CVE-2006-6503
- EPSS 17.11%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: ...
CVE-2006-6504
- EPSS 41.55%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
CVE-2006-5868
- EPSS 1.46%
- Veröffentlicht 22.11.2006 01:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafted SGI image.
CVE-2006-5779
- EPSS 43.37%
- Veröffentlicht 07.11.2006 18:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
OpenLDAP before 2.3.29 allows remote attackers to cause a denial of service (daemon crash) via LDAP BIND requests with long authcid names, which triggers an assertion failure.
CVE-2006-5173
- EPSS 0.07%
- Veröffentlicht 17.10.2006 22:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignmen...
CVE-2006-4997
- EPSS 35.02%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (f...
CVE-2006-5158
- EPSS 4.05%
- Veröffentlicht 05.10.2006 04:04:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference...
CVE-2006-4343
- EPSS 6.93%
- Veröffentlicht 28.09.2006 18:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer derefer...
CVE-2006-4095
- EPSS 4.88%
- Veröffentlicht 06.09.2006 00:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
CVE-2006-4482
- EPSS 4.1%
- Veröffentlicht 31.08.2006 21:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990...