NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61593 | CVE-2006-2909 | Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61849 | CVE-2006-3170 | CS-Forum before 0.82 allows remote attackers to obtain sensitive information via unspecified manipulations, possibly involving an empty collapse[] or readall parameter to index.php, which reveals the installation path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
62105 | CVE-2006-3427 | Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
62361 | CVE-2006-3693 | Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
62617 | CVE-2006-3959 | SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 17065 of 17672, showing 5 records out of 88360 total, starting on record 85321, ending on 85325