NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61419 | CVE-2006-2734 | enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote attackers to conduct password guessing attacks by setting the guvenlik parameter to the same value as the hidden gguvenlik parameter, which bypasses a verification step because the gguvenlik parameter is assumed to be immutable by the attacker. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61675 | CVE-2006-2991 | Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2 allow remote attackers to inject arbitrary web script or HTML via a JavaScript URI in the SRC attribute of an IMG element, and possibly other manipulations, in the ringid parameter in (1) next.cgi, (2) stats.cgi, or (3) list.cgi. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
61931 | CVE-2006-3252 | Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
62187 | CVE-2006-3513 | danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
62443 | CVE-2006-3775 | SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER["HTTP_CLIENT_IP"] variable), as utilized by index.php. | 2 | 7.5 | High | 2016-12-20 | 2011-08-08 | View |
Page 16310 of 17672, showing 5 records out of 88360 total, starting on record 81546, ending on 81550