NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60409  CVE-2006-1704  Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.    Medium  2016-12-20  2008-09-05  View
60665  CVE-2006-1960  Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.    5.8  Medium  2016-12-20  2011-03-07  View
61177  CVE-2006-2482  Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive vector is covered by CVE-2005-2856.    6.8  Medium  2016-12-20  2011-10-17  View
61433  CVE-2006-2748  SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple vectors, as demonstrated by the (1) type parameter in adminfunctions.php and the (2) catalogue_id parameter in editcatalogue.php.    6.4  Medium  2016-12-20  2008-09-05  View
61689  CVE-2006-3005  The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.    Medium  2016-12-20  2008-09-05  View

Page 17462 of 17672, showing 5 records out of 88360 total, starting on record 87306, ending on 87310

Actions