Show filters
545 Total Results
Displaying 471-480 of 545
Sort by:
Attacker Value
Unknown

CVE-2006-6673

Disclosure Date: December 21, 2006 (last updated October 04, 2023)
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands.
0
Attacker Value
Unknown

CVE-2006-6641

Disclosure Date: December 20, 2006 (last updated October 04, 2023)
Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.
0
Attacker Value
Unknown

CVE-2006-6576

Disclosure Date: December 15, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.
0
Attacker Value
Unknown

CVE-2006-6387

Disclosure Date: December 08, 2006 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-6241

Disclosure Date: December 03, 2006 (last updated October 04, 2023)
Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to cause a denial of service (crash) via consecutive RETR commands. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-6240

Disclosure Date: December 03, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to list contents of arbitrary directories and download arbitrary files via a .. (dot dot) sequence in an FTP command argument, as demonstrated by RETR (GET) or STOR (PUT). NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-2450

Disclosure Date: July 18, 2006 (last updated October 04, 2023)
auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, a different issue than CVE-2006-2369.
0
Attacker Value
Unknown

CVE-2006-2393

Disclosure Date: May 16, 2006 (last updated October 04, 2023)
The client_cmd function in Empire 4.3.2 and earlier allows remote attackers to cause a denial of service (application crash) by causing long text strings to be appended to the player->client buffer, which causes an invalid memory access.
0
Attacker Value
Unknown

CVE-2006-2141

Disclosure Date: May 02, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.
0
Attacker Value
Unknown

CVE-2006-2110

Disclosure Date: May 01, 2006 (last updated October 04, 2023)
Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.
0