Show filters
250 Total Results
Displaying 121-130 of 250
Sort by:
Attacker Value
Unknown
CVE-2006-6997
Disclosure Date: February 12, 2007 (last updated October 04, 2023)
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 leads to "weakened authentication security" with unknown impact and attack vectors. NOTE: due to lack of details, it is not clear whether this is the same as CVE-2006-1792.
0
Attacker Value
Unknown
CVE-2007-0786
Disclosure Date: February 06, 2007 (last updated October 04, 2023)
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2007-0514
Disclosure Date: January 26, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.
0
Attacker Value
Unknown
CVE-2006-6696
Disclosure Date: December 22, 2006 (last updated October 04, 2023)
Double free vulnerability in Microsoft Windows 2000, XP, 2003, and Vista allows local users to gain privileges by calling the MessageBox function with a MB_SERVICE_NOTIFICATION message with crafted data, which sends a HardError message to Client/Server Runtime Server Subsystem (CSRSS) process, which is not properly handled when invoking the UserHardError and GetHardErrorText functions in WINSRV.DLL.
0
Attacker Value
Unknown
CVE-2006-6605
Disclosure Date: December 19, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41, and 2.35 and earlier before ME-10026 allows remote attackers to execute arbitrary code via a long argument to the PASS command.
0
Attacker Value
Unknown
CVE-2006-0032
Disclosure Date: September 12, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.
0
Attacker Value
Unknown
CVE-2006-4379
Disclosure Date: September 08, 2006 (last updated October 04, 2023)
Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.
0
Attacker Value
Unknown
CVE-2006-4616
Disclosure Date: September 07, 2006 (last updated October 04, 2023)
SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception.
0
Attacker Value
Unknown
CVE-2006-3880
Disclosure Date: July 27, 2006 (last updated November 08, 2023)
Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation.
0
Attacker Value
Unknown
CVE-2006-3351
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.
0