Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 269

Количество 374 269

nvd логотип

CVE-2006-0389

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-0388

больше 20 лет назад

Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2006-0387

больше 20 лет назад

Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2006-0386

больше 20 лет назад

FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.

CVSS2: 1.7
EPSS: Низкий
nvd логотип

CVE-2006-0384

больше 20 лет назад

automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-0383

больше 20 лет назад

IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0382

больше 20 лет назад

Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-0381

больше 20 лет назад

A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0380

больше 20 лет назад

A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-0379

больше 20 лет назад

FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2006-0378

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the affected program might be installation-dependent, but it has been identified as "product_details.php" by some sources.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-0377

больше 20 лет назад

CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0376

больше 20 лет назад

The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2006-0375

больше 20 лет назад

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0374

больше 20 лет назад

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-0373

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-0372

больше 20 лет назад

Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2006-0371

больше 20 лет назад

Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0370

больше 20 лет назад

Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-0369

больше 20 лет назад

MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-0389

Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.

CVSS2: 2.6
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0388

Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.

CVSS2: 2.6
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0387

Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.

CVSS2: 6.4
8%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0386

FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.

CVSS2: 1.7
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0384

automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".

CVSS2: 7.5
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0383

IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".

CVSS2: 5
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0382

Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0381

A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub fragment crop' or 'scrub fragment drop-ovl' rule is being used, allows remote attackers to cause a denial of service (crash) via crafted packets that cause a packet fragment to be inserted twice.

CVSS2: 5
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0380

A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which causes more data to be copied to userland than intended, which could allow local users to read portions of kernel memory.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0379

FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which could allow local users to read portions of kernel memory.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0378

Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the affected program might be installation-dependent, but it has been identified as "product_details.php" by some sources.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0377

CRLF injection vulnerability in SquirrelMail 1.4.0 to 1.4.5 allows remote attackers to inject arbitrary IMAP commands via newline characters in the mailbox parameter of the sqimap_mailbox_select command, aka "IMAP injection."

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0376

The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does not warn the user when (1) it establishes an association with a station in ad hoc (aka peer-to-peer) mode or (2) a station in ad hoc mode establishes an association with it, which allows remote attackers to put unexpected wireless communication into place.

CVSS2: 7.5
18%
Средний
больше 20 лет назад
nvd логотип
CVE-2006-0375

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0374

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging ONCRPC (aka wdbrpc) on UDP 17185, (2) reflect network data using echo (TCP 7), or (3) gain access without authentication using rlogin (TCP 513).

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0373

Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0372

Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0371

Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter.

CVSS2: 5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0370

Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2006-0369

MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired aspect of database access

CVSS2: 2.1
1%
Низкий
больше 20 лет назад

Уязвимостей на страницу