modified: 27 Aug 2013

    Cross-site scripting (XSS) vulnerability in ftplogin/index.php in Confixx 3.1.2 allows remote attackers to inject arbitrary web script or HTML via the login parameter.

    Source:LoK-Crew
    Published:17 May 2006
    5
    Medium

    CVE-2006-2413

    Last Modified: 29 Jul 2016

    GNUnet before SVN revision 2781 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an empty UDP datagram, possibly involving FIONREAD errors.

    Source:Luigi Auriemma
    Published:16 May 2006
    5
    Medium

    CVE-2006-2412

    Last Modified: 14 Aug 2017

    The raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a large ID, which causes an invalid memory access (buffer over-read).

    Source:Luigi Auriemma
    Published:16 May 2006
    7.5
    High

    CVE-2006-2411

    Last Modified: 14 Aug 2017

    Buffer overflow in raydium_network_read function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to execute arbitrary code by sending packets with long global variables to the client.

    Source:Luigi Auriemma
    Published:16 May 2006
    5
    Medium

    CVE-2006-2410

    Last Modified: 14 Aug 2017

    raydium_network_netcall_exec function in network.c in Raydium SVN revision 312 and earlier allows remote attackers to cause a denial of service (application crash) via a packet of type 0xFF, which causes a null dereference.

    Source:Luigi Auriemma
    Published:16 May 2006
    4.6
    Medium

    CVE-2006-2409

    Last Modified: 14 Aug 2017

    Format string vulnerability in the raydium_log function in console.c in Raydium before SVN revision 310 allows local users to execute arbitrary code via format string specifiers in the format parameter, which are not properly handled in a call to raydium_console_line_add.

    Source:Luigi Auriemma
    Published:16 May 2006
    7.5
    High

    CVE-2006-2408

    Last Modified: 14 Aug 2017

    Multiple buffer overflows in Raydium before SVN revision 310 allow remote attackers to execute arbitrary code via a large packet when logged via (1) the raydium_log function in log.c or (2) the raydium_console_line_add function in console.c, possibly from a long player name.

    Source:Luigi Auriemma
    Published:16 May 2006
    7.5
    High

    CVE-2006-2407

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.

    Source:Metasploit
    Published:16 May 2006
    2.6
    Low

    CVE-2006-2406

    Last Modified: 20 Jul 2016

    Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter.

    Source:rgod
    Published:16 May 2006
    6.8
    Medium

    CVE-2006-2405

    Last Modified: 20 Jul 2016

    Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to unb_lib/abbc.css.php.

    Source:rgod
    Published:16 May 2006
    6.4
    Medium

    CVE-2006-2404

    Last Modified: 26 Aug 2013

    Directory traversal vulnerability in popup.php in RadScripts RadLance Gold 7.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.

    Source:Mr.CrackerZ
    Published:16 May 2006
    5
    Medium

    CVE-2006-2402

    Last Modified: 29 Jul 2016

    Buffer overflow in the changeRegistration function in servernet.cpp for Outgun 1.0.3 bot 2 and earlier allows remote attackers to change the registration information of other players via a long string.

    Source:Luigi Auriemma
    Published:16 May 2006
    7.8
    High

    CVE-2006-2401

    Last Modified: 29 Jul 2016

    The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (application crash) via packets with incorrect message sizes, which triggers a buffer over-read.

    Source:Luigi Auriemma
    Published:16 May 2006
    7.8
    High

    CVE-2006-2400

    Last Modified: 29 Jul 2016

    The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and earlier allow remote attackers to cause a denial of service (game interruption) via large packets, which cause an exception to be thrown.

    Source:Luigi Auriemma
    Published:16 May 2006
    7.5
    High

    CVE-2006-2399

    Last Modified: 29 Jul 2016

    Stack-based buffer overflow in the ServerNetworking::incoming_client_data function in servnet.cpp in Outgun 1.0.3 bot 2 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a data_file_request command with a long (1) type or (2) name string.

    Source:Luigi Auriemma
    Published:16 May 2006
    5
    Medium

    CVE-2006-2398

    Last Modified: 25 Aug 2013

    Directory traversal vulnerability in index.php in GPhotos 1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rep parameter.

    Source:Morocco Security Team
    Published:16 May 2006
    5.8
    Medium

    CVE-2006-2397

    Last Modified: 25 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) rep parameter to (a) index.php or (b) diapo.php or (2) image parameter to (c) affich.php. NOTE: item 1a might be resultant from directory traversal.

    Source:Morocco Security Team
    Published:16 May 2006
    5.8
    Medium

    CVE-2006-2396

    Last Modified: 26 Aug 2013

    Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote attackers to inject arbitrary web script via the browse parameter.

    Source:Kiki
    Published:16 May 2006
    5
    Medium

    CVE-2006-2395

    Last Modified: 25 Aug 2013

    PHP remote file inclusion vulnerability in resources/includes/popp.config.loader.inc.php in PopSoft Digital PopPhoto Studio 3.5.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter (cfg['popphoto_base_path'] variable). NOTE: Pixaria has notified CVE that "PopPhoto is NOT a product of Pixaria. It was a product of PopSoft Digital and is only hosted by Pixaria as a courtesy... The vulnerability listed was patched by the previous vendor and all previous users have received this update."

    Source:VietMafia
    Published:16 May 2006
    5
    Medium

    CVE-2006-2393

    Last Modified: 16 Apr 2026

    The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.

    Source:Luigi Auriemma
    Published:16 May 2006
    6.4
    Medium

    CVE-2006-2392

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.

    Source:Kacper
    Published:16 May 2006
    5.8
    Medium

    CVE-2006-2390

    Last Modified: 27 Oct 2016

    Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality.

    Source:Kiki
    Published:16 May 2006
    9.3
    Critical

    CVE-2006-2389

    Last Modified: 10 Sept 2013

    Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.

    Source:anonymous
    Published:11 Jul 2006
    9.3
    Critical

    CVE-2006-2383

    Last Modified: 31 Aug 2013

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.

    Source:Will Dormann
    Published:13 Jun 2006
    9.3
    Critical

    CVE-2006-2379

    Last Modified: 16 Apr 2026

    Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.

    Source:Preddy
    Published:13 Jun 2006
    5.5
    Medium

    CVE-2006-2374

    Last Modified: 1 Sept 2013

    The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."

    Source:Ruben Santamarta
    Published:13 Jun 2006
    10
    Critical

    CVE-2006-2373

    Last Modified: 31 Mar 2017

    The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."

    Source:Ruben Santamarta
    Published:13 Jun 2006
    10
    Critical

    CVE-2006-2372

    Last Modified: 16 Apr 2026

    Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.

    Source:redsand
    Published:11 Jul 2006
    7.5
    High

    CVE-2006-2370

    Last Modified: 8 Mar 2011

    Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."

    Source:Metasploit
    Published:13 Jun 2006
    7.5
    High

    CVE-2006-2369

    Last Modified: 17 Aug 2017

    RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

    Source:redsand
    Published:15 May 2006
    5.8
    Medium

    CVE-2006-2365

    Last Modified: 25 Aug 2013

    Cross-site scripting (XSS) vulnerability in a_login.php in Vizra allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:R00TT3R
    Published:15 May 2006
    5.1
    Medium

    CVE-2006-2363

    Last Modified: 10 Nov 2016

    SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:[Oo]
    Published:15 May 2006
    7.3
    High

    CVE-2006-2362

    Last Modified: 25 Aug 2013

    Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

    Source:Jesus Olmos Gonzalez
    Published:15 May 2006
    7.5
    High

    CVE-2006-2361

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:Darkfire
    Published:15 May 2006
    7.5
    High

    CVE-2006-2360

    Last Modified: 25 Aug 2013

    SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:sn4k3.23
    Published:15 May 2006
    4.3
    Medium

    CVE-2006-2359

    Last Modified: 25 Aug 2013

    Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.

    Source:sn4k3.23
    Published:15 May 2006
    4.3
    Medium

    CVE-2006-2351

    Last Modified: 25 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.

    Source:David Maciejak
    Published:15 May 2006
    5
    Medium

    CVE-2006-2341

    Last Modified: 25 Aug 2013

    The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI.

    Source:Bernhard Mueller
    Published:12 May 2006
    6.4
    Medium

    CVE-2006-2339

    Last Modified: 25 Aug 2013

    SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.

    Source:Hamid Ebadi
    Published:12 May 2006
    6.4
    Medium

    CVE-2006-2336

    Last Modified: 25 Aug 2013

    SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter.

    Source:Breeeeh
    Published:12 May 2006