NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
61403  CVE-2006-2718  JIWA Financials 6.4.14 passes a Microsoft SQL Server account"s username and password, and the name of a data source, to a Crystal Reports .rpt file, which allows remote authenticated users to execute certain standard stored procedures by referencing them in a user-written .rpt file, as demonstrated by using a stored procedure that provides the username and cleartext password of every account.    6.5  Medium  2016-12-20  2008-09-05  View
62171  CVE-2006-3497  Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive.    5.1  Medium  2016-12-20  2011-04-07  View
62427  CVE-2006-3759  Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related has unspecified impact and attack vectors related to "user group manipulation."    Medium  2016-12-20  2008-09-05  View
63195  CVE-2006-4562  ** DISPUTED ** The proxy DNS service in Symantec Gateway Security (SGS) allows remote attackers to make arbitrary DNS queries to third-party DNS servers, while hiding the source IP address of the attacker. NOTE: another researcher has stated that the default configuration does not proxy DNS queries received on the external interface.    Medium  2016-12-20  2008-09-05  View
64475  CVE-2006-5900  Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.    6.8  Medium  2016-12-20  2008-09-05  View

Page 16396 of 17672, showing 5 records out of 88360 total, starting on record 81976, ending on 81980

Actions