NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60601  CVE-2006-1896  Unspecified vulnerability in phpBB allows remote authenticated users with Administration Panel access to execute arbitrary PHP code via crafted Font Colour 3 ($theme[fontcolor3] variable) and/or signature values, possibly involving the highlight functionality. NOTE: the original report does not clarify whether this issue is static code injection, eval injection, or another type of vulnerability.    Medium  2016-12-20  2008-09-05  View
61881  CVE-2006-3202  The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain configurations, does not check to see if IPv4-mapped sockets are being used before processing IPv6 socket options, which allows local users to cause a denial of service (crash) by creating an IPv4-mapped IPv6 socket with the SO_TIMESTAMP socket option set, then sending an IPv4 packet through the socket.    4.9  Medium  2016-12-20  2008-09-05  View
62393  CVE-2006-3725  Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLMSYSTEMCurrentControlSetServicesSNDSrvc and (2) HKLMSYSTEMCurrentControlSetServicesSymEvent registry keys.    2.1  Low  2016-12-20  2008-09-05  View
62905  CVE-2006-4266  Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegRestoreKey to modify HKLMSOFTWARESymantecCCPDSuiteOwners, as demonstrated using NISProd.dll. NOTE: in most cases, this attack would not cross privilege boundaries, because modifying the SuiteOwners key requires administrative privileges. However, this issue is a vulnerability because the product"s functionality is intended to protect against privileged actions such as this.    3.6  Low  2016-12-20  2008-09-05  View
63673  CVE-2006-5067  ** DISPUTED ** PHP remote file inclusion vulnerability in loader.php in PHP System Administration Toolkit (PHPSaTK) allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config] parameter. NOTE: this issue is disputed by CVE; analysis shows that the GLOBALS[config] variable is initialized before being used.    7.5  High  2016-12-20  2008-09-05  View

Page 17215 of 17672, showing 5 records out of 88360 total, starting on record 86071, ending on 86075

Actions