NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
62363  CVE-2006-3695  Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.    6.8  Medium  2016-12-20  2011-03-16  View
62619  CVE-2006-3961  Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.    6.8  Medium  2016-12-20  2011-03-07  View
62875  CVE-2006-4234  PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.    7.5  High  2016-12-20  2011-03-07  View
63131  CVE-2006-4496  Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.    4.3  Medium  2016-12-20  2008-09-05  View
63387  CVE-2006-4763  IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client"s Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user"s privileges by intercepting the LtpaToken cookie.    7.5  High  2016-12-20  2008-09-05  View

Page 907 of 17672, showing 5 records out of 88360 total, starting on record 4531, ending on 4535

Actions