Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,896 CVEs tagged with CWE-201,634 Critical, 5,054 High, 5,683 Medium, 521 Low, 4 Unrated.

CVE-2007-0103

Published Jan 9, 2007

The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite lo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0104

Published Jan 9, 2007

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to h…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5265

Published Dec 31, 2006

Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5867

Published Dec 31, 2006

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5974

Published Dec 31, 2006

fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6852

Published Dec 31, 2006

Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to inco…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6653

Published Dec 20, 2006

The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5872

Published Dec 18, 2006

login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6581

Published Dec 15, 2006

PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLoc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6383

Published Dec 10, 2006

PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and open_basedir restrictions via a malicious path and a null byte before a ";" in a session_save_path argument, followed…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6241

Published Dec 3, 2006

Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to cause a denial of service (crash) via consecutive RETR commands. NOTE: The provenance of this information i…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6168

Published Nov 29, 2006

tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email fiel…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5990

Published Nov 21, 2006

VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when server certificate verification is enabled, does not verify t…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5793

Published Nov 17, 2006

The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attac…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5938

Published Nov 16, 2006

Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors involving an uninitialized variable and a crafted CAB file.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5313

Published Oct 17, 2006

Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message paramete…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4842

Published Oct 12, 2006

The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from se…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5084

Published Sep 29, 2006

Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4935

Published Sep 23, 2006

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4936

Published Sep 23, 2006

Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4541

Published Sep 5, 2006

RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtO…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4466

Published Aug 31, 2006

Joomla! before 1.0.11 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4468

Published Aug 31, 2006

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to unvalidated input, allow attackers to have an unknown impact via unspecified vectors involving the (1) mo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,726-12,750 of 12,896 CVEsPage 510 of 516