Show filters
486 Total Results
Displaying 321-330 of 486
Sort by:
Attacker Value
Unknown

CVE-2006-5350

Disclosure Date: October 18, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and local attack vectors, aka Vuln# OHS08.
0
Attacker Value
Unknown

CVE-2006-5354

Disclosure Date: October 18, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06.
0
Attacker Value
Unknown

CVE-2006-4154

Disclosure Date: October 16, 2006 (last updated October 04, 2023)
Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
0
Attacker Value
Unknown

CVE-2006-4110

Disclosure Date: August 14, 2006 (last updated October 04, 2023)
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.
0
Attacker Value
Unknown

CVE-2006-3747

Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
0
Attacker Value
Unknown

CVE-2006-3918

Disclosure Date: July 28, 2006 (last updated October 04, 2023)
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
0
Attacker Value
Unknown

CVE-2006-0819

Disclosure Date: March 13, 2006 (last updated February 22, 2025)
Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.
0
Attacker Value
Unknown

CVE-2006-0820

Disclosure Date: March 13, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.
0
Attacker Value
Unknown

CVE-2006-0435

Disclosure Date: January 26, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01.
0
Attacker Value
Unknown

CVE-2005-4823

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.
0