NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 63051 | CVE-2006-4416 | Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 and 5.3 allows local users to gain privileges by modifying the path to point to a malicious (1) chdev, (2) mkboot, (3) varyonvg, or (4) varyoffvg program. | 2 | 7.2 | High | 2016-12-20 | 2011-03-07 | View | |
| 63307 | CVE-2006-4674 | Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 64075 | CVE-2006-5474 | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
| 64587 | CVE-2006-6026 | Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request that contains an invalid LoadTestPassword field. | 2 | 10 | High | 2016-12-20 | 2011-10-18 | View | |
| 64843 | CVE-2006-6282 | members.php in Vikingboard 0.1.2 allows remote attackers to trigger a forced SQL error via an invalid s parameter, a different vector than CVE-2006-4709. NOTE: might only be an exposure if display_errors is enabled, but due to lack of details, even this is not clear. | 2 | 9.3 | High | 2016-12-20 | 2008-09-05 | View |
Page 2360 of 17672, showing 5 records out of 88360 total, starting on record 11796, ending on 11800