Total
254754 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-3722 | 1 Oracle | 1 Peoplesoft Enterprise | 2024-02-04 | 10.0 HIGH | N/A |
Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.4 Bundle #16, 8.8 Bundle #10, and 8.9 Bundle #3 has unknown impact and attack vectors, aka Oracle Vuln# PSE01. | |||||
CVE-2006-4450 | 1 Phpbb Group | 1 Phpbb | 2024-02-04 | 5.1 MEDIUM | N/A |
usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request. | |||||
CVE-2006-2853 | 1 Abarcar | 1 Abarcar Realty Portal | 2024-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in content.php in abarcar Realty Portal 5.1.5 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |||||
CVE-2006-2330 | 1 Php Fusion | 1 Php Fusion | 2024-02-04 | 6.4 MEDIUM | N/A |
PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata. | |||||
CVE-2005-0478 | 1 Trackercam | 1 Trackercam | 2024-02-04 | 5.0 MEDIUM | N/A |
Multiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP request with a long User-Agent header or (2) a long argument to an arbitrary PHP script. | |||||
CVE-2006-0207 | 1 Php | 1 Php | 2024-02-04 | 5.0 MEDIUM | N/A |
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function. | |||||
CVE-2005-3307 | 1 Flatnuke | 1 Flatnuke | 2024-02-04 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation. | |||||
CVE-2006-2018 | 1 Jelsoft | 1 Vbulletin | 2024-02-04 | 7.5 HIGH | N/A |
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4. | |||||
CVE-2004-2345 | 1 Oracle | 1 Database Server | 2024-02-04 | 6.5 MEDIUM | N/A |
Unknown multiple vulnerabilities in Oracle9i Database Server 9.0.1.4, 9.0.1.5, 9.2.0.3, and 9.2.0.4 allow local users with the ability to invoke SQL to cause a denial of service or obtain sensitive information. | |||||
CVE-2005-0400 | 1 Linux | 1 Linux Kernel | 2024-02-04 | 2.1 LOW | N/A |
The ext2_make_empty function call in the Linux kernel before 2.6.11.6 does not properly initialize memory when creating a block for a new directory entry, which allows local users to obtain potentially sensitive information by reading the block. | |||||
CVE-2006-0357 | 1 Grant Averett | 1 Cerberus Ftp Server | 2024-02-04 | 5.0 MEDIUM | N/A |
Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command. | |||||
CVE-2006-0785 | 1 Phpkit | 1 Phpkit | 2024-02-04 | 6.4 MEDIUM | N/A |
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions. | |||||
CVE-2005-0776 | 1 Photopost | 1 Photopost Php Pro | 2024-02-04 | 5.0 MEDIUM | N/A |
adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos. | |||||
CVE-2006-0451 | 1 Redhat | 1 Fedora Core | 2024-02-04 | 5.0 MEDIUM | N/A |
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite. | |||||
CVE-2006-4005 | 1 Bomberclone | 1 Bomberclone | 2024-02-04 | 5.0 MEDIUM | N/A |
BomberClone 0.11.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) a certain malformed PKGF_ackreq packet, which triggers a crash in the rscache_add() function in pkgcache.c; and (2) an error packet, which is intended to be received by clients and force client shutdown, but also triggers server shutdown. | |||||
CVE-2006-2667 | 1 Wordpress | 1 Wordpress | 2024-02-04 | 7.5 HIGH | N/A |
Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument. | |||||
CVE-2004-2405 | 1 F-secure | 4 F-secure Anti-virus, F-secure For Firewalls, F-secure Internet Security and 1 more | 2024-02-04 | 6.4 MEDIUM | N/A |
Buffer overflow in multiple F-Secure Anti-Virus products, including F-Secure Anti-Virus 5.42 and earlier, allows remote attackers to bypass scanning or cause a denial of service (crash or module restart), depending on the product, via a malformed LHA archive. | |||||
CVE-2004-2688 | 1 Newsphp | 1 Newsphp | 2024-02-04 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358. | |||||
CVE-2004-1289 | 1 Pcal | 1 Pcal | 2024-02-04 | 10.0 HIGH | N/A |
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file. | |||||
CVE-2005-0951 | 2024-02-04 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate was created as a result of an analysis error for a researcher advisory for an issue that already existed. It stated an incorrect parameter, which was not part of the vulnerability at all. Notes: CVE users should not reference this candidate at all. |