Primary Vendor -- Product | Description | | CVSS Score | Source & Patch Info | Apple -- Mac OS X
| Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information. | | 2.3 | CVE-2006-1468 APPLE FRSIRT BID BID SECTRACK
| Apple -- Mac OS X Server Apple -- Mac OS X
| OpenLDAP Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error. | | 2.3 | CVE-2006-1470 APPLE FRSIRT CERT-VN BID BID SECTRACK
| Apple -- Safari
| Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself. | | 2.7 | CVE-2006-3224 FULLDISC XF
| Azureus Tracker -- Azureus Tracker
| Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus Tracker 2.4.0.2 and earlier (Java BitTorrent Client Tracker) allows remote attackers to inject arbitrary web script or HTML via the search parameter. | | 1.9 | CVE-2006-3230 OTHER-REF FRSIRT SECUNIA SECTRACK
| BNBT -- TrinEdit BNBT -- EasyTracker
| Multiple cross-site scripting (XSS) vulnerabilities in index.html in BNBT TrinEdit and EasyTracker 7.7r3.2004.10.27 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) filter or (2) sort parameters. | | 1.9 | CVE-2006-3258 BLOGSPOT SECUNIA FRSIRT SECTRACK
| Cisco -- Wireless Control System
| Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a directory path name that contains a space character, allows remote authenticated users to read and overwrite arbitrary files via unspecified vectors. | | 2.3 | CVE-2006-3288 CISCO BID FRSIRT SECTRACK SECUNIA XF
| Cisco -- Wireless Control System
| Cross-site scripting (XSS) vulnerability in the login page of the HTTP interface for the Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a "malicious URL". | | 1.9 | CVE-2006-3289 CISCO BID FRSIRT SECTRACK SECUNIA XF
| Cisco -- Wireless Control System
| HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request. | | 2.3 | CVE-2006-3290 CISCO BID FRSIRT SECTRACK SECUNIA XF
| cjGuestbook -- cjGuestbook
| Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments parameter. | | 2.3 | CVE-2006-3211 BUGTRAQ FRSIRT SECUNIA BID XF
| cjGuestbook -- cjGuestbook
| Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject web script or HTML via the (1) name, (2) email, (3) add, and (4) wName parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | | 2.3 | CVE-2006-3212 BID FRSIRT SECUNIA XF
| Claroline -- Claroline
| Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7 allow remote attackers to inject arbitrary HTML or web script via unspecified attack vectors, possibly including (1) calendar/myagenda.php, (2) document/document.php, (3) phpbb/newtopic.php, (4) tracking/userLog.php, and (5) wiki/page.php. | | 2.3 | CVE-2006-3257 BUGTRAQ OTHER-REF
| Clearswift -- MAILsweeper for SMTP Clearswift -- MAILsweeper for Exchange
| Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed messages, which causes "unpredictable behavior" that prevents the Security service from processing more messages. | | 2.3 | CVE-2006-3216 MIMESWEEPER BID FRSIRT SECUNIA XF
| datetopia -- Dating Agent PRO
| requirements.php in Dating Agent PRO 4.7.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | | 2.3 | CVE-2006-3282 BUGTRAQ FRSIRT SECUNIA
| datetopia -- Dating Agent PRO
| Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in (1) webmaster/index.php and (2) search.php. | | 1.9 | CVE-2006-3284 BUGTRAQ FRSIRT SECUNIA XF
| dotProject -- dotProject
| Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter. | | 1.9 | CVE-2006-3240 OTHER-REF OTHER-REF OTHER-REF FRSIRT SECUNIA BID
| e107.org -- e107 website system
| Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment). | | 2.3 | CVE-2006-3259 BUGTRAQ BID FRSIRT SECUNIA
| Fortinet -- FortiOS
| The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode. | | 2.3 | CVE-2006-3222 OTHER-REF BID FRSIRT SECUNIA
| George Currums -- Open Guestbook
| Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | | 2.3 | CVE-2006-3295 BUGTRAQ BID XF
| GL-SH -- Deaf Forum
| Cross-site scripting (XSS) vulnerability in show.php in GL-SH Deaf Forum 6.4.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the sort parameter. | | 1.9 | CVE-2006-3246 OTHER-REF FRSIRT SECUNIA
| GL-SH -- Deaf Forum
| Multiple cross-site scripting (XSS) vulnerabilities in show.php in GL-SH Deaf Forum 6.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) page, and (3) action parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | | 1.9 | CVE-2006-3247 OTHER-REF FRSIRT SECUNIA
| Hitachi -- Groupmax Address Server Hitachi -- Groupmax Mail Server
| Unspecified vulnerability in Hitachi Groupmax Address Server 7 and earlier, and Groupmax Mail Server 7 and earlier allows remote attackers to cause a denial of service (product "stop") via unspecified vectors involving "unexpected requests". | | 2.3 | CVE-2006-3214 HITACHI FRSIRT SECTRACK SECUNIA XF
| IBM -- Websphere Application Server
| Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 allows remote attackers to obtain the source code of JSP files via unknown vectors. | | 2.3 | CVE-2006-3231 OTHER-REF BID FRSIRT SECUNIA
| JaguarSoft -- JaguarEdit
| JaguarEditControl (JEdit) ActiveX Control 1.1.0.20 and earlier allows remote attackers to obtain sensitive information, such as the username and MAC and IP addresses, by setting the test field to certain values such as 2404 or 2790, then reading the information from the .JText field. | | 1.9 | CVE-2006-3217 BUGTRAQ SRLABS SRLABS BID FRSIRT SECUNIA XF
| Jelsoft -- vBulletin
| Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. | | 1.9 | CVE-2006-3253 BUGTRAQ SECTRACK
| Jon Link -- Some Chess
| Cross-site request forgery (CSRF) vulnerability in menu.php in Some Chess 1.5 rc2 allows remote attackers to conduct actions as another user, such as changing usernames and passwords, via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | | 2.3 | CVE-2006-3272 SECUNIA
| Jon Link -- Some Chess
| Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 rc1 allows remote attackers to inject arbitrary web script or HTML via the user parameter ("New Name" field). | | 1.9 | CVE-2006-3273 BUGTRAQ SECTRACK SECUNIA XF
| Lanap BotDetect -- CAPTCHA ASP.NET
| The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by "replaying the ViewState for a known number." | | 2.3 | CVE-2006-2918 BUGTRAQ BID OTHER-REF FRSIRT SECUNIA SECTRACK XF
| Linux -- Linux kernel
| The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors. | | 1.6 | CVE-2006-0456 OTHER-REF OTHER-REF OTHER-REF OTHER-REF DEBIAN FRSIRT BID
| Linux -- Linux kernel
| Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signal_64.c) and cause a denial of service (crash) and possibly read kernel memory on 32-bit systems (signal_32.c). | | 3.7 | CVE-2006-2448 OTHER-REF OTHER-REF OTHER-REF BID FRSIRT BUGTRAQ TRUSTIX SECUNIA
| LookNet -- FineShop
| Multiple cross-site scripting (XSS) vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc parameters. | | 1.9 | CVE-2006-3235 OTHER-REF SECTRACK XF
| MailEnable -- MailEnable
| The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument. | | 2.3 | CVE-2006-3277 BUGTRAQ OTHER-REF OTHER-REF BID FRSIRT SECTRACK SECUNIA OTHER-REF XF
| MetalheadWs -- Usenet
| Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary web script or HTML via the group parameter. | | 2.3 | CVE-2006-3299 BUGTRAQ BID FRSIRT SECUNIA
| mvnForum -- mvnForum
| Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters. | | 1.9 | CVE-2006-3245 OTHER-REF SECUNIA BID FRSIRT XF
| Namo -- DeepSearch
| Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo DeepSearch 4.5 allows remote attackers to inject arbitrary web script or HTML via the p parameter. | | 1.9 | CVE-2006-3264 BUGTRAQ OTHER-REF BID FRSIRT SECTRACK SECUNIA XF
| Netsoft -- smartNet
| Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter. | | 2.3 | CVE-2006-3313 BUGTRAQ OTHER-REF BID OTHER-REF SECTRACK XF
| New Atlanta Communications -- BlueDragon Server JX New Atlanta Communications -- BlueDragon Server
| BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a dneial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2. | | 2.3 | CVE-2006-2310 OTHER-REF FRSIRT SECUNIA BID
| New Atlanta Communications -- BlueDragon Server JX New Atlanta Communications -- BlueDragon Server
| Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page. | | 1.9 | CVE-2006-2311 OTHER-REF FRSIRT SECUNIA
| Novell -- Groupwise
| Unspecified vulnerability in the Windows Client API in Novell GroupWise 5.x through 7 might allow users to obtain "random programmatic access" to other email within the same post office. | | 2.3 | CVE-2006-3268 OTHER-REF OTHER-REF OTHER-REF BID FRSIRT SECUNIA
| Open WebMail -- Open WebMail
| Cross-site scripting (XSS) vulnerability in OpenWebMail (OWM) 2.52, and other versions released before 05/12/2006, allows remote attackers to inject arbitrary web script or HTML via the (1) To and (2) From fields in openwebmail-main.pl, and possibly (3) other unspecified vectors related to "openwebmailerror calls that need to display HTML." | | 2.3 | CVE-2006-3229 OTHER-REF OTHER-REF MLIST
| Open WebMail -- Open WebMail
| Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in OpenWebMail (OWM) 2.52, and other versions released before 06/18/2006, allows remote attackers to inject arbitrary web script or HTML via the from field. NOTE: some third party sources have mentioned the "to" and "from" fields, although CVE analysis shows that these are associated with the previous version, a different executable, and a different CVE. | | 2.3 | CVE-2006-3233 MLIST OTHER-REF OTHER-REF BID
| phpQLAdmin -- phpQLAdmin
| Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin 2.2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) user_add.php or (2) unit_add.php. | | 2.3 | CVE-2006-3301 OTHER-REF BID FRSIRT SECUNIA XF
| Positive Software -- H-Sphere
| Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) next_template, (2) start, (3) curr_menu_id, and (4) arid parameters in psoft/servlet/resadmin/psoft.hsphere.C when using the mailman/massmail.html template_name. | | 1.9 | CVE-2006-3278 OTHER-REF FRSIRT SECUNIA
| Proton -- EnergyMech IRC Bot
| parse_notice (TiCPU) in EnergyMech (emech) before 3.0.2 allows remote attackers to cause a denial of service (crash) via empty IRC CTCP NOTICE messages. | | 2.3 | CVE-2006-3293 OTHER-REF GENTOO BID FRSIRT SECUNIA SECUNIA XF
| QaTraq -- QaTraq
| Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, and (6) link_list parameters in top.inc as included by queries_view_search.php; the (7) msg, (8) component_name, and (9) component_desc parameters in (a) components_copy_content.php, (b) components_modify_content.php, and (c) components_new_content.php; the (10) title, (11) version, and (12) content parameters in design_copy_content.php; the (13) plan_title and (14) plan_content parameters in design_copy_plan_search.php; the (15) title, (16) minor_version, (17) new_version, and (18) content parameters in design_modify_content.php; the (19) title, (20) version, and (21) content parameters in design_new_content.php; the (22) plan_name and (23) plan_desc parameters in design_new_search.php; the (24) file_name parameter in download.php; the (25) username and (26) password parameters in login.php; the (27) title, (28) version, and (29) content parameters in phase_copy_content.php; the (30) content parameter in phase_delete_search.php; the (31) title, (32) minor_version, (33) new_version, and (34) content parameters in phase_modify_content.php; the (35) content, (36) title, (37) version, and (38) content parameters in phase_modify_search.php; the (39) content parameter in phase_view_search.php; the (40) msg, (41) product_name, and (42) product_desc parameters in products_copy_content.php; and possibly the (43) product_name and (44) product_desc parameters in (d) products_copy_search.php, and a large number of additional parameters and executables. | | 2.3 | CVE-2006-3312 BUGTRAQ OTHER-REF BID
| Qdig -- Qdig
| Multiple cross-site scripting (XSS) vulnerabilities in index.php in Qdig before 1.2.9.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pre_gallery or (2) post_gallery parameters. | | 1.9 | CVE-2006-3265 OTHER-REF FRSIRT SECUNIA
| Senokian Solutions -- Enterprise Groupware Systems
| Cross-site scripting (XSS) vulnerability in index.php in Enterprise Groupware System (EGS) 1.2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter. | | 1.9 | CVE-2006-3237 OTHER-REF BID FRSIRT SECTRACK SECUNIA XF
| Sun -- ONE Application Server Sun -- Java System Application Server
| Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java System Application Server Enterprise Edition 8.1 2005 Q1 allows remote attackers to inject arbitrary HTML or web script via unknown vectors. | | 1.9 | CVE-2006-3225 SUNALERT FRSIRT BID SECTRACK SECUNIA XF
| Trend Micro -- Control Manager
| Cross-site scripting (XSS) vulnerability in Trend Micro Control Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web script or HTML via the username field on the login page, which is not properly sanitized before being displayed in the error log. | | 2.3 | CVE-2006-3261 BUGTRAQ BID FRSIRT SECTRACK SECUNIA XF
| UebiMiau -- UebiMiau
| Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau Webmail 2.7.10, and 2.7.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) f_user parameter in index.php, the (2) pag parameter in messages.php, or the (3) lid, (4) tid, and (5) sid parameters in error.php. | | 2.3 | CVE-2006-3305 OTHER-REF BID FRSIRT SECUNIA XF
| Virtual Design Studios -- vlbook
| Cross-site scripting (XSS) vulnerability in index.php in vlbook 1.02 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | | 2.3 | CVE-2006-3260 BUGTRAQ ALTERVISTA BID SECUNIA FRSIRT
| Webmin -- Webmin
| Directory traversal vulnerability in Webmin before 1.280, when run on Windows, allows remote attackers to read arbitrary files via \ (backslash) characters in the URL to certain directories under the web root, such as the image directory. | | 2.3 | CVE-2006-3274 BUGTRAQ OTHER-REF OTHER-REF OTHER-REF BID FRSIRT SECTRACK SECUNIA
| XennoBB -- XennoBB
| Cross-site scripting (XSS) vulnerability in messages.php in XennoBB 1.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the tid parameter. | | 1.9 | CVE-2006-3241 OTHER-REF FRSIRT SECUNIA
| Yahoo -- Yahoo! Messenger
| Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll. | | 2.3 | CVE-2006-3298 OTHER-REF BID SECUNIA XF
| Zoid Technologies -- Project Eros bbsengine
| Cross-site scripting (XSS) vulnerability in the preparestring funtion in lib/common.php in Project EROS bbsengine before 20060501-0142-jam, and possibly earlier versions dating back to 2006-02-23, might allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | | 2.3 | CVE-2006-3306 OTHER-REF BID FRSIRT SECUNIA XF
|