NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60719 | CVE-2006-2014 | Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
60975 | CVE-2006-2272 | Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks. | 2 | 7.8 | High | 2016-12-20 | 2011-03-07 | View | |
61231 | CVE-2006-2536 | Cross-site scripting (XSS) vulnerability in Destiney Links Script 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) "Search" (term parameter in index.php) and (2) "Add a Site" (add.php) fields. | 2 | 5.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
61487 | CVE-2006-2802 | Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6. | 2 | 5 | Medium | 2016-12-20 | 2016-11-18 | View | |
61743 | CVE-2006-3060 | Cross-site scripting (XSS) vulnerability in P.A.I.D 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) read parameter in index.php, (2) farea parameter in faq.php, and (3) unspecified input fields on the "My Account" login page. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16439 of 17672, showing 5 records out of 88360 total, starting on record 82191, ending on 82195