Primary Vendor -- Product | Description | | CVSS Score | Source & Patch Info | 3Com -- TippingPoint IPS
| TippingPoint IPS running the TippingPoint Operating System (TOS) before 2.2.4.6519 allows remote attackers to "force the device into layer 2 fallback (L2FB)", causing a denial of service (page fault), via a malformed packet. | | 2.3 | CVE-2006-3678 BUGTRAQ OTHER-REF BID FRSIRT
| AdventNet -- Zoho Virtual Office
| Cross-site scripting (XSS) vulnerability in Zoho Virtual Office 3.2 Build 3210 allows remote attackers to execute arbitrary web script or HTML via an HTML message. | | 2.3 | CVE-2006-3842 BUGTRAQ BID SECUNIA
| Amazing Flash Commerce -- AFCommerce Shopping Cart
| Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the "new review" text box. | | 2.3 | CVE-2006-3800 BUGTRAQ BID XF
| Apache Group -- Tomcat
| Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do. | | 2.3 | CVE-2006-3835 FULLDISC BID XF
| ATutor -- ATutor
| Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in (a) index_list.php and (2) year, (3) month, and (4) day parameter in (b) registration.php. | | 2.3 | CVE-2006-3821 BUGTRAQ BUGTRAQ
| Check Point Software -- Check Point FireWall-1
| Directory traversal vulnerability in Check Point Firewall-1 R55W before HFA03 allows remote attackers to read arbitrary files via an encoded .. (dot dot) in the URL on TCP port 18264. | | 2.3 | CVE-2006-3885 BUGTRAQ OTHER-REF BID FRSIRT XF
| DeluxeBB -- DeluxeBB
| Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php. | | 1.9 | CVE-2006-3795 BUGTRAQ BID FRSIRT SECUNIA XF XF
| DeluxeBB -- DeluxeBB
| DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOKIE) variable, which can overwrite the other variables during an extract function call, probably leading to multiple security vulnerabilities, aka "pollution of the global namespace." | | 2.3 | CVE-2006-3798 BUGTRAQ
| EJ3 Soft -- TOPo
| index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite existing entries and establish new passwords for the overwritten entries via a URL with a modified entry ID. | | 2.3 | CVE-2006-3833 BUGTRAQ
| EJ3 Soft -- TOPo
| EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors. | | 2.3 | CVE-2006-3834 BUGTRAQ
| Ethereal Group -- Ethereal Wireshark -- Wireshark
| Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors. | | 3.3 | CVE-2006-3627 WIRESHARK BUGTRAQ MANDRIVA BID FRSIRT SECUNIA SECUNIA GENTOO SECUNIA SECUNIA
| Ethereal Group -- Ethereal
| Unspecified vulnerability in the MOUNT dissector in Wireshark (aka Ethereal) 0.9.4 to 0.99.0 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. | | 2.3 | CVE-2006-3629 WIRESHARK BUGTRAQ MANDRIVA BID FRSIRT SECUNIA SECUNIA GENTOO SECUNIA SECUNIA
| Ethereal Group -- Ethereal
| Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. | | 3.3 | CVE-2006-3631 WIRESHARK BUGTRAQ MANDRIVA BID FRSIRT SECUNIA SECUNIA GENTOO SECUNIA SECUNIA
| FastJar -- FastJar
| Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC 4.1.1 and earlier, and 3.4.6 and earlier, allows user-assisted attackers to overwrite arbitrary files via a .jar file containing filenames with "../" sequences. | | 1.9 | CVE-2006-3619 OTHER-REF OTHER-REF BID FRSIRT FRSIRT OSVDB SECUNIA SECUNIA
| Gonafish -- LinksCaffe
| Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor parameters in (c) menu.inc.php. | | 2.3 | CVE-2006-3883 BUGTRAQ BID
| ISS -- RealSecure Desktop ISS -- RealSecure Network ISS -- BlackICE Server Protection ISS -- BlackICE PC Protection ISS -- RealSecure Server Sensor ISS -- Proventia Server ISS -- Proventia Desktop ISS -- Proventia
| The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode. | | 1.9 | CVE-2006-3840 OTHER-REF FRSIRT ISS
| Kailash Nadh -- boastMachine
| Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface. | | 2.3 | CVE-2006-3826 BUGTRAQ OTHER-REF FRSIRT SECTRACK SECUNIA
| Kailash Nadh -- boastMachine
| Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote attackers to perform unauthorized actions as an administrator and delete arbitrary user accounts via a delete_user action. | | 2.3 | CVE-2006-3829 BUGTRAQ OTHER-REF SECTRACK SECUNIA
| Kailash Nadh -- boastMachine
| The Languages selection in the admin interface in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allows remote authenticated administrators to upload files with arbitrary extensions to the bmc/Inc/Lang directory. NOTE: because the uploaded files cannot be accessed through HTTP, this issue is a vulnerability only if there is a likely usage pattern in which the files would be opened or executed by local users, e.g., malware files with names that entice local users to open the files. | | 1.4 | CVE-2006-3830 OTHER-REF SECUNIA
| Kailash Nadh -- boastMachine
| The Backup selection in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier uses predicable filenames for database backups and stores the files under the web root with insufficient access control, which allows remote attackers to obtain sensitive information by downloading a backup file. | | 2.3 | CVE-2006-3831 BUGTRAQ OTHER-REF SECTRACK SECUNIA
| Krischan Jodies -- IP Calculator
| Cross-site scripting (XSS) vulnerability in CGI wrapper for IP Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI environment variable), which is used in the actionurl variable. | | 1.9 | CVE-2006-3848 FULLDISC OTHER-REF FRSIRT OSVDB SECUNIA
| Linux-HA -- heartbeat
| heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup. | | 1.6 | CVE-2006-3815 OTHER-REF OTHER-REF
| Microsoft -- Windows 2000 Microsoft -- Windows Server 2003 Microsoft -- Windows XP
| ** DISPUTED ** Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation." | | 2.3 | CVE-2006-3880 BUGTRAQ BID
| Microsoft -- Internet Explorer
| Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property. | | 2.3 | CVE-2006-3897 OTHER-REF BID FRSIRT OSVDB XF
| Miod Vallat -- mikmod
| Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3 through 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xFFFFFF) comment length value in an XCOM chunk. | | 2.3 | CVE-2006-3879 BUGTRAQ OTHER-REF BID
| MusicBox -- MusicBox
| Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI. NOTE: the id parameter in index.php, and the type and show parameters in a top action, are already covered by CVE-2006-1349; and the term parameter in a search action is already covered by CVE-2006-1806. | | 2.3 | CVE-2006-3881 BUGTRAQ XF
| MusicBox -- MusicBox
| Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | | 2.3 | CVE-2006-3882 BUGTRAQ
| Opsware -- Network Automation System
| Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysqll with world-readable permissions, which allows local users to read the root password for the MySQL MAX database. | | 1.6 | CVE-2006-3878 BUGTRAQ BID SECTRACK
| OWASP -- WebScarab
| Cross-site scripting (XSS) vulnerability in WebScarab before 20060718-1904, when used with Microsoft Internet Explorer 6 SP2 or Konqueror 3.5.3, allows remote attackers to inject arbitrary web script or HTML via the URL, which is not sanitized before being returned in an error message when WebScarab is not able to access the URL. | | 1.9 | CVE-2006-3841 BUGTRAQ OTHER-REF SECUNIA
| PHPToys -- Micro Guestbook
| Cross-site scripting (XSS) vulnerability in index.php in Micro GuestBook allows remote attackers to execute arbitrary SQL commands via the (1) name or (2) comment ("text") fields. | | 2.3 | CVE-2006-3852 BUGTRAQ
| Professional Home Page Tools -- Guestbook
| delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout. | | 2.3 | CVE-2006-3837 BUGTRAQ OTHER-REF SECUNIA XF
| Sun -- Solaris
| Unspecified vulnerability in the kernel in Solaris 10 with patch 118822-29 (118844-29 on x86) and without patch 118833-11 (118855-08) allows remote authenticated users to cause a denial of service via unspecified vectors that lead to "kernel data structure corruption" that can trigger a system panic, application failure, or "data corruption." | | 2.0 | CVE-2006-3728 SUNALERT BID FRSIRT SECUNIA XF SECTRACK
| Sun -- Solaris
| Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors involving (1) the /net mount point and (2) the "-hosts" map in a mount point. | | 1.6 | CVE-2006-3783 SUNALERT FRSIRT BID SECTRACK SECUNIA XF
| Sun -- Solaris
| systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow. | | 2.3 | CVE-2006-3824 IDEFENSE BID
| Sun -- Solaris
| The IPv4 implementation in Sun Solaris 10 before 20060721 allows local users to select routes that differ from the routing table, possibly facilitating firewall bypass or unauthorized network communication. | | 1.6 | CVE-2006-3825 SUNALERT BID FRSIRT SECUNIA XF
| Sunbelt Software -- Kerio Personal Firewall
| kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread. | | 1.6 | CVE-2006-3787 BUGTRAQ OTHER-REF BID FRSIRT SECUNIA
| UFO2000 -- UFO2000
| The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that is inconsistent with the packet size, which leads to a buffer over-read. | | 2.3 | CVE-2006-3790 BUGTRAQ OTHER-REF OTHER-REF FRSIRT SECTRACK SECUNIA
| UFO2000 -- UFO2000
| The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a large keysize or valsize, which causes a crash when the resize function cannot allocate sufficient memory. | | 2.3 | CVE-2006-3791 BUGTRAQ OTHER-REF OTHER-REF FRSIRT SECTRACK SECUNIA
| UNIDOmedia -- Chameleon LE
| Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter. | | 2.3 | CVE-2006-3836 BUGTRAQ BID
|