Primary Vendor -- Product | Description | | CVSS Score | Source & Patch Info | ArcSoft -- MMS Composer
| Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind, (2) M-Retrieve.conf (Header and Body), or (3) SMIL parsers. | | 7.0 | CVE-2006-4131 BUGTRAQ FULLDISC OTHER-REF OTHER-REF OTHER-REF BID FRSIRT SECUNIA
| Bob Jewell -- Discloser
| Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php. | | 7.0 | CVE-2006-4207 OTHER-REF OTHER-REF BID XF
| Boite de News -- Boite de News
| PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the url_index parameter. | | 7.0 | CVE-2006-4123 Milw0rm BID XF
| Chaussette -- Chaussette
| Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _BASE parameter to (1) Classes/Evenement.php, (2) Classes/Event.php, (3) Classes/Event_for_month.php, (4) Classes/Event_for_week.php, (5) Classes/My_Log.php, and (6) Classes/My_Smarty.php. | | 7.0 | CVE-2006-4159 OTHER-REF BID FRSIRT SECUNIA
| Chaussette -- Chaussette
| PHP remote file inclusion vulnerability in Chaussette 080706 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _BASE parameter to Classes/Event_for_month_per_day.php, a different vector than CVE-2006-4159. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | | 7.0 | CVE-2006-4216 SECUNIA
| Cisco -- PIX Firewall
| ** DISPUTED ** Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006-4032. NOTE: the vendor, after working with the researcher, has been unable to reproduce the issue. | | 7.0 | CVE-2006-4194 OTHER-REF OTHER-REF OTHER-REF CISCO
| CPG-Nuke -- Dragonfly CMS
| Cross-site scripting (XSS) vulnerability in Dragonfly CMS 9.0.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search field. | | 7.0 | CVE-2006-4162 BUGTRAQ XF
| David Kent Norman -- Thatware
| PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | | 7.0 | CVE-2006-4213 OTHER-REF FRSIRT XF
| DConnect -- DConnect Daemon
| Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function. | | 7.0 | CVE-2006-4125 BUGTRAQ OTHER-REF OTHER-REF BID FRSIRT SECTRACK SECUNIA XF
| Dolphin -- Dolphin
| Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php, (5) click.php, (6) faq.php, (7) gallery.php, (8) im.php, (9) inbox.php, (10) join_form.php, (11) logout.php, (12) messages_inbox.php, and many other scripts. | | 7.0 | CVE-2006-4189 SECTRACK XF
| Drupal -- Job Search
| SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary SQL commands via a job or resume search. | | 7.0 | CVE-2006-4107 OTHER-REF BID FRSIRT SECUNIA XF
| Drupal -- Bibliography Module
| SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | | 7.0 | CVE-2006-4108 OTHER-REF BID FRSIRT SECUNIA
| Falko Timme and Till Brehm -- SQLiteWebAdmin
| PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter. | | 7.0 | CVE-2006-4102 OTHER-REF FRSIRT XF
| HP -- OpenView Storage Data Protector
| Unspecified vulnerability in the backup agent and Cell Manager in HP OpenView Storage Data Protector 5.1 and 5.5 before 20060810 allows remote attackers to execute arbitrary code on an agent via unspecified vectors related to authentication and input validation. | | 7.0 | CVE-2006-4201 OTHER-REF HP BID FRSIRT SECTRACK SECUNIA XF
| IBM -- Informix Dynamic Database Server
| Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853. | | 7.0 | CVE-2006-3854 BUGTRAQ BUGTRAQ OTHER-REF
| IBM -- Websphere Application Server
| Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOAP requests and responses", (2) mbean, (3) ThreadIdentitySupport, and possibly others. | | 7.0 | CVE-2006-4136 OTHER-REF AIXAPAR AIXAPAR AIXAPAR BID FRSIRT SECUNIA
| IBM -- Access Support eGatherer ActiveX control
| Stack-based buffer overflow in the IBM Access Support eGatherer ActiveX control before 3.20.0284.0 allows remote attackers to execute arbitrary code via a long filename parameter to the RunEgatherer method. | | 7.0 | CVE-2006-4221 OTHER-REF BID FRSIRT SECUNIA
| Invision Power Services -- Invision Power Board
| Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic." | | 7.0 | CVE-2006-4155 OTHER-REF FRSIRT SECUNIA
| Jason Alexander -- phNNTP
| PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. | | 7.0 | CVE-2006-4103 BUGTRAQ OTHER-REF BID FRSIRT SECUNIA XF
| Joomla! -- Webring Component
| PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter. | | 7.0 | CVE-2006-4129 OTHER-REF BID FRSIRT SECUNIA
| Microsoft -- Windows Help File Viewer
| Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files. | | 8.0 | CVE-2006-4138 BUGTRAQ BUGTRAQ BID
| Microsoft -- Internet Explorer
| Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files. | | 7.0 | CVE-2006-4193 BUGTRAQ BUGTRAQ BUGTRAQ OTHER-REF OTHER-REF OTHER-REF BID BID BID
| Microsoft -- Internet Explorer
| The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN. | | 7.0 | CVE-2006-4219 BUGTRAQ OTHER-REF BID
| MODPlug -- Tracker
| Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and (2) crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files. | | 7.0 | CVE-2006-4192 BUGTRAQ OTHER-REF FRSIRT SECUNIA XF XF
| MusicBrainz -- libmusicbrainz MusicBrainz -- libmusicbrainz SVN
| Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c. | | 8.0 | CVE-2006-4197 BUGTRAQ BID SECTRACK SECUNIA XF XF
| MVCnPHP -- MVCnPHP
| Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the glConf[path_library] parameter to (1) BaseCommand.php, (2) BaseLoader.php, and (3) BaseView.php. | | 7.0 | CVE-2006-4160 OTHER-REF BID FRSIRT SECUNIA
| myWebland -- miniBloggie
| ** DISPUTED ** PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NOTE: another researcher was unable to find a way to execute code after including it via a URL. CVE analysis as of 20060816 was inconclusive. | | 7.0 | CVE-2006-4163 BUGTRAQ BUGTRAQ BID
| ncompress -- ncompress
| The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow. | | 7.0 | CVE-2006-1168 OTHER-REF DEBIAN MANDRIVA FRSIRT SECUNIA SECUNIA SECUNIA
| NetCommons -- NetCommons
| Cross-site scripting (XSS) vulnerability in NetCommons 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | | 7.0 | CVE-2006-4165 JVN BID SECUNIA XF
| Pearlabs -- Mafia MoBlog
| ** DISPUTED ** PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtotemplate parameter. NOTE: a third party claims that the researcher is incorrect, because template.php defines pathtotemplate before big.php uses pathtotemplate. CVE has not verified either claim, but during August 2006, the original researcher has made several significant errors regarding this bug type. | | 7.0 | CVE-2006-4156 BUGTRAQ BID
| PHPMyRing -- PHPMyRing
| SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter. | | 7.0 | CVE-2006-4114 Milw0rm BID FRSIRT SECUNIA
| phpPrintAnalyzer -- phpPrintAnalyzer
| PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ficStyle parameter. | | 7.0 | CVE-2006-4164 Milw0rm BID FRSIRT XF
| Ruby on Rails -- Ruby on Rails
| Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112. | | 7.0 | CVE-2006-4111 RUBY ON RAILS GENTOO OTHER-REF BID FRSIRT SECUNIA
| Ruby on Rails -- Ruby on Rails
| Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111. | | 7.0 | CVE-2006-4112 RUBY ON RAILS GENTOO CERT-VN BID SECUNIA SECUNIA XF
| SAP Software -- Internet Graphics Server
| Buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted HTTP requests. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. | | 7.0 | CVE-2006-4133 BUGTRAQ OTHER-REF BID FRSIRT SECTRACK SECUNIA
| Simple One-File Guestbook -- Simple One-File Guestbook
| Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php. | | 7.0 | CVE-2006-4122 OTHER-REF BID FRSIRT SECUNIA XF
| Soft3304 -- 04WebServer
| Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page, a different vulnerability than CVE-2004-1512. | | 7.0 | CVE-2006-4199 OTHER-REF BID SECUNIA XF
| Soft3304 -- 04WebServer
| Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing. | | 7.0 | CVE-2006-4200 OTHER-REF BID SECUNIA XF
| TinyWebGallery -- TinyWebGallery
| PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2. | | 7.0 | CVE-2006-4166 BUGTRAQ Milw0rm SECTRACK XF
| Vincent Hor -- Calendarix
| ** DISPUTED ** PHP remote file inclusion vulnerability in cal_config.inc.php in Calendarix 0.7.20060401 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the calpath parameter. NOTE: this issue has been disputed by a third party, who says that the affected $calpath variable is set to a constant value in the beginning of the script. CVE concurs that the initial report is invalid. | | 7.0 | CVE-2006-4135 BUGTRAQ BUGTRAQ MLIST XF
| VWar -- Virtual War
| SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) sortby and (2) sortorder parameters. | | 7.0 | CVE-2006-4141 BUGTRAQ XF
| VWar -- Virtual War
| SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter. | | 7.0 | CVE-2006-4142 BUGTRAQ BID XF
| WebDynamite -- ProjectButler
| Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to /classes/ scripts including (1) Cache.class.php, (2) Customer.class.php, (3) Performance.class.php, (4) Project.class.php, (5) Representative.class.php, (6) User.class.php, or (7) common.php. | | 7.0 | CVE-2006-4205 OTHER-REF BID XF
| WEBInsta -- CMS
| PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir parameter. | | 7.0 | CVE-2006-4196 BUGTRAQ ECHO Milw0rm BID FRSIRT SECUNIA
| WEBInsta -- Mailing List Manager
| PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter. | | 7.0 | CVE-2006-4209 BUGTRAQ OTHER-REF OTHER-REF XF
| YaBB -- YaBB SE
| Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter. | | 7.0 | CVE-2006-4157 BUGTRAQ BID XF
| Zen Cart -- Zen Cart
| Multiple SQL injection vulnerabilities in Zen Cart 1.3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) GPC data to ipn_get_stored_session, which can be leveraged to modify elements of $_SESSION; and allow remote authenticated users to execute arbitrary SQL commands via (2) a session id within a cookie to whos_online_session_recreate, (3) the quantity field to the add_cart function, (4) an id[] parameter when adding an item to a shopping cart, or (5) a redemption code when checking out. | | 7.0 | CVE-2006-4214 OTHER-REF BID FRSIRT SECUNIA
| Zen Cart -- Zen Cart
| PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in autoLoadConfig[999][0][loadFile] parameter. | | 7.0 | CVE-2006-4215 OTHER-REF BID FRSIRT SECUNIA
| Zen Cart -- Zen Cart
| Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier allows remote attackers to include and possibly execute arbitrary local files via directory traversal sequences in the typefilter parameter. | | 7.0 | CVE-2006-4218 OTHER-REF BID FRSIRT SECUNIA
|