NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60130 | CVE-2006-1421 | Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60386 | CVE-2006-1681 | Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60642 | CVE-2006-1937 | Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter. | 2 | 5 | Medium | 2016-12-20 | 2011-09-06 | View | |
60898 | CVE-2006-2194 | The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges. | 2 | 7.2 | High | 2016-12-20 | 2010-04-02 | View | |
61154 | CVE-2006-2459 | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1329 of 17672, showing 5 records out of 88360 total, starting on record 6641, ending on 6645