Export limit exceeded: 29911 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (29911 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2006-3763 1 Dieselscripts 1 Diesel Joke Site 2025-04-03 N/A
SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2006-2713 1 Secure Elements 1 C5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates predictable CEIDs, which allows remote attackers to determine the CEID of a protected asset, which can be used in other attacks against AVR.
CVE-2006-2712 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.
CVE-2006-3764 1 Till Gerken 1 Phppolls 2025-04-03 N/A
Till Gerken phpPolls 1.0.3 allows remote attackers to create a new poll via a direct request to phpPollAdmin.php3 with the poll_action parameter set to create.
CVE-2006-2711 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and possibly later 2.8.x releases, uses the same initialization vector and key for each message session, which allows remote attackers to obtain potentially sensitive information about messages.
CVE-2006-3765 1 Huttenlocher Webdesign 1 Hwdeguest 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the "name input" field in new_entry.php.
CVE-2005-2918 1 Gtkdiskfree 1 Gtkdiskfree 2025-04-03 N/A
The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.
CVE-2006-2710 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same invariant RSA key for all installations, which allows remote attackers with the key to decrypt communications.
CVE-2006-2709 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate the source address of a message, which allows remote attackers to (1) execute arbitrary code on a client or (2) forge messages to the server.
CVE-2006-2708 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows remote attackers to read portions of process memory via a modified size for (1) EM_GET_CE_PARAMETER and (2) EM_SET_CE_PARAMETER messages, which leads to a buffer overflow (probably an over-read).
CVE-2006-2707 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not validate the peer certificate when obtaining an update, which could allow remote attackers to distribute malicious updates to clients.
CVE-2006-3766 1 Darrens 5-dollar Script Archive 1 Osdate 2025-04-03 N/A
Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10.
CVE-2006-3767 1 Darrens 5-dollar Script Archive 1 Osdate 2025-04-03 N/A
Cross-site scripting (XSS) vulnerability in showprofile.php in Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file in txtcomment parameter, which is used when posting a comment.
CVE-2006-2706 1 Secure Elements 1 Class 5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause a denial of service via forged "session start" messages that cause AVR to connect to arbitrary hosts.
CVE-2006-2705 1 Secure Elements 1 C5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows remote attackers to cause an unspecified denial of service via a large number of forged client registration messages.
CVE-2006-2704 1 Secure Elements 1 C5 Enterprise Vulnerability Management 2025-04-03 N/A
Secure Elements Class 5 AVR server and client (aka C5 EVM) before 2.8.1 send messages in cleartext, which allows remote attackers to read sensitive vulnerability information.
CVE-2006-3768 1 Intervations 1 Filecopa 2025-04-03 N/A
Integer underflow in filecpnt.exe in FileCOPA FTP Server 1.01 before 2006-07-21 allow remote authenticated users to execute arbitrary code via a long argument to the (1) CWD, (2) DELE, (3) MDTM, and (4) MKD commands, which triggers a stack-based buffer overflow.
CVE-2006-2703 1 Suse 1 Suse Linux 2025-04-03 N/A
The RedCarpet command-line client (rug) does not verify SSL certificates from a server, which allows remote attackers to read network traffic and execute commands via a man-in-the-middle (MITM) attack.
CVE-2006-2702 1 Wordpress 1 Wordpress 2025-04-03 N/A
vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR'].
CVE-2006-2701 1 Geeklog 1 Geeklog 2025-04-03 N/A
SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to story submission.