CVE-2006-6942
- EPSS 1.92%
- Veröffentlicht 19.01.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1) a comment for a table name, as exploited through (a) db_operations.php, (2) the db parameter to (b)...
CVE-2006-6499
- EPSS 13.71%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers ...
CVE-2006-6500
- EPSS 37.53%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting...
CVE-2006-6501
- EPSS 26.24%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
CVE-2006-6503
- EPSS 10.29%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: ...
CVE-2006-6614
- EPSS 0.07%
- Veröffentlicht 18.12.2006 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts whe...
CVE-2006-5873
- EPSS 1.51%
- Veröffentlicht 12.12.2006 00:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
CVE-2006-5868
- EPSS 1.17%
- Veröffentlicht 22.11.2006 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.
CVE-2006-5170
- EPSS 3.51%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the...
CVE-2006-4343
- EPSS 7.85%
- Veröffentlicht 28.09.2006 18:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer derefer...