Show filters
403 Total Results
Displaying 311-320 of 403
Sort by:
Attacker Value
Unknown
CVE-2006-4727
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote attackers to inject arbitrary web script or HTML via the (1) lineId and (2) sort parameters.
0
Attacker Value
Unknown
CVE-2006-6884
Disclosure Date: December 31, 2006 (last updated October 04, 2023)
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.
0
Attacker Value
Unknown
CVE-2006-6635
Disclosure Date: December 18, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the jcms_root_path parameter.
0
Attacker Value
Unknown
CVE-2006-3973
Disclosure Date: November 22, 2006 (last updated October 04, 2023)
My Firewall Plus 5.0 Build 1119 does not verify if explorer.exe is running before launching iexplore.exe from the "Test Your Firewall" feature, which allows local users to gain SYSTEM privileges.
0
Attacker Value
Unknown
CVE-2006-5817
Disclosure Date: November 08, 2006 (last updated October 04, 2023)
prl_dhcpd in Parallels Desktop for Mac Build 1940 uses insecure permissions (0666) for /Library/Parallels/.dhcpd_configuration, which allows local users to modify DHCP configuration.
0
Attacker Value
Unknown
CVE-2006-3455
Disclosure Date: October 23, 2006 (last updated October 04, 2023)
The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function.
0
Attacker Value
Unknown
CVE-2006-5249
Disclosure Date: October 12, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitrary PHP code via a URL in the configpath parameter.
0
Attacker Value
Unknown
CVE-2006-5093
Disclosure Date: September 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
0
Attacker Value
Unknown
CVE-2006-4855
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data.
0
Attacker Value
Unknown
CVE-2006-4802
Disclosure Date: September 14, 2006 (last updated October 04, 2023)
Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notification messages, a different vector than CVE-2006-3454, a "second format string vulnerability" as found by the vendor.
0