NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61000 | CVE-2006-2297 | Heap-based buffer overflow in Microsoft Infotech Storage System Library (itss.dll) allows user-assisted attackers to execute arbitrary code via a crafted CHM / ITS file that triggers the overflow while decompiling. | 2 | 4 | Medium | 2016-12-20 | 2011-10-18 | View | |
61256 | CVE-2006-2561 | Edimax BR-6104K router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified InternalClient parameter (possibly within NewInternalClient), which is not validated, as demonstrated by using AddPortMapping to forward arbitrary traffic. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
61512 | CVE-2006-2827 | ** DISPUTED ** SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue in a comment on the original researcher"s blog, saying "the bug does not impose any security threat and remote attackers can"t add, modify, or delete information in the back-end database by sending specially-crafted SQL statements to the search.php script using various search parameters." As of 20060605, the original blog entry is unavailable, although ISS also reports the same dispute. CVE has not been able to investigate this issue further, although the researcher sometimes makes inaccurate claims. | 2 | 6.4 | Medium | 2016-12-20 | 2008-11-09 | View | |
61768 | CVE-2006-3085 | xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers to cause a denial of service (infinite loop) via an SCTP chunk with a 0 length. | 2 | 7.8 | High | 2016-12-20 | 2011-03-07 | View | |
62024 | CVE-2006-3346 | SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View |
Page 414 of 17672, showing 5 records out of 88360 total, starting on record 2066, ending on 2070