Total
29522 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-5001 | 2 Ipswitch, Progress | 2 Ws Ftp Server, Ws Ftp Server | 2024-11-21 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue. | |||||
CVE-2006-4693 | 1 Microsoft | 2 Office, Word | 2024-11-21 | 9.3 HIGH | N/A |
Unspecified vulnerability in Microsoft Word 2004 for Mac and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word file, a different issue than CVE-2006-3647 and CVE-2006-3651. | |||||
CVE-2006-4571 | 1 Mozilla | 2 Seamonkey, Thunderbird | 2024-11-21 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified vectors, some of which involve JavaScript, and possibly large images or plugin data. | |||||
CVE-2006-4534 | 1 Microsoft | 1 Office | 2024-11-21 | 9.3 HIGH | N/A |
Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo. | |||||
CVE-2006-4472 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow attackers to bypass user authentication via unknown vectors involving the (1) do_pdf command and the (2) emailform com_content task. | |||||
CVE-2006-4470 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 7.5 HIGH | N/A |
Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is defined, which allows attackers to have an unknown impact, possibly resulting in PHP remote file inclusion. | |||||
CVE-2006-4469 | 1 Joomla | 1 Joomla\! | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows remote attackers to perform "remote execution," related to "Injection Flaws." | |||||
CVE-2006-4307 | 1 Sun | 2 Solaris, Sunos | 2024-11-21 | 7.2 HIGH | N/A |
Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319. | |||||
CVE-2006-4112 | 1 Rubyonrails | 1 Rails | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111. | |||||
CVE-2006-4097 | 1 Cisco | 1 Secure Access Control Server | 2024-11-21 | 7.8 HIGH | N/A |
Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it has been reported that at least one issue is a heap-based buffer overflow involving the Tunnel-Password attribute. | |||||
CVE-2006-4028 | 1 Wordpress | 1 Wordpress | 2024-11-21 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests). | |||||
CVE-2006-3975 | 1 Broadcom | 1 Etrust Antivirus Webscan | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in CA eTrust Antivirus WebScan allows remote attackers to execute arbitrary code due to "improper bounds checking when processing certain user input." | |||||
CVE-2006-3958 | 1 Pkr Internet | 1 Taskjitsu | 2024-11-21 | 4.3 MEDIUM | N/A |
Multiple unspecified cross-site scripting (XSS) vulnerabilities in Taskjitsu 2.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the Search Tasks system, or authenticated users via (2) the Edit Task system, (3) the back-end Category Editor system, and (4) "Pages that display task status, email addresses, URL, customer, and project information." | |||||
CVE-2006-3941 | 1 Sun | 1 N1 Grid Engine | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate. | |||||
CVE-2006-3864 | 1 Microsoft | 3 Office, Project, Visio | 2024-11-21 | 9.3 HIGH | N/A |
Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868. | |||||
CVE-2006-3855 | 1 Ibm | 1 Informix Dynamic Server | 2024-11-21 | 6.5 MEDIUM | N/A |
The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR." | |||||
CVE-2006-3745 | 1 Linux | 1 Linux Kernel | 2024-11-21 | 7.2 HIGH | N/A |
Unspecified vulnerability in the sctp_make_abort_user function in the SCTP implementation in Linux 2.6.x before 2.6.17.10 and 2.4.23 up to 2.4.33 allows local users to cause a denial of service (panic) and possibly gain root privileges via unknown attack vectors. | |||||
CVE-2006-3728 | 1 Sun | 2 Solaris, Sunos | 2024-11-21 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption." | |||||
CVE-2006-3720 | 1 Oracle | 1 Enterprise Manager | 2024-11-21 | 5.5 MEDIUM | N/A |
Unspecified vulnerability in Enterprise Config Management for Oracle Enterprise Manager 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# EM02. | |||||
CVE-2006-3719 | 1 Oracle | 1 Enterprise Manager | 2024-11-21 | 5.5 MEDIUM | N/A |
Unspecified vulnerability in CORE: Repository for Oracle Enterprise Manager 9.0.1.0 and 9.2.0.1 has unknown impact and attack vectors, aka Oracle Vuln# EM01. |