NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61255 | CVE-2006-2560 | Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter, which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | 2 | 7.5 | High | 2016-12-20 | 2013-01-24 | View | |
61511 | CVE-2006-2826 | SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61767 | CVE-2006-3084 | The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check return codes for setuid calls, which might allow local users to gain privileges by causing setuid to fail to drop privileges. NOTE: as of 20060808, it is not known whether an exploitable attack scenario exists for these issues. | 2 | 7.2 | High | 2016-12-20 | 2011-07-25 | View | |
62023 | CVE-2006-3345 | Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and earlier, allows remote attackers to inject arbitrary web script or HTML via a chat line. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
62279 | CVE-2006-3605 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 16579 of 17672, showing 5 records out of 88360 total, starting on record 82891, ending on 82895