NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60386 | CVE-2006-1681 | Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60642 | CVE-2006-1937 | Multiple unspecified vulnerabilities in Ethereal 0.10.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via (1) multiple vectors in H.248, and the (2) X.509if, (3) SRVLOC, (4) H.245, (5) AIM, and (6) general packet dissectors; and (7) the statistics counter. | 2 | 5 | Medium | 2016-12-20 | 2011-09-06 | View | |
60898 | CVE-2006-2194 | The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges. | 2 | 7.2 | High | 2016-12-20 | 2010-04-02 | View | |
61154 | CVE-2006-2459 | SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View | |
61410 | CVE-2006-2725 | SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 6.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 17500 of 17672, showing 5 records out of 88360 total, starting on record 87496, ending on 87500