Show filters
198 Total Results
Displaying 111-120 of 198
Sort by:
Attacker Value
Unknown

CVE-2006-5653

Disclosure Date: November 03, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.
0
Attacker Value
Unknown

CVE-2006-5563

Disclosure Date: October 27, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-4511

Disclosure Date: October 05, 2006 (last updated October 04, 2023)
Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to "zero-size strings in blowfish routines."
0
Attacker Value
Unknown

CVE-2006-4975

Disclosure Date: September 25, 2006 (last updated October 04, 2023)
Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service.
0
Attacker Value
Unknown

CVE-2006-4615

Disclosure Date: September 07, 2006 (last updated October 04, 2023)
Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file.
0
Attacker Value
Unknown

CVE-2006-4347

Disclosure Date: August 24, 2006 (last updated October 04, 2023)
SQL injection vulnerability in user logon authentication request handling in Cool_CoolD.exe in Cool Manager 5.0 (5,60,90,28) and Cool Messenger Office/School Server 5.5 (5,65,12,13) allows remote attackers to execute arbitrary SQL commands via the username field.
0
Attacker Value
Unknown

CVE-2006-4229

Disclosure Date: August 18, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (com_lm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown

CVE-2006-3692

Disclosure Date: July 21, 2006 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating that the $lm_path variable is set to a constant value. As of 20060726, CVE concurs with the vendor based on SecurityTracker's post-disclosure analysis
0
Attacker Value
Unknown

CVE-2006-3669

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.
0
Attacker Value
Unknown

CVE-2006-3298

Disclosure Date: June 29, 2006 (last updated October 04, 2023)
Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll.
0