NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 59418 | CVE-2006-0687 | process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote attackers to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View | |
| 59674 | CVE-2006-0947 | Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 59930 | CVE-2006-1216 | Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 60186 | CVE-2006-1477 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
| 60442 | CVE-2006-1737 | Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression. | 2 | 9.3 | High | 2016-12-20 | 2011-03-07 | View |
Page 2179 of 17672, showing 5 records out of 88360 total, starting on record 10891, ending on 10895