NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
60438 | CVE-2006-1733 | Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inserting an XBL method into the DOM"s document.body prototype chain." | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
60694 | CVE-2006-1989 | Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers. | 2 | 5.1 | Medium | 2016-12-20 | 2011-03-07 | View | |
60950 | CVE-2006-2247 | WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61206 | CVE-2006-2511 | The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extension that is not associated with an application, and selecting a file from the "Open With..." dialog. | 2 | 6.5 | Medium | 2016-12-20 | 2008-09-05 | View | |
61718 | CVE-2006-3034 | MyScrapbook 3.1 allows remote attackers to obtain sensitive information via a direct request to files in the txt-db-api directory such as txt-db-api/sql.php, which reveals the path in an error message. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 825 of 17672, showing 5 records out of 88360 total, starting on record 4121, ending on 4125