NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
60386  CVE-2006-1681  Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated.    4.3  Medium  2016-12-20  2011-03-07  View
60642  CVE-2006-1937  Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter.    Medium  2016-12-20  2011-09-06  View
60898  CVE-2006-2194  The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.    7.2  High  2016-12-20  2010-04-02  View
61154  CVE-2006-2459  SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter.    6.4  Medium  2016-12-20  2011-03-07  View
61410  CVE-2006-2725  SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.    6.4  Medium  2016-12-20  2011-03-07  View

Page 17500 of 17672, showing 5 records out of 88360 total, starting on record 87496, ending on 87500

Actions