- EPSS 17.06%
- Published 13.02.2007 23:28:00
- Last modified 09.04.2025 00:30:58
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element ...
CVE-2007-0455
- EPSS 4.93%
- Published 30.01.2007 17:28:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded...
CVE-2006-6143
- EPSS 28.98%
- Published 31.12.2006 05:00:00
- Last modified 09.04.2025 00:30:58
The RPC library in Kerberos 5 1.4 through 1.4.4, and 1.5 through 1.5.1, as used in Kerberos administration daemon (kadmind) and other products that use this library, calls an uninitialized function pointer in freed memory, which allows remote attacke...
CVE-2006-7232
- EPSS 1.89%
- Published 31.12.2006 05:00:00
- Last modified 09.04.2025 00:30:58
sql_select.cc in MySQL 5.0.x before 5.0.32 and 5.1.x before 5.1.14 allows remote authenticated users to cause a denial of service (crash) via an EXPLAIN SELECT FROM on the INFORMATION_SCHEMA table, as originally demonstrated using ORDER BY.
CVE-2006-6811
- EPSS 5.48%
- Published 29.12.2006 11:28:00
- Last modified 09.04.2025 00:30:58
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference. NOTE: this issue...
CVE-2006-6499
- EPSS 13.71%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers ...
CVE-2006-6500
- EPSS 37.53%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting...
CVE-2006-6501
- EPSS 26.24%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
CVE-2006-6503
- EPSS 10.29%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: ...
CVE-2006-6504
- EPSS 41.55%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.