Show filters
84 Total Results
Displaying 51-60 of 84
Sort by:
Attacker Value
Unknown
CVE-2007-3181
Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."
0
Attacker Value
Unknown
CVE-2007-2606
Disclosure Date: May 11, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Firebird 2.1 allow attackers to trigger memory corruption and possibly have other unspecified impact via certain input processed by (1) config\ConfigFile.cpp or (2) msgs\check_msgs.epp. NOTE: if ConfigFile.cpp reads a configuration file with restrictive permissions, then the ConfigFile.cpp vector may not cross privilege boundaries and perhaps should not be included in CVE.
0
Attacker Value
Unknown
CVE-2006-6250
Disclosure Date: December 04, 2006 (last updated October 04, 2023)
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist file containing extended ASCII, which causes the Unicode converter to be invoked.
0
Attacker Value
Unknown
CVE-2006-6211
Disclosure Date: December 01, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to (a) admin/admincore.php, the (2) month parameter to (b) admin/comments.php or (c) admin/entries.php, or the (3) page parameter to (d) admin/logs.php, different vectors than CVE-2006-5064.
0
Attacker Value
Unknown
CVE-2006-5064
Disclosure Date: September 28, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-1240
Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.
0
Attacker Value
Unknown
CVE-2006-1241
Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Firebird 1.5.2.4731 installs (1) fb_lock_mgr, (2) gds_drop, and (3) fb_inet_server with setuid firebird permissions, which might allow local users to gain privileges via a buffer overflow as identified by CVE-2006-1240, or possibly other vulnerabilities.
0
Attacker Value
Unknown
CVE-2006-0172
Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.
0
Attacker Value
Unknown
CVE-2006-0173
Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.
0
Attacker Value
Unknown
CVE-2006-0174
Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.
0