NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
59388  CVE-2006-0657  Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS.    3.5  Low  2016-12-20  2011-03-07  View
59644  CVE-2006-0917  Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP headers and possibly gain sensitive information, such as credentials, by setting up a listening port and reading the credentials when the victim clicks on the link.    2.1  Low  2016-12-20  2008-09-05  View
59900  CVE-2006-1185  Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.    7.5  High  2016-12-20  2011-03-07  View
60156  CVE-2006-1447  LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.    Medium  2016-12-20  2011-03-07  View
60412  CVE-2006-1707  index.php in Shopweezle 2.0 allows remote attackers to include arbitrary local files via the url parameter.    Medium  2016-12-20  2008-11-03  View

Page 17489 of 17672, showing 5 records out of 88360 total, starting on record 87441, ending on 87445

Actions