Show filters
84 Total Results
Displaying 51-60 of 84
Sort by:
Attacker Value
Unknown

CVE-2007-3181

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
0
Attacker Value
Unknown

CVE-2007-2606

Disclosure Date: May 11, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact via certain input processed by (1) config\ConfigFile.cpp or (2) msgs\check_msgs.epp. NOTE: if ConfigFile.cpp reads a configuration file with restrictive permissions, then the ConfigFile.cpp vector may not cross privilege boundaries and perhaps should not be included in CVE.
0
Attacker Value
Unknown

CVE-2006-6250

Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist file containing extended ASCII, which causes the Unicode converter to be invoked.
0
Attacker Value
Unknown

CVE-2006-6211

Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to (a) admin/admincore.php, the (2) month parameter to (b) admin/comments.php or (c) admin/entries.php, or the (3) page parameter to (d) admin/logs.php, different vectors than CVE-2006-5064.
0
Attacker Value
Unknown

CVE-2006-5064

Disclosure Date: September 28, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-1240

Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.
0
Attacker Value
Unknown

CVE-2006-1241

Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.
0
Attacker Value
Unknown

CVE-2006-0172

Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.
0
Attacker Value
Unknown

CVE-2006-0173

Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.
0
Attacker Value
Unknown

CVE-2006-0174

Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.
0