/[secure-testing]/data/CVE/list
ViewVC logotype

Contents of /data/CVE/list

Parent Directory Parent Directory | Revision Log Revision Log


Revision 4706 - (show annotations) (download)
Sat Sep 9 22:22:45 2006 UTC (6 years, 8 months ago) by stef-guest
File size: 2319245 byte(s)
- CVE-2006-4561 new firefox issue (low)
- tikiwiki CVEified
- CVE-2006-4618 adodb not affected (in 6 packages)
- CVE-2006-4455 xchat not affected
- some NFUs
1 CVE-2006-4622 (PHP remote file inclusion vulnerability in annonce.php in AnnonceV ...)
2 NOT-FOR-US: AnnonceV
3 CVE-2006-4621 (PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, ...)
4 NOT-FOR-US: Pheap
5 CVE-2006-4620 (The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with ...)
6 NOT-FOR-US: Alt-N WebAdmin
7 CVE-2006-4619 (The start update window in Avira AntiVir PersonalEdition Classic ...)
8 NOT-FOR-US: Avira
9 CVE-2006-4618 (PHP remote file inclusion vulnerability in adodb-postgres7.inc.php in ...)
10 - libphp-adodb <not-affected> (vulnerable code seems to be In-link specific)
11 - egroupware <not-affected> (vulnerable code seems to be In-link specific)
12 - moodle <not-affected> (vulnerable code seems to be In-link specific)
13 - phppgadmin <not-affected> (vulnerable code seems to be In-link specific)
14 - gallery2 <not-affected> (vulnerable code seems to be In-link specific)
15 - phpwiki <not-affected> (vulnerable code seems to be In-link specific)
16 CVE-2006-4617 (Unrestricted file upload vulnerability in fileupload.html in vtiger ...)
17 NOT-FOR-US: vtiger CRM
18 CVE-2006-4616 (SMTP service in MailEnable Standard, Professional, and Enterprise ...)
19 NOT-FOR-US: MailEnable
20 CVE-2006-4615 (Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores ...)
21 NOT-FOR-US: Shape Services
22 CVE-2006-4614 (PDAapps Verichat for Pocket PC 1.30bh stores usernames and passwords ...)
23 NOT-FOR-US: PDAapps Verichat
24 CVE-2006-4613 (Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow ...)
25 NOT-FOR-US: SnapGear
26 CVE-2006-4612 (SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows ...)
27 NOT-FOR-US: ZIXForum
28 CVE-2006-4611 (Buffer overflow in the _tor_resolve function in dsocks.c in dsocks ...)
29 NOT-FOR-US: dsocks
30 CVE-2006-4610 (PHP remote file inclusion vulnerability in index.php in GrapAgenda ...)
31 NOT-FOR-US: GrapAgenda
32 CVE-2006-4609 (** DISPUTED ** ...)
33 NOT-FOR-US: PHProjekt
34 CVE-2006-4608 (Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome ...)
35 NOT-FOR-US: php-Revista
36 CVE-2006-4607 (admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote ...)
37 NOT-FOR-US: php-Revista
38 CVE-2006-4606 (Multiple SQL injection vulnerabilities in Longino Jacome php-Revista ...)
39 NOT-FOR-US: php-Revista
40 CVE-2006-4605 (PHP remote file inclusion vulnerability in index.php in Longino Jacome ...)
41 NOT-FOR-US: php-Revista
42 CVE-2006-4604 (PHP remote file inclusion vulnerability in LFXlib/access_manager.php ...)
43 NOT-FOR-US: Lanifex Database of Managed Objects (DMO)
44 CVE-2006-4603 (NCH Swift Sound Web Dictate 1.02 allows remote attackers to bypass ...)
45 NOT-FOR-US: Swift Sound Web Dictate
46 CVE-2006-4601 (SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows ...)
47 NOT-FOR-US: 1Two
48 CVE-2006-4600 (slapd in OpenLDAP before 2.3.25 allows remote authenticated users with ...)
49 - openldap2.3 2.3.25-1
50 - openldap2.2 <removed> (low)
51 - openldap2 <not-affected> (low) (slapd not built from this version)
52 CVE-2006-4599 (SQL injection vulnerability in aut_verifica.inc.php in Autentificator ...)
53 NOT-FOR-US: Autentificator
54 CVE-2006-4598 (Multiple SQL injection vulnerabilities in links.php in ssLinks 1.22 ...)
55 NOT-FOR-US: ssLinks
56 CVE-2006-4597 (SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier ...)
57 NOT-FOR-US: ICBlogger
58 CVE-2006-4596 (PHP remote file inclusion in MyBace Light Skrip, when register_globals ...)
59 NOT-FOR-US: MyBace Light Skrip
60 CVE-2006-4595 (muforum (&#181;forum) 0.4c stores membres/members.dat under the web ...)
61 NOT-FOR-US: muforum
62 CVE-2006-4594 (Multiple PHP remote file inclusion vulnerabilities in PHP Advanced ...)
63 NOT-FOR-US: phpAtm
64 CVE-2006-4593 (Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 ...)
65 NOT-FOR-US: SoftBB
66 CVE-2006-4592 (Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple ...)
67 NOT-FOR-US: Simple Blog
68 CVE-2006-4591 (Multiple PHP remote file inclusion vulnerabilities in AlstraSoft ...)
69 NOT-FOR-US: AltraSoft Template Seller
70 CVE-2006-4590 (SQL injection vulnerability in admin/default.asp in Jetstat.com JS ASP ...)
71 NOT-FOR-US: Jetstat.com JS ASP Faq Manager
72 CVE-2006-4589 (PHP remote file inclusion vulnerability in ...)
73 NOT-FOR-US: DynCMS
74 CVE-2006-4588 (vtiger CRM 4.2.4, and possibly earlier, allows remote attackers to ...)
75 NOT-FOR-US: vtiger CRM
76 CVE-2006-4587 (Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM ...)
77 NOT-FOR-US: vtiger CRM
78 CVE-2006-4586 (The admin panel in Tr Forum 2.0 accepts a username and password hash ...)
79 NOT-FOR-US: Tr Forum
80 CVE-2006-4585 (SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows ...)
81 NOT-FOR-US: Tr Forum
82 CVE-2006-4584 (Tr Forum 2.0 allows remote attackers to bypass authentication and add ...)
83 NOT-FOR-US: Tr Forum
84 CVE-2006-4583 (Multiple PHP remote file inclusion vulnerabilities in FlashChat before ...)
85 NOT-FOR-US: FlashChat
86 CVE-2006-4582
87 RESERVED
88 CVE-2006-4581
89 RESERVED
90 CVE-2006-4580
91 RESERVED
92 CVE-2006-4579
93 RESERVED
94 CVE-2006-4578
95 RESERVED
96 CVE-2006-4577
97 RESERVED
98 CVE-2006-4576
99 RESERVED
100 CVE-2006-4575
101 RESERVED
102 CVE-2006-4574
103 RESERVED
104 CVE-2006-4573
105 RESERVED
106 CVE-2006-4572
107 RESERVED
108 CVE-2006-4571
109 RESERVED
110 CVE-2006-4570
111 RESERVED
112 CVE-2006-4569
113 RESERVED
114 CVE-2006-4568
115 RESERVED
116 CVE-2006-4567
117 RESERVED
118 CVE-2006-4566
119 RESERVED
120 CVE-2006-4565
121 RESERVED
122 CVE-2006-4564 (SQL injection vulnerability in Sources/ManageBoards.php in Simple ...)
123 NOT-FOR-US: Simple Machines Forum
124 CVE-2006-4563 (Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke ...)
125 NOT-FOR-US: PHP-Nuke
126 CVE-2006-4562 (** DISPUTED ** ...)
127 NOT-FOR-US: Symantec
128 CVE-2006-4561 (Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary ...)
129 - xulrunner <unfixed> (low)
130 - firefox <unfixed> (low>
131 - mozilla <unfixed> (low>
132 - mozilla-firefox <removed> (low)
133 CVE-2006-4560 (Internet Explorer 6 on Windows XP SP2 allows remote attackers to ...)
134 NOT-FOR-US: Internet Explorer
135 CVE-2006-4559 (Multiple PHP remote file inclusion vulnerabilities in Yet Another ...)
136 NOT-FOR-US: Yet Another Community System (YACS) CMS
137 CVE-2006-4558 (DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the ...)
138 NOT-FOR-US: DeluxeBB
139 CVE-2006-4557 (** DISPUTED ** ...)
140 NOT-FOR-US: Discloser
141 CVE-2006-4556 (** DISPUTED ** ...)
142 NOT-FOR-US: JIM component for Mambo and Joomla!
143 CVE-2006-4555 (Buffer overflow in the Retro64 / Miniclip CR64Loader ActiveX control ...)
144 NOT-FOR-US: Miniclip CR64Loader ActiveX control
145 CVE-2006-4554 (Stack-based buffer overflow in the ReadFile function in the ...)
146 NOT-FOR-US: BeCubed Compression Plus
147 CVE-2006-4553 (PHP remote file inclusion vulnerability in plugin.class.php in the ...)
148 NOT-FOR-US: com_comprofiler Components for Mambo and Joomla!
149 CVE-2006-4552 (Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter ...)
150 NOT-FOR-US: CHXO Feedsplitter
151 CVE-2006-4551 (Eval injection vulnerability in CHXO Feedsplitter 2006-01-21 allows ...)
152 NOT-FOR-US: CHXO Feedsplitter
153 CVE-2006-4550 (Directory traversal vulnerability in CHXO Feedsplitter 2006-01-21 ...)
154 NOT-FOR-US: CHXO Feedsplitter
155 CVE-2006-4549 (CHXO Feedsplitter 2006-01-21 allows remote attackers to read the ...)
156 NOT-FOR-US: CHXO Feedsplitter
157 CVE-2006-4548 (e107 0.75 and earlier does not properly unset variables when the input ...)
158 NOTE: this should be fixed in PHP (CVE-2006-3017)
159 CVE-2006-4547 (Lyris ListManager 8.95 allows remote authenticated users to obtain ...)
160 NOT-FOR-US: Lyris ListManager
161 CVE-2006-4546 (Lyris ListManager 8.95 allows remote authenticated users, who have ...)
162 NOT-FOR-US: Lyris ListManager
163 CVE-2006-4545 (** DISPUTED ** ...)
164 NOT-FOR-US: ModuleBased CMS Pre-Alpha
165 CVE-2006-4544 (Multiple PHP remote file inclusion vulnerabilities in ExBB 1.9.1, when ...)
166 NOT-FOR-US: ExBB
167 CVE-2006-4543 (Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 ...)
168 NOT-FOR-US: HLStats
169 CVE-2006-4542 (Webmin before 1.296 and Usermin before 1.226 do not properly handle a ...)
170 TODO: check
171 CVE-2006-4541 (RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly ...)
172 NOT-FOR-US: BlackICE PC Protection
173 CVE-2006-4540 (Cross-site scripting (XSS) vulnerability in learncenter.asp in ...)
174 NOT-FOR-US: Learn.com LearnCenter
175 CVE-2006-4539 ((1) includes/widgets/module_company_tickets.php and (2) ...)
176 NOT-FOR-US: Cerberus Helpdesk
177 CVE-2006-4538 (Linux kernel 2.6.17 and earlier, when running on IA64 or SPARC ...)
178 TODO: check
179 CVE-2006-4537 (NET$SESSION_CONTROL.EXE before 20060825 in DECnet-Plus in OpenVMS ...)
180 NOT-FOR-US: OpenVMS
181 CVE-2006-4536 (SQL injection vulnerability in module/rejestracja.php in CMS Frogss ...)
182 NOT-FOR-US: CMS Frogss
183 CVE-2006-4535
184 RESERVED
185 CVE-2006-4534 (Unspecified vulnerability in Microsoft Word 2000 allows remote ...)
186 NOT-FOR-US: Microsoft
187 CVE-2006-4533 (Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 ...)
188 NOT-FOR-US: Plume CMS
189 CVE-2006-4532 (PHP remote file inclusion vulnerability in articles/article.php in Yet ...)
190 NOT-FOR-US: Yet Another Community System (YACS) CMS
191 CVE-2006-4531 (PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS ...)
192 NOT-FOR-US: Pheap CMS
193 CVE-2006-4530 (Direct static code injection vulnerability in include/change.php in ...)
194 NOT-FOR-US: membrepass
195 CVE-2006-4529 (SQL injection vulnerability in recherchemembre.php in membrepass 1.5. ...)
196 NOT-FOR-US: membrepass
197 CVE-2006-4528 (Multiple cross-site scripting (XSS) vulnerabilities in membrepass 1.5 ...)
198 NOT-FOR-US: membrepass
199 CVE-2006-4527 (includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when ...)
200 NOT-FOR-US: CubeCart
201 CVE-2006-4526 (SQL injection vulnerability in includes/content/viewCat.inc.php in ...)
202 NOT-FOR-US: CubeCart
203 CVE-2006-4525 (Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and ...)
204 NOT-FOR-US: CubeCart
205 CVE-2006-4524 (Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz ...)
206 NOT-FOR-US: Digiappz Freekot
207 CVE-2006-4523 (The web-based management interface in 2Wire, Inc. HomePortal and ...)
208 NOT-FOR-US: 2Wire
209 CVE-2006-4522 (Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows ...)
210 NOT-FOR-US: IBM AIX
211 CVE-2004-2664 (John Lim ADOdb Library for PHP before 4.23 allows remote attackers to ...)
212 TODO: check
213 CVE-2006-XXXX [hostapd dos]
214 - hostapd 1:0.5.4-1
215 [sarge] - hostapd <not-affected> (Vulnerable code not present)
216 CVE-2006-4521
217 RESERVED
218 CVE-2006-4520
219 RESERVED
220 CVE-2006-4519
221 RESERVED
222 CVE-2006-4518
223 RESERVED
224 CVE-2006-4517
225 RESERVED
226 CVE-2006-4516
227 RESERVED
228 CVE-2006-4515
229 RESERVED
230 CVE-2006-4514
231 RESERVED
232 CVE-2006-4513
233 RESERVED
234 CVE-2006-4512
235 RESERVED
236 CVE-2006-4511
237 RESERVED
238 CVE-2006-4510
239 RESERVED
240 CVE-2006-4509
241 RESERVED
242 CVE-2006-4508 (Unspecified vulnerability in (1) Tor 0.1.0.x before 0.1.0.18 and ...)
243 - tor 0.1.1.23-1
244 CVE-2006-4507 (Unspecified vulnerability in the TIFF viewer (possibly libTIFF) in the ...)
245 NOT-FOR-US: Sony
246 NOTE: According to the original advisory, this is just CVE-2006-3459
247 CVE-2006-4506 (idmlib.sh in nxdrv in Novell Identity Manager (IDM) 3.0.1 allows local ...)
248 NOT-FOR-US: Novell Identity Manager
249 CVE-2006-4505 (CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote ...)
250 NOT-FOR-US: NX5Linx
251 CVE-2006-4504 (SQL injection vulnerability in NX5Linx 1.0 allows remote attackers to ...)
252 NOT-FOR-US: NX5Linx
253 CVE-2006-4503 (Directory traversal vulnerability in link.php in NX5Linx 1.0 allows ...)
254 NOT-FOR-US: NX5Linx
255 CVE-2006-4502 (ezPortal/ztml CMS 1.0 allows remote attackers to bypass authentication ...)
256 NOT-FOR-US: ezPortal/ztml CMS
257 CVE-2006-4501 (SQL injection vulnerability in index.php in ezPortal/ztml CMS 1.0 ...)
258 NOT-FOR-US: ezPortal/ztml CMS
259 CVE-2006-4500 (Cross-site scripting (XSS) vulnerability in index.php in ezPortal/ztml ...)
260 NOT-FOR-US: ezPortal/ztml CMS
261 CVE-2006-4499 (ModernBill 5.0.4 and earlier uses cURL with insecure settings for ...)
262 NOT-FOR-US: ModernBill
263 CVE-2006-4498 (PHP remote file inclusion vulnerability in sommaire_admin.php in ...)
264 NOT-FOR-US: PortailPHP
265 CVE-2006-4497 (SQL injection vulnerability in comments.php in IwebNegar 1.1 allows ...)
266 NOT-FOR-US: IwebNegar
267 CVE-2006-4496 (Cross-site scripting (XSS) vulnerability in comments.php in IwebNegar ...)
268 NOT-FOR-US: IwebNegar
269 CVE-2006-4495 (Microsoft Internet Explorer allows remote attackers to cause a denial ...)
270 NOT-FOR-US: Microsoft Internet Explorer
271 CVE-2006-4494 (Microsoft Visual Studio 6.0 allows remote attackers to cause a denial ...)
272 NOT-FOR-US: Microsoft
273 CVE-2006-4493 (xbiff2 1.9 creates $HOME/.xbiff2rc in a user's home directory with ...)
274 NOT-FOR-US: xbiff2
275 NOTE: xbase-clients contains xbiff, but it is not affected as it doesn't use a .xbiffrc
276 CVE-2006-4492 (Unspecified vulnerability in Cybozu Office 6.5 Build 1.2 for Windows ...)
277 NOT-FOR-US: Cybozu Office
278 CVE-2006-4491 (Directory traversal vulnerability in Cybozu Collaborex, AG before ...)
279 NOT-FOR-US: Cybozu Collaborex
280 CVE-2006-4490 (Multiple directory traversal vulnerabilities in Cybozu Office before ...)
281 NOT-FOR-US: Cybozu Office
282 CVE-2006-4489 (Multiple PHP remote file inclusion vulnerabilities in MiniBill ...)
283 NOT-FOR-US: MiniBill
284 CVE-2006-4488 (PHP remote file inclusion vulnerability in ...)
285 NOT-FOR-US: ExBB Italia
286 CVE-2006-4487 (DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web ...)
287 NOT-FOR-US: DUpoll
288 CVE-2006-4486 (Unspecified vulnerability in PHP before 5.1.6, when running on a ...)
289 - php5 5.1.6-1
290 - php4 4:4.4.4-1
291 CVE-2006-4485 (The stripos function in PHP before 5.1.5 has unknown impact and attack ...)
292 - php5 5.1.6-1
293 - php4 <not-affected> (Vulnerable function doesn't exist)
294 CVE-2006-4484 (Buffer overflow in the LWZReadByte_ function in ...)
295 - libgd2 <unfixed> (medium; bug #384838)
296 - xloadimage <unfixed> (low; bug #384841)
297 CVE-2006-4483 (The cURL extension files (1) ext/curl/interface.c and (2) ...)
298 - php5 5.1.6-1 (low)
299 - php4 4:4.4.4-1 (low)
300 [sarge] - php4 <no-dsa> (Safe mode violations not supported, insufficient measure)
301 CVE-2006-4482 (Multiple heap-based buffer overflows in the (1) str_repeat and (2) ...)
302 - php5 5.1.6-1 (low)
303 - php4 4:4.4.4-1 (low)
304 CVE-2006-4481 (The (1) file_exists and (2) imap_reopen functions in PHP before 5.1.5 ...)
305 - php5 5.1.6-1 (low)
306 - php4 4:4.4.4-1 (low)
307 [sarge] - php4 <no-dsa> (Basedir violations not supported, insufficient measure)
308 CVE-2006-4480 (Incomplete blacklist vulnerability in the nk_CSS function in nuked.php ...)
309 NOT-FOR-US: Nuked-Klan
310 CVE-2006-4479 (Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual ...)
311 NOT-FOR-US: ezContents
312 CVE-2006-4478 (SQL injection vulnerability in headeruserdata.php in Visual Shapers ...)
313 NOT-FOR-US: ezContents
314 CVE-2006-4477 (Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ...)
315 NOT-FOR-US: ezContents
316 CVE-2006-4476 (Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related ...)
317 - joomla <itp> (bug #326398)
318 CVE-2006-4475 (Joomla! before 1.0.11 does not limit access to the Admin Popups ...)
319 - joomla <itp> (bug #326398)
320 CVE-2006-4474 (Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before ...)
321 - joomla <itp> (bug #326398)
322 CVE-2006-4473 (Unspecified vulnerability in com_content in Joomla! before 1.0.11, ...)
323 - joomla <itp> (bug #326398)
324 CVE-2006-4472 (Multiple unspecified vulnerabilities in Joomla! before 1.0.11 allow ...)
325 - joomla <itp> (bug #326398)
326 CVE-2006-4471 (The Admin Upload Image functionality in Joomla! before 1.0.11 allows ...)
327 - joomla <itp> (bug #326398)
328 CVE-2006-4470 (Joomla! before 1.0.11 omits some checks for whether _VALID_MOS is ...)
329 - joomla <itp> (bug #326398)
330 CVE-2006-4469 (Unspecified vulnerability in PEAR.php in Joomla! before 1.0.11 allows ...)
331 - joomla <itp> (bug #326398)
332 CVE-2006-4468 (Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related ...)
333 - joomla <itp> (bug #326398)
334 CVE-2006-4467 (Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before ...)
335 NOT-FOR-US: Simple Machines Forum
336 CVE-2006-4466 (Joomla! before 1.0.11 does not properly unset variables when the input ...)
337 - joomla <itp> (bug #326398)
338 CVE-2006-4465 (** DISPUTED ** ...)
339 NOT-FOR-US: Microsoft
340 CVE-2006-4464 (The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, ...)
341 NOT-FOR-US: Nokia
342 CVE-2006-4463 (SQL injection vulnerability in the administrator control panel in ...)
343 NOT-FOR-US: JS ASP Faq Manager
344 CVE-2006-4462 (Gonafish.com LinksCaffe 2.0 and 3.0 do not properly restrict access to ...)
345 NOT-FOR-US: LinksCaffe
346 CVE-2006-4461 (Paessler IPCheck Server Monitor before 5.3.3.639/640 does not properly ...)
347 NOT-FOR-US: Paessler IPCheck Server Monitor (not related to ipcheck in Debian)
348 CVE-2006-4460 (Cross-site scripting (XSS) vulnerability in PHP iAddressBook before ...)
349 NOT-FOR-US: iAddressBook
350 CVE-2006-4459 (Integer overflow in AnywhereUSB/5 1.80.00 allows local users to cause ...)
351 NOT-FOR-US: AnywhereUSB/5
352 CVE-2006-4458 (Directory traversal vulnerability in ...)
353 - phpgroupware <unfixed> (bug #386061; medium)
354 CVE-2006-4457 (PHP remote file inclusion vulnerability in index.php in phpECard 2.1.4 ...)
355 NOT-FOR-US: phpECard
356 CVE-2006-4456 (PHP remote file inclusion vulnerability in functions.php in phpECard ...)
357 NOT-FOR-US: phpECard
358 CVE-2006-4455 (** DISPUTED ** ...)
359 - xchat <not-affected> (not reproducible)
360 CVE-2006-4454 (Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats ...)
361 NOT-FOR-US: HLstats
362 CVE-2006-4453 (Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 ...)
363 NOT-FOR-US: PmWiki
364 CVE-2006-4452 (PHP remote file inclusion vulnerability in ...)
365 NOT-FOR-US: Web3news
366 CVE-2006-4451 (Direct static code injection vulnerability in CJ Tag Board 3.0 allows ...)
367 NOT-FOR-US: Tag Board
368 CVE-2006-4450 (usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, ...)
369 - phpbb2 2.0.21-1 (low)
370 CVE-2006-4449 (Cross-site scripting (XSS) vulnerability in attachment.php in ...)
371 NOT-FOR-US: MyBulletinBoard (MyBB)
372 CVE-2006-4448 (Multiple PHP remote file inclusion vulnerabilities in interact 2.2, ...)
373 NOT-FOR-US: interact
374 CVE-2006-4447 (X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, ...)
375 - xbase-clients 1:7.1.ds-2
376 - xtrans 1.0.0-6
377 - xorg-server 1:1.0.2-9
378 - libx11 2:1.0.0-7
379 - xdm 1:1.0.5-1
380 - xterm <unfixed>
381 [sarge] - xfree86 <unfixed>
382 CVE-2006-4446 (Heap-based buffer overflow in DirectAnimation.PathControl COM object ...)
383 NOT-FOR-US: Microsoft
384 CVE-2006-4445 (** DISPUTED ** ...)
385 NOT-FOR-US: CuteNews
386 CVE-2006-4444 (Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for ...)
387 NOT-FOR-US: Cybozu Garoon
388 CVE-2006-4443 (PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft ...)
389 NOT-FOR-US: AlstraSoft Video Share Enterprise
390 CVE-2006-4442 (Cross-site scripting (XSS) vulnerability in PHP iAddressBook before ...)
391 NOT-FOR-US: iAddressBook
392 CVE-2006-4441 (Multiple PHP remote file inclusion vulnerabilities in Ay System ...)
393 NOT-FOR-US: Ay System Solutions CMS
394 CVE-2006-4440 (PHP remote file inclusion vulnerability in main.php in Ay System ...)
395 NOT-FOR-US: Ay System Solutions CMS
396 CVE-2006-4439 (pkgadd in Sun Solaris 10 before 20060825 installs files with insecure ...)
397 NOT-FOR-US: Solaris
398 CVE-2006-4438
399 RESERVED
400 CVE-2006-4437
401 RESERVED
402 CVE-2005-4810 (Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote ...)
403 NOT-FOR-US: Microsoft
404 CVE-2005-4809 (Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla ...)
405 - mozilla <unfixed> (low)
406 - firefox <not-affected> (at least 1.5.0.6 is not vulnerable)
407 - xulrunner <not-affected>
408 [sarge] - mozilla <no-dsa> (Conceptual problem, not fixable in a backport)
409 CVE-2003-1305 (Microsoft Internet Explorer allows remote attackers to cause a denial ...)
410 NOT-FOR-US: Microsoft
411 CVE-2006-4602 (Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 ...)
412 - tikiwiki 1.9.4+dfsg2-3
413 CVE-2006-4436 (isakmpd in OpenBSD 3.8, 3.9, and possibly earlier versions, creates ...)
414 - isakmpd 20041012-4 (bug #385894; medium)
415 CVE-2006-4435 (OpenBSD 3.8, 3.9, and possibly earlier versions allows ...)
416 NOT-FOR-US: OpenBSD
417 CVE-2006-4434 (Use-after-free vulnerability in Sendmail before 8.13.8 allows remote ...)
418 {DSA-1164}
419 - sendmail 8.13.8-1 (bug #385054; medium)
420 CVE-2006-4433 (PHP before 4.4.3 and 5.x before 5.1.4 does not limit the character set ...)
421 - php4 4:4.4.4-1 (low)
422 - php5 5.1.4-0.1 (low)
423 CVE-2006-4432 (Directory traversal vulnerability in Zend Platform 2.2.1 and earlier ...)
424 NOT-FOR-US: Zend Platform
425 CVE-2006-4431 (Multiple buffer overflows in the (a) Session Clustering Daemon and the ...)
426 NOT-FOR-US: Zend Platform
427 CVE-2006-4430 (The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows ...)
428 NOT-FOR-US: Cisco
429 CVE-2006-4429 (** DISPUTED ** ...)
430 NOT-FOR-US: PHlyMail Lite
431 CVE-2006-4428 (** DISPUTED ** ...)
432 NOT-FOR-US: Jupiter CMS
433 CVE-2006-4427 (index.php in eFiction before 2.0.7 allows remote attackers to bypass ...)
434 NOT-FOR-US: eFiction
435 CVE-2006-4426 (PHP remote file inclusion vulnerability in ...)
436 NOT-FOR-US: AlberT-EasySite
437 CVE-2006-4425 (Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 ...)
438 NOT-FOR-US: phpCOIN
439 CVE-2006-4424 (PHP remote file inclusion vulnerability in coin_includes/constants.php ...)
440 NOT-FOR-US: phpCOIN
441 CVE-2006-4423 (Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 ...)
442 NOT-FOR-US: Bigace
443 CVE-2006-4422 (** DISPUTED ** ...)
444 NOT-FOR-US: Jetbox CMS
445 CVE-2006-4421 (Cross-site scripting (XSS) vulnerability in ...)
446 NOT-FOR-US: Yet Another PHP Image Gallery
447 CVE-2006-4420 (Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 ...)
448 NOT-FOR-US: Phaos
449 CVE-2006-4419 (SQL injection vulnerability in note.php in ProManager 0.73 allows ...)
450 NOT-FOR-US: ProManager
451 CVE-2006-4418 (Directory traversal vulnerability in index.php for Wikepage 2006.2a ...)
452 NOT-FOR-US: Wikepage
453 CVE-2006-4417 (SQL injection vulnerability in edituser.php in Xoops before 2.0.15 ...)
454 NOT-FOR-US: Xoops
455 CVE-2006-4416 (Untrusted search path vulnerability in the mkvg command in IBM AIX 5.2 ...)
456 NOT-FOR-US: IBM AIX
457 CVE-2006-4415
458 RESERVED
459 CVE-2006-4414
460 RESERVED
461 CVE-2006-4413
462 RESERVED
463 CVE-2006-4412
464 RESERVED
465 CVE-2006-4411
466 RESERVED
467 CVE-2006-4410
468 RESERVED
469 CVE-2006-4409
470 RESERVED
471 CVE-2006-4408
472 RESERVED
473 CVE-2006-4407
474 RESERVED
475 CVE-2006-4406
476 RESERVED
477 CVE-2006-4405
478 RESERVED
479 CVE-2006-4404
480 RESERVED
481 CVE-2006-4403
482 RESERVED
483 CVE-2006-4402
484 RESERVED
485 CVE-2006-4401
486 RESERVED
487 CVE-2006-4400
488 RESERVED
489 CVE-2006-4399
490 RESERVED
491 CVE-2006-4398
492 RESERVED
493 CVE-2006-4397
494 RESERVED
495 CVE-2006-4396
496 RESERVED
497 CVE-2006-4395
498 RESERVED
499 CVE-2006-4394
500 RESERVED
501 CVE-2006-4393
502 RESERVED
503 CVE-2006-4392
504 RESERVED
505 CVE-2006-4391
506 RESERVED
507 CVE-2006-4390
508 RESERVED
509 CVE-2006-4389
510 RESERVED
511 CVE-2006-4388
512 RESERVED
513 CVE-2006-4387
514 RESERVED
515 CVE-2006-4386
516 RESERVED
517 CVE-2006-4385
518 RESERVED
519 CVE-2006-4384
520 RESERVED
521 CVE-2006-4383
522 RESERVED
523 CVE-2006-4382
524 RESERVED
525 CVE-2006-4381
526 RESERVED
527 CVE-2006-4380 (MySQL before 4.1.13 allows local users to cause a denial of service ...)
528 {DSA-1169}
529 - mysql-dfsg-5.0 <not-affected> (only 4.1 affected)
530 - mysql-dfsg <not-affected> (only 4.1 affected)
531 - mysql-dfsg-4.1 <removed>
532 CVE-2006-4379
533 RESERVED
534 CVE-2006-4378 (** DISPUTED ** ...)
535 NOT-FOR-US: Rssxt component for Joomla! (com_rssxt)
536 CVE-2006-4377 (Multiple SQL injection vulnerabilities in Guder und Koch ...)
537 NOT-FOR-US: Eichhorn Portal
538 CVE-2006-4376 (Multiple cross-site scripting (XSS) vulnerabilities in Guder und Koch ...)
539 NOT-FOR-US: Eichhorn Portal
540 CVE-2006-4375 (** DISPUTED ** ...)
541 NOT-FOR-US: Contacts XTD (ContXTD) component for Mambo (com_contxtd)
542 CVE-2006-4374 (IrfanView 3.98 (with plugins) allows user-assisted attackers to cause ...)
543 NOT-FOR-US: IrfanView
544 CVE-2006-4373 (PHP remote file inclusion vulnerability in ...)
545 NOT-FOR-US: pSlash
546 CVE-2006-4372 (PHP remote file inclusion vulnerability in admin.lurm_constructor.php ...)
547 NOT-FOR-US: Lurm Constructor component (com_lurm_constructor) for Mambo
548 CVE-2006-4371 (Multiple directory traversal vulnerabilities in Alt-N WebAdmin 3.2.3 ...)
549 NOT-FOR-US: Alt-N WebAdmin
550 CVE-2006-4370 (Alt-N WebAdmin 3.2.3 and 3.2.4 running with MDaemon 9.0.5, and ...)
551 NOT-FOR-US: Alt-N WebAdmin
552 CVE-2006-4369 (Absolute path traversal vulnerability in includes/functions_portal.php ...)
553 NOT-FOR-US: IntegraMOD Portal
554 CVE-2006-4368 (PHP remote file inclusion vulnerability in ...)
555 NOT-FOR-US: IntegraMOD Portal
556 CVE-2006-4367 (SQL injection vulnerability in alltopics.php in the All Topics Hack ...)
557 NOT-FOR-US: All Topics Hack for phpBB
558 CVE-2006-4366 (PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 ...)
559 NOT-FOR-US: RedBLoG
560 CVE-2006-4365 (Multiple PHP remote file inclusion vulnerabilities in VistaBB 2.0.33 ...)
561 NOT-FOR-US: VistaBB
562 CVE-2006-4364 (Multiple heap-based buffer overflows in the POP3 server in Alt-N ...)
563 NOT-FOR-US: Alt-N Technologies MDaemon
564 CVE-2006-4363 (PHP remote file inclusion vulnerability in admin.cropcanvas.php in the ...)
565 NOT-FOR-US: CropImage component (com_cropimage) for Mambo
566 CVE-2006-4362 (Cross-site scripting (XSS) vulnerability in getad.php in Diesel Paid ...)
567 NOT-FOR-US: Diesel Paid Mail
568 CVE-2006-4361 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
569 NOT-FOR-US: Diesel Job Site
570 CVE-2006-4360 (Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal ...)
571 NOT-FOR-US: E-commerce for Drupal
572 CVE-2006-4359 (Stack-based buffer overflow in Trident Software PowerZip 7.06 Build ...)
573 NOT-FOR-US: PowerZip
574 CVE-2006-4358 (Cross-site scripting (XSS) vulnerability in index.php in Diesel Pay ...)
575 NOT-FOR-US: Diesel Pay
576 CVE-2006-4357 (PHP remote file inclusion vulnerability in clients/index.php in Diesel ...)
577 NOT-FOR-US: Diesel Smart Traffic
578 CVE-2006-4356 (SQL injection vulnerability in Drupal Easylinks Module ...)
579 NOT-FOR-US: Easylinks Module for Drupal
580 CVE-2006-4355 (Cross-site scripting (XSS) vulnerability in Drupal Easylinks Module ...)
581 NOT-FOR-US: Easylinks Module for Drupal
582 CVE-2006-4354 (PHP remote file inclusion vulnerability in e/class/CheckLevel.php in ...)
583 NOT-FOR-US: Phome Empire CMS
584 CVE-2006-4353 (Unspecified vulnerability in Sun Java System Content Delivery Server ...)
585 NOT-FOR-US: Sun Java System Content Delivery Server
586 CVE-2006-4352 (The ArrowPoint cookie functionality for Cisco 11000 series Content ...)
587 NOT-FOR-US: Cisco
588 CVE-2006-4351 (Cross-site scripting (XSS) vulnerability in index.php in OneOrZero ...)
589 NOT-FOR-US: OneOrZero
590 CVE-2006-4350 (SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows ...)
591 NOT-FOR-US: OneOrZero
592 CVE-2006-4349 (** DISPUTED ** ...)
593 NOT-FOR-US: ToendaCMS
594 CVE-2006-4348 (PHP remote file inclusion vulnerability in config.kochsuite.php in the ...)
595 NOT-FOR-US: Kochsuite (com_kochsuite) component for Mambo and Joomla!
596 CVE-2006-4347 (SQL injection vulnerability in user logon authentication request ...)
597 NOT-FOR-US: Cool Manager
598 CVE-2006-4346 (Asterisk 1.2.10 supports the use of client-controlled variables to ...)
599 - asterisk 1:1.2.11.dfsg-1 (medium; bug #385060)
600 CVE-2006-4345 (Stack-based buffer overflow in channels/chan_mgcp.c in MGCP in ...)
601 - asterisk 1:1.2.11.dfsg-1 (medium; bug #385060)
602 CVE-2006-4344 (CRLF injection vulnerability in CGI-Rescue Mail F/W System (formd) ...)
603 NOT-FOR-US: CGI-Rescue Mail F/W System
604 CVE-2006-4343
605 RESERVED
606 CVE-2006-4342
607 RESERVED
608 CVE-2006-4341
609 RESERVED
610 CVE-2006-4340
611 RESERVED
612 CVE-2006-4339 (OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, ...)
613 - openssl 0.9.8b-3 (medium)
614 - openssl097 0.9.7i-2 (medium)
615 - openssl096 <removed>
616 CVE-2006-4338
617 RESERVED
618 CVE-2006-4337
619 RESERVED
620 CVE-2006-4336
621 RESERVED
622 CVE-2006-4335
623 RESERVED
624 CVE-2006-4334
625 RESERVED
626 CVE-2006-4333 (The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows ...)
627 {DSA-1171}
628 - wireshark 0.99.2-5.1 (low; bug #384529)
629 - ethereal <removed> (low; bug #384528)
630 CVE-2006-4332 (Unspecified vulnerability in the DHCP dissector in Wireshark (formerly ...)
631 - wireshark <not-affected> (windows only)
632 - ethereal <not-affected> (windows only)
633 CVE-2006-4331 (Multiple off-by-one errors in the IPSec ESP preference parser in ...)
634 - wireshark 0.99.2-5.1 (medium; bug #384529)
635 - ethereal <not-affected> (only wireshark 0.99.2 affected)
636 CVE-2006-4330 (Unspecified vulnerability in the SCSI dissector in Wireshark (formerly ...)
637 - wireshark 0.99.2-5 (medium; bug #384529)
638 - ethereal <not-affected> (only wireshark 0.99.2 affected)
639 CVE-2006-XXXX [zope Arbitrary file inclusion]
640 TODO: check zope zope-2.7 zope2.8 zope2.9 zope3
641 - zope2.8 2.8.8-2
642 CVE-2006-4329 (Multiple PHP remote file inclusion vulnerabilities in Shadows Rising ...)
643 NOT-FOR-US: Shadows Rising
644 CVE-2006-4328 (SQL injection vulnerability in admin.php in CloudNine Interactive ...)
645 NOT-FOR-US: CloudNine
646 CVE-2006-4327 (Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in ...)
647 NOT-FOR-US: CloudNine
648 CVE-2006-4326 (Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, ...)
649 NOT-FOR-US: Ichitaro
650 CVE-2006-4325 (Cross-site scripting (XSS) vulnerability in gbook.php in Doika ...)
651 NOT-FOR-US: Doika
652 CVE-2006-4324 (Cross-site scripting (XSS) vulnerability in add_url2.php in ...)
653 NOT-FOR-US: CityForFree
654 CVE-2006-4323 (SQL injection vulnerability in list.php in CityForFree indexcity 1.0, ...)
655 NOT-FOR-US: CityForFree
656 CVE-2006-4322 (PHP remote file inclusion vulnerability in estateagent.php in the ...)
657 NOT-FOR-US: Mambo
658 CVE-2006-4321 (PHP remote file inclusion vulnerability in cpg.php in the Coppermine ...)
659 NOT-FOR-US: Mambo
660 CVE-2006-4320 (PHP remote file inclusion vulnerability in sef.php in the OpenSEF ...)
661 NOT-FOR-US: OpenSEF for Joomla
662 CVE-2006-4319 (Buffer overflow in the format command in Solaris 8, 9, and 10 allows ...)
663 NOT-FOR-US: Solaris
664 CVE-2006-4318 (Buffer overflow in WFTPD Server 3.23 allows remote attackers to ...)
665 NOT-FOR-US: WFTPD
666 CVE-2006-4317 (Cross-site scripting (XSS) vulnerability in attachment.php in WoltLab ...)
667 NOT-FOR-US: WoltLab
668 CVE-2006-4316 (SSH Tectia Management Agent 2.1.2 allows local users to gain root ...)
669 NOT-FOR-US: SSH Tectia Management Agent
670 CVE-2006-4315 (Unquoted Windows search path vulnerability in multiple SSH Tectia ...)
671 NOT-FOR-US: SSH Tectia Management Agent
672 CVE-2006-4314 (The manager server in Symantec Enterprise Security Manager (ESM) 6 and ...)
673 NOT-FOR-US: Symantec
674 CVE-2006-4313 (Multiple unspecified vulnerabilities in Cisco VPN 3000 series ...)
675 NOT-FOR-US: Cisco
676 CVE-2006-4312 (Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive ...)
677 NOT-FOR-US: Cisco
678 CVE-2006-4311 (PHP remote file inclusion vulnerability in Sonium Enterprise ...)
679 NOT-FOR-US: Sonium Enterprise Adressbook
680 CVE-2006-4310 (Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of ...)
681 - xulrunner <unfixed>
682 - firefox <unfixed>
683 - mozilla <unfixed>
684 - mozilla-firefox <unfixed>
685 CVE-2006-4309 (VNC server on the AK-Systems Windows Terminal 1.2.5 ExVLP is not ...)
686 NOT-FOR-US: AK-Systems Windows Terminal
687 CVE-2006-4308 (Multiple cross-site scripting (XSS) vulnerabilities in Blackboard ...)
688 NOT-FOR-US: Blackboard Learning System
689 CVE-2006-4307 (Unspecified vulnerability in the format command in Sun Solaris 8 and 9 ...)
690 NOT-FOR-US: Solaris
691 CVE-2006-4306 (Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 ...)
692 NOT-FOR-US: Solaris
693 CVE-2006-4305 (Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote ...)
694 - maxdb-7.5.00 <unfixed> (high; bug #386182)
695 CVE-2006-4304 (Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1 and ...)
696 NOT-FOR-US: FreeBSD NetBSD
697 CVE-2006-4303 (Race condition in (1) libnsl and (2) TLI/XTI API routines in Sun ...)
698 NOT-FOR-US: Solaris
699 CVE-2006-4302 (The Java Plug-in J2SE 1.3.0_02 through 5.0 Update 5, and Java Web ...)
700 TODO: check
701 CVE-2006-4301 (Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a ...)
702 NOT-FOR-US: Microsoft
703 CVE-2006-4300 (SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and ...)
704 NOT-FOR-US: SimpleBlog
705 CVE-2006-4299 (Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in ...)
706 - tikiwiki 1.9.4+dfsg2-2 (low; bug #384796)
707 CVE-2006-4298 (Multiple directory traversal vulnerabilities in cache.php in ...)
708 NOT-FOR-US: osCommerce
709 CVE-2006-4297 (SQL injection vulnerability in shopping_cart.php in osCommerce before ...)
710 NOT-FOR-US: osCommerce
711 CVE-2006-4296 (PHP remote file inclusion vulnerability in classes/Tar.php in ...)
712 NOT-FOR-US: bigAPE-Backup component (com_babackup) for Mambo
713 CVE-2006-4295 (Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ...)
714 NOT-FOR-US: Panda ActiveScan
715 CVE-2006-4294
716 RESERVED
717 CVE-2006-4293 (Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow ...)
718 NOT-FOR-US: cPanel
719 CVE-2006-4292 (Unspecified vulnerability in Niels Provos Honeyd before 1.5b allows ...)
720 - honeyd <unfixed> (low; bug #384806)
721 CVE-2006-4291 (PHP remote file inclusion vulnerability in ...)
722 NOT-FOR-US: PHlyMail Lite
723 CVE-2006-4290 (Directory traversal vulnerability in Sony VAIO Media Server 2.x, 3.x, ...)
724 NOT-FOR-US: Sony
725 CVE-2006-4289 (Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x ...)
726 NOT-FOR-US: Sony
727 CVE-2006-4288 (PHP remote file inclusion vulnerability in admin.a6mambocredits.php in ...)
728 NOT-FOR-US: a6mambocredits component (com_a6mambocredits) for Mambo
729 CVE-2006-4287 (Multiple PHP remote file inclusion vulnerabilities in NES Game and NES ...)
730 NOT-FOR-US: NES Game and NES System
731 CVE-2006-4286 (PHP remote file inclusion vulnerability in contentpublisher.php in the ...)
732 NOT-FOR-US: contentpublisher component (com_contentpublisher) for Mambo
733 CVE-2006-4285 (PHP remote file inclusion vulnerability in news.php in Fantastic News ...)
734 NOT-FOR-US: Fantastic News
735 CVE-2006-4284 (SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier ...)
736 NOT-FOR-US: LBlog
737 CVE-2006-4283 (Multiple PHP remote file inclusion vulnerabilities in SOLMETRA SPAW ...)
738 NOT-FOR-US: SOLMETRA SPAW Editor
739 CVE-2006-4282 (PHP remote file inclusion vulnerability in MamboLogin.php in the ...)
740 NOT-FOR-US: MamboWiki component (com_mambowiki) for Mambo and Joomla!
741 CVE-2006-4281 (PHP remote file inclusion vulnerability in akocomments.php in ...)
742 NOT-FOR-US: AkoComment 1.1 module (com_akocomment) for Mambo
743 CVE-2006-4280 (PHP remote file inclusion vulnerability in anjel.index.php in ANJEL ...)
744 NOT-FOR-US: ANJEL (formerly MaMML) Component (com_anjel) for Mambo
745 CVE-2006-4279 (SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and ...)
746 NOT-FOR-US: XennoBB
747 CVE-2006-4278 (PHP remote file inclusion vulnerability in ...)
748 NOT-FOR-US: SportsPHool
749 CVE-2006-4277 (Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 ...)
750 NOT-FOR-US: Tutti Nova
751 CVE-2006-4276 (PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier ...)
752 NOT-FOR-US: Tutti Nova
753 CVE-2006-4275 (PHP remote file inclusion vulnerability in catalogshop.php in the ...)
754 NOT-FOR-US: CatalogShop component for Mambo (com_catalogshop)
755 CVE-2006-4274
756 REJECTED
757 NOT-FOR-US: Microsoft
758 CVE-2006-4273 (Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 ...)
759 NOT-FOR-US: Jelsoft vBulletin
760 CVE-2006-4272 (** DISPUTED ** ...)
761 NOT-FOR-US: Jelsoft vBulletin
762 CVE-2006-4271 (** DISPUTED ** ...)
763 NOT-FOR-US: Jelsoft vBulletin
764 CVE-2006-4270 (PHP remote file inclusion vulnerability in mambelfish.class.php in the ...)
765 NOT-FOR-US: mambelfish component (com_mambelfish) for Mambo
766 CVE-2006-4269 (PHP remote file inclusion vulnerability in admin.x-shop.php in the ...)
767 NOT-FOR-US: x-shop component (com_x-shop) for Mambo and Joomla!
768 CVE-2006-4268 (Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.11 ...)
769 NOT-FOR-US: CubeCart
770 CVE-2006-4267 (Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier ...)
771 NOT-FOR-US: CubeCart
772 CVE-2006-4266 (Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, ...)
773 NOT-FOR-US: Symantec
774 CVE-2006-4265 (Kaspersky Anti-Hacker 1.8.180, when Stealth Mode is enabled, allows ...)
775 NOT-FOR-US: Kaspersky
776 CVE-2006-4264 (** DISPUTED ** ...)
777 NOT-FOR-US: lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo
778 CVE-2006-4263 (Multiple PHP remote file inclusion vulnerabilities in the Product ...)
779 NOT-FOR-US: mambo-phpshop (com_phpshop) for Mambo and Joomla!
780 CVE-2006-4262 (Multiple buffer overflows in cscope 15.5 and earlier allow ...)
781 - cscope 15.5+cvs20060902-1 (low; bug #385893)
782 CVE-2006-4261 (Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a ...)
783 - xulrunner <unfixed>
784 - firefox <unfixed>
785 - mozilla <unfixed>
786 - mozilla-firefox <unfixed>
787 CVE-2006-4260 (Directory traversal vulnerability in index.php in Fotopholder 1.8 ...)
788 NOT-FOR-US: Fotopholder
789 CVE-2006-4259 (Cross-site scripting (XSS) vulnerability in index.php in Fotopholder ...)
790 NOT-FOR-US: Fotopholder
791 CVE-2006-4258 (Absolute path traversal vulnerability in the get functionality in ...)
792 NOT-FOR-US: Anti-Spam SMTP Proxy
793 CVE-2006-4257 (IBM DB2 Universal Database (UDB) before 8.1 FixPak 13 allows remote ...)
794 NOT-FOR-US: IBM DB2
795 CVE-2006-4256 (index.php in Horde Application Framework before 3.1.2 allows remote ...)
796 - horde3 3.1.3-1 (low; bug #383416)
797 CVE-2006-4255 (Cross-site scripting (XSS) vulnerability in horde/imp/search.php in ...)
798 - imp4 4.1.3-1 (low; bug #383416)
799 CVE-2006-4254 (Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 ...)
800 NOT-FOR-US: IBM AIX
801 CVE-2006-4253 (Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a ...)
802 - xulrunner <unfixed>
803 - firefox <unfixed>
804 - mozilla <unfixed>
805 - mozilla-firefox <unfixed>
806 CVE-2006-4252
807 RESERVED
808 CVE-2006-4251
809 RESERVED
810 CVE-2006-4250
811 RESERVED
812 CVE-2006-4249
813 RESERVED
814 CVE-2006-4248
815 RESERVED
816 CVE-2006-4247
817 RESERVED
818 CVE-2006-4246
819 RESERVED
820 CVE-2006-4245
821 RESERVED
822 CVE-2006-4244 (Unspecified vulnerability in unspecified versions of SQL-Ledger, ...)
823 - sql-ledger <unfixed> (medium)
824 CVE-2006-4243
825 RESERVED
826 CVE-2006-4242 (PHP remote file inclusion vulnerability in install.jim.php in the JIM ...)
827 NOT-FOR-US: JIM component for Joomla or Mambo
828 CVE-2006-4241 (PHP remote file inclusion vulnerability in processor/reporter.sql.php ...)
829 NOT-FOR-US: Reporter Mambo component (com_reporter)
830 CVE-2006-4240 (PHP remote file inclusion vulnerability in index.php in Fusion News ...)
831 NOT-FOR-US: Fusion News
832 CVE-2006-4239 (PHP remote file inclusion vulnerability in include/urights.php in ...)
833 NOT-FOR-US: Outreach Project Tool
834 CVE-2006-4238 (SQL injection vulnerability in torrents.php in WebTorrent (WTcom) ...)
835 NOT-FOR-US: WebTorrent (WTcom)
836 CVE-2006-4237 (PHP remote file inclusion vulnerability in pageheaderdefault.inc.php ...)
837 NOT-FOR-US: Invisionix Roaming System Remote (IRSR)
838 CVE-2006-4236 (Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow ...)
839 NOT-FOR-US: POWERGAP
840 CVE-2006-4235 (Buffer overflow in the import project functionality in Sony SonicStage ...)
841 NOT-FOR-US: Sony
842 CVE-2006-4234 (PHP remote file inclusion vulnerability in classes/query.class.php in ...)
843 NOT-FOR-US: dotProject
844 CVE-2006-4233 (Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allow local ...)
845 NOT-FOR-US: Globus Toolkit
846 CVE-2006-4232 (Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, ...)
847 NOT-FOR-US: Globus Toolkit
848 CVE-2006-4231 (IrfanView 3.98 (with plugins) allows remote attackers to cause a ...)
849 NOT-FOR-US: IrfanView
850 CVE-2006-4230 (Multiple PHP remote file inclusion vulnerabilities in index.php in ...)
851 NOT-FOR-US: Lizge Web Portal
852 CVE-2006-4229 (PHP remote file inclusion vulnerability in archive.php in the ...)
853 NOT-FOR-US: mosListMessenger Component (com_lm) for Mambo and Joomla!
854 CVE-2006-4228 (Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 before ...)
855 NOT-FOR-US: Symantec
856 CVE-2006-4227 (MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid ...)
857 - mysql-dfsg-5.0 5.0.24-3 (low; bug #384798)
858 CVE-2006-4226 (MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when ...)
859 {DSA-1169}
860 - mysql-dfsg-5.0 5.0.24-3 (low; bug #384798)
861 [sarge] - mysql-dfsg <not-affected> (Vulnerable code not present)
862 CVE-2006-4225
863 REJECTED
864 CVE-2006-4224 (Cross-site scripting (XSS) vulnerability in calendar.php in Virtual ...)
865 NOT-FOR-US: Virtual War
866 CVE-2006-4223 (IBM WebSphere Application Server before 6.0.2.13 allows ...)
867 NOT-FOR-US: IBM WebSphere Application
868 CVE-2006-4222 (Multiple unspecified vulnerabilities in IBM WebSphere Application ...)
869 NOT-FOR-US: IBM WebSphere Application
870 CVE-2006-4221 (Stack-based buffer overflow in the IBM Access Support eGatherer ...)
871 NOT-FOR-US: IBM
872 CVE-2006-4220
873 RESERVED
874 CVE-2006-4219 (The Terminal Services COM object (tsuserex.dll) allows remote ...)
875 NOT-FOR-US: Terminal Services COM object
876 CVE-2006-4218 (Directory traversal vulnerability in Zen Cart 1.3.0.2 and earlier ...)
877 NOT-FOR-US: Zen Cart
878 CVE-2006-4217 (PHP remote file inclusion vulnerability in ...)
879 NOT-FOR-US: WEBInsta CMS
880 CVE-2006-4216
881 REJECTED
882 NOT-FOR-US: Chaussette
883 CVE-2006-4215 (PHP remote file inclusion vulnerability in index.php in Zen Cart ...)
884 NOT-FOR-US: Zen Cart
885 CVE-2006-4214 (Multiple SQL injection vulnerabilities in Zen Cart 1.3.0.2 and earlier ...)
886 NOT-FOR-US: Zen Cart
887 CVE-2006-4213 (PHP remote file inclusion vulnerability in config.php in David Kent ...)
888 NOT-FOR-US: Thatware
889 CVE-2006-4212 (SQL injection vulnerability in b0zz and Chris Vincent Owl Intranet ...)
890 NOT-FOR-US: Owl Intranet Engine
891 CVE-2006-4211 (Cross-site scripting (XSS) vulnerability in b0zz and Chris Vincent Owl ...)
892 NOT-FOR-US: Owl Intranet Engine
893 CVE-2006-4210 (nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when ...)
894 NOT-FOR-US: phPay
895 CVE-2006-4209 (PHP remote file inclusion vulnerability in install3.php in WEBInsta ...)
896 NOT-FOR-US: WEBInsta Mailing List Manager
897 CVE-2006-4208 (Directory traversal vulnerability in wp-db-backup.php in Skippy ...)
898 - wordpress <unfixed> (low; bug #384800)
899 CVE-2006-4207 (Multiple PHP remote file inclusion vulnerabilities in Bob Jewell ...)
900 NOT-FOR-US: Discloser
901 CVE-2006-4206 (Cross-site scripting (XSS) vulnerability in calendar.asp in ...)
902 NOT-FOR-US: ASPPlayground.NET Forum Advanced Edition
903 CVE-2006-4205 (Multiple PHP remote file inclusion vulnerabilities in WebDynamite ...)
904 NOT-FOR-US: WebDynamite ProjectButler
905 CVE-2006-4204 (Multile PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and ...)
906 NOT-FOR-US: PHProjekt
907 CVE-2006-4203 (PHP remote file inclusion vulnerability in help.mmp.php in the MMP ...)
908 NOT-FOR-US: MMP Component (com_mmp) for Mambo
909 CVE-2006-4202 (SQL injection vulnerability in proje_goster.php in Spidey Blog Script ...)
910 NOT-FOR-US: Spidey Blog Script
911 CVE-2006-4201 (Unspecified vulnerability in the backup agent and Cell Manager in HP ...)
912 NOT-FOR-US: HP OpenView Storage Data Protector
913 CVE-2006-4200 (Unspecified vulnerability in 04WebServer 1.83 and earlier allows ...)
914 NOT-FOR-US: 04WebServer
915 CVE-2006-4199 (Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 ...)
916 NOT-FOR-US: 04WebServer
917 CVE-2006-4198 (PHP remote file inclusion vulnerability in includes/session.php in ...)
918 NOT-FOR-US: Wheatblog
919 CVE-2006-4197 (Multiple buffer overflows in libmusicbrainz (aka mb_client or ...)
920 {DSA-1162}
921 - libmusicbrainz-2.1 2.1.4-1 (medium; bug #383030)
922 - libmusicbrainz-2.0 <removed> (medium; bug #383031)
923 CVE-2006-4196 (PHP remote file inclusion vulnerability in index.php in WEBInsta CMS ...)
924 NOT-FOR-US: WEBInsta CMS
925 CVE-2006-4195 (PHP remote file inclusion vulnerability in param.peoplebook.php in the ...)
926 NOT-FOR-US: Peoplebook Component for Mambo (com_peoplebook)
927 CVE-2005-4808 (Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) ...)
928 - binutils 2.17-1 (low)
929 [sarge] - binutils <no-dsa> (Only a security-problems in far-fetched configurations)
930 CVE-2005-4807 (Stack-based buffer overflow in the as_bad function in messages.c in ...)
931 - binutils 2.17-1 (low)
932 [sarge] - binutils <no-dsa> (Only a security-problems in far-fetched configurations)
933 CVE-2004-2663 (The (1) SetDebugging and (2) RunEgatherer methods in IBM Access ...)
934 NOT-FOR-US: IBM
935 CVE-2004-2662 (Soft3304 04WebServer before 1.41 allows remote attackers to cause a ...)
936 NOT-FOR-US: 04WebServer
937 CVE-2004-2661 (Soft3304 04WebServer before 1.41 does not properly check file names, ...)
938 NOT-FOR-US: 04WebServer
939 CVE-2002-2216 (Soft3304 04WebServer before 1.20 does not properly process URL ...)
940 NOT-FOR-US: 04WebServer
941 CVE-2006-XXXX [gallery2 session ID disclosure]
942 - gallery2 2.1.2-1
943 CVE-2006-XXXX [insecure filehandling in mysql_upgrade]
944 - mysql-dfsg-5.0 5.0.24-1
945 TODO: check 4.x
946 CVE-2006-4194 (** DISPUTED ** ...)
947 NOT-FOR-US: Cisco
948 CVE-2006-4193 (Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows ...)
949 NOT-FOR-US: MS IE
950 CVE-2006-4192 (Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and ...)
951 - libmodplug <unfixed> (medium; bug #383574)
952 CVE-2006-4191 (Directory traversal vulnerability in memcp.php in XMB (Extreme Message ...)
953 NOT-FOR-US: XMB
954 CVE-2006-4190 (Directory traversal vulnerability in autohtml.php in the AutoHTML ...)
955 NOT-FOR-US: PHP-Nuke module AutoHTML
956 CVE-2006-4189 (Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 ...)
957 NOT-FOR-US: Dolphin
958 CVE-2006-4188 (Unspecified vulnerability in the LP subsystem in HP-UX B.11.00, ...)
959 NOT-FOR-US: HP-UX
960 CVE-2006-4187 (Unspecified vulnerability in HP-UX B.11.00, B.11.11 and B.11.23, when ...)
961 NOT-FOR-US: HP-UX
962 CVE-2006-4186 (The iManager in eMBoxClient.jar in Novell eDirectory 8.7.3.8 writes ...)
963 NOT-FOR-US: Novell eDirectory
964 CVE-2006-4185 (Unspecified vulnerability in the NCPENGINE in Novell eDirectory ...)
965 NOT-FOR-US: Novell eDirectory
966 CVE-2006-4184 (SmartLine DeviceLock before 5.73 Build 305 does not properly enforce ...)
967 NOT-FOR-US: SmartLine DeviceLock
968 CVE-2006-4183
969 RESERVED
970 CVE-2006-4182
971 RESERVED
972 CVE-2006-4181
973 RESERVED
974 CVE-2006-4180
975 RESERVED
976 CVE-2006-4179
977 RESERVED
978 CVE-2006-4178
979 RESERVED
980 CVE-2006-4177
981 RESERVED
982 CVE-2006-4176
983 RESERVED
984 CVE-2006-4175
985 RESERVED
986 CVE-2006-4174
987 RESERVED
988 CVE-2006-4173
989 RESERVED
990 CVE-2006-4172
991 RESERVED
992 CVE-2006-4171
993 RESERVED
994 CVE-2006-4170
995 RESERVED
996 CVE-2006-4169
997 RESERVED
998 CVE-2006-4168
999 RESERVED
1000 CVE-2006-4167
1001 RESERVED
1002 CVE-2006-4166 (PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and ...)
1003 NOT-FOR-US: TinyWebGallery
1004 CVE-2006-4165 (Cross-site scripting (XSS) vulnerability in NetCommons 1.0.8 and ...)
1005 NOT-FOR-US: NetCommons
1006 CVE-2006-4164 (PHP remote file inclusion vulnerability in inc/header.inc.php in ...)
1007 NOT-FOR-US: phpPrintAnalyzer
1008 CVE-2006-4163 (** DISPUTED ** ...)
1009 NOT-FOR-US: miniBloggie
1010 CVE-2006-4162 (Cross-site scripting (XSS) vulnerability in Dragonfly CMS 9.0.6.1 and ...)
1011 NOT-FOR-US: Dragonfly CMS
1012 CVE-2006-4161 (Directory traversal vulnerability in the avatar_gallery action in ...)
1013 NOT-FOR-US: XennoBB
1014 CVE-2006-4160 (Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and ...)
1015 NOT-FOR-US: MVCnPHP
1016 CVE-2006-4159 (Multiple PHP remote file inclusion vulnerabilities in Chaussette ...)
1017 NOT-FOR-US: Chaussette
1018 CVE-2006-4158 (PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 ...)
1019 NOT-FOR-US: Spaminator
1020 CVE-2006-4157 (Cross-site scripting (XSS) vulnerability in index.php in Yet another ...)
1021 NOT-FOR-US: Yet another Bulletin Board (YaBB)
1022 CVE-2006-4156 (** DISPUTED ** ...)
1023 NOT-FOR-US: pearlabs mafia moblog
1024 CVE-2006-4155 (Unspecified vulnerability in func_topic_threaded.php (aka threaded ...)
1025 NOT-FOR-US: Invision Power Board (IPB)
1026 CVE-2006-4154
1027 RESERVED
1028 CVE-2006-4153
1029 RESERVED
1030 CVE-2006-4152
1031 RESERVED
1032 CVE-2006-4151
1033 RESERVED
1034 CVE-2006-4150
1035 RESERVED
1036 CVE-2006-4149
1037 RESERVED
1038 CVE-2006-4148
1039 RESERVED
1040 CVE-2006-4147
1041 RESERVED
1042 CVE-2006-4146 (Buffer overflow in the (1) DWARF (dwarfread.c) and DWARF2 ...)
1043 - gdb <unfixed> (unimportant)
1044 NOTE: Every sensible use of gdb involves executing the debugged binary
1045 TODO: file bug
1046 CVE-2006-4145 (The Universal Disk Format (UDF) filesystem driver in Linux kernel ...)
1047 - linux-2.6 2.6.17-7
1048 - linux-2.6.16 <unfixed>
1049 CVE-2006-4143 (Netgear FVG318 running firmware 1.0.40 allows remote attackers to ...)
1050 NOT-FOR-US: Netgear
1051 CVE-2006-4142 (SQL injection vulnerability in extra/online.php in Virtual War (VWar) ...)
1052 NOT-FOR-US: Virtual War (VWar)
1053 CVE-2006-4141 (SQL injection vulnerability in news.php in Virtual War (VWar) 1.5.0 ...)
1054 NOT-FOR-US: Virtual War (VWar)
1055 CVE-2006-4140 (Directory traversal vulnerability in IPCheck Server Monitor before ...)
1056 NOT-FOR-US: IPCheck Server Monitor
1057 CVE-2006-4139 (Race condition in Sun Solaris 10 allows attackers to cause a denial of ...)
1058 NOT-FOR-US: Solaris
1059 CVE-2006-4138 (Multiple unspecified vulnerabilities in Microsoft Windows Help File ...)
1060 NOT-FOR-US: Microsoft
1061 CVE-2006-4137 (IBM WebSphere Application Server before 6.1.0.1 allows attackers to ...)
1062 NOT-FOR-US: IBM WebSphere
1063 CVE-2006-4136 (Multiple unspecified vulnerabilities in IBM WebSphere Application ...)
1064 NOT-FOR-US: IBM WebSphere
1065 CVE-2006-4135 (** DISPUTED ** ...)
1066 NOT-FOR-US: Calendarix
1067 CVE-2006-4134 (Unspecified vulnerability related to a &quot;design flaw&quot; in SAP Internet ...)
1068 NOT-FOR-US: SAP
1069 CVE-2006-4133 (Buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and ...)
1070 NOT-FOR-US: SAP
1071 CVE-2006-4132 (ArcSoft MMS Composer 1.5.5.6 and possibly earlier, and 2.0.0.13 and ...)
1072 NOT-FOR-US: ArcSoft MMS Composer
1073 CVE-2006-4131 (Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and ...)
1074 NOT-FOR-US: ArcSoft MMS Composer
1075 CVE-2006-4130 (PHP remote file inclusion vulnerability in admin.remository.php in the ...)
1076 NOT-FOR-US: Remository Component (com_remository) for Mambo and Joomla!
1077 CVE-2006-4129 (PHP remote file inclusion vulnerability in admin.webring.docs.php in ...)
1078 NOT-FOR-US: Webring Component (com_webring) for Joomla!
1079 CVE-2006-4128 (Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec ...)
1080 NOT-FOR-US: Symantec VERITAS
1081 CVE-2006-4127 (Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and ...)
1082 NOT-FOR-US: DConnect Daemon (dcd)
1083 CVE-2006-4126 (The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier ...)
1084 NOT-FOR-US: DConnect Daemon (dcd)
1085 CVE-2006-4125 (Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and ...)
1086 NOT-FOR-US: DConnect Daemon (dcd)
1087 CVE-2006-4124 (The libXm library in LessTif 0.95.0 and earlier allows local users to ...)
1088 - lesstif2 <unfixed> (bug #382411; low)
1089 CVE-2006-4123 (PHP remote file inclusion vulnerability in boitenews4/index.php in ...)
1090 NOT-FOR-US: Boite de News
1091 CVE-2006-4122 (Simple one-file guestbook 1.0 and earlier allows remote attackers to ...)
1092 NOT-FOR-US: Simple one-file guestbook
1093 CVE-2006-4121 (PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce ...)
1094 NOT-FOR-US: See-Commerce
1095 CVE-2006-4120 (Cross-site scripting (XSS) vulnerability in the Recipe module ...)
1096 NOT-FOR-US: Recipe module (recipe.module) for Drupal
1097 CVE-2006-4119 (SQL injection vulnerability in gc.php in GeheimChaos 0.5 and earlier ...)
1098 NOT-FOR-US: GeheimChaos
1099 CVE-2006-4118 (Multiple SQL injection vulnerabilities in GeheimChaos 0.5 and earlier ...)
1100 NOT-FOR-US: GeheimChaos
1101 CVE-2006-4117 (The squeue_drain function in Sun Solaris 10, possibly only when run on ...)
1102 NOT-FOR-US: Solaris
1103 CVE-2006-4116 (Multiple stack-based buffer overflows in Lhaz before 1.32 allow ...)
1104 NOT-FOR-US: Lhaz
1105 CVE-2006-4115 (PHP remote file inclusion vulnerability in common.inc.php in PgMarket ...)
1106 NOT-FOR-US: PgMarket
1107 CVE-2006-4114 (SQL injection vulnerability in view_com.php in Nicolas Grandjean ...)
1108 NOT-FOR-US: PHPMyRing
1109 CVE-2006-4113 (PHP remote file inclusion vulnerability in genpage-cgi.php in Brian ...)
1110 NOT-FOR-US: hitweb
1111 CVE-2006-4112 (Unspecified vulnerability in the &quot;dependency resolution mechanism&quot; in ...)
1112 - rails 1.1.6-1 (bug #382255; medium)
1113 CVE-2006-4111 (Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby ...)
1114 - rails 1.1.5-1 (bug #382255; medium)
1115 CVE-2006-4110 (Apache 2.2.2, when running on Windows, allows remote attackers to read ...)
1116 - apache2 <not-affected> (Affects Apache on Windows only)
1117 CVE-2006-4109 (Cross-site scripting (XSS) vulnerability in Bibliography ...)
1118 NOT-FOR-US: Bibliography (biblio.module) for Drupal
1119 CVE-2006-4108 (SQL injection vulnerability in Bibliography (biblio.module) 4.6 before ...)
1120 NOT-FOR-US: Bibliography (biblio.module) for Drupal
1121 CVE-2006-4107 (SQL injection vulnerability in the Job Search module (job.module) 4.6 ...)
1122 NOT-FOR-US: Job Search module (job.module) for Drupal
1123 CVE-2006-4106 (Cross-site scripting (XSS) vulnerability in blursoft blur6ex 0.3 ...)
1124 NOT-FOR-US: blur6ex
1125 CVE-2006-4105 (Cross-site scripting (XSS) vulnerability in Fill Threads Database ...)
1126 NOT-FOR-US: Fill Threads Database
1127 CVE-2006-4104 (Cross-site scripting (XSS) vulnerability in admin.cgi in ...)
1128 NOT-FOR-US: mojoGallery
1129 CVE-2006-4103 (PHP remote file inclusion vulnerability in article-raw.php in Jason ...)
1130 NOT-FOR-US: phNNTP
1131 CVE-2006-4102 (PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme ...)
1132 NOT-FOR-US: SQLiteWebAdmin
1133 CVE-2006-4101
1134 RESERVED
1135 CVE-2006-4100
1136 RESERVED
1137 CVE-2006-4099
1138 RESERVED
1139 CVE-2006-4098
1140 RESERVED
1141 CVE-2006-4097
1142 RESERVED
1143 CVE-2006-4096 (BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to ...)
1144 - bind <unfixed> (medium)
1145 - bind9 1:9.3.2-P1-1 (medium; bug #386245)
1146 NOTE: there is no info whether bind 8 is affected
1147 CVE-2006-4095 (BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers ...)
1148 - bind <unfixed> (medium)
1149 - bind9 1:9.3.2-P1-1 (medium; bug #386245)
1150 NOTE: there is no info whether bind 8 is affected
1151 CVE-2006-4094
1152 RESERVED
1153 CVE-2006-4093 (Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on ...)
1154 - linux-2.6 2.6.17-7
1155 - linux-2.6.16 <unfixed>
1156 CVE-2006-4092 (Simpliciti Locked Browser does not properly limit a user's actions to ...)
1157 NOT-FOR-US: Simpliciti Locked Browser
1158 CVE-2006-4091 (Multiple cross-site scripting (XSS) vulnerabilities in Archangel ...)
1159 NOT-FOR-US: Archangel Weblog
1160 CVE-2006-4090 (Cross-site scripting (XSS) vulnerability in Webligo BlogHoster 2.2 ...)
1161 NOT-FOR-US: Webligo BlogHoster
1162 CVE-2006-4089 (Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and ...)
1163 - alsaplayer <unfixed> (medium; bug #382842)
1164 CVE-2006-4088 (Multiple cross-site scripting (XSS) vulnerabilities in CivicSpace ...)
1165 NOT-FOR-US: CivicSpace
1166 CVE-2006-4087 (Cross-site scripting (XSS) vulnerability in admin.cgi in ...)
1167 NOT-FOR-US: mojoGallery
1168 CVE-2006-4086 (Cross-site scripting (XSS) vulnerability in index.php in Elaine Aquino ...)
1169 NOT-FOR-US: Online Zone Journals (OZJournals)
1170 CVE-2006-4085 (PHP remote file inclusion vulnerability in Olaf Noehring The Search ...)
1171 NOT-FOR-US: The Search Engine Project (TSEP)
1172 CVE-2006-4084 (Unspecified vulnerability in phpAutoMembersArea (phpAMA) before 3.2.4 ...)
1173 NOT-FOR-US: phpAutoMembersArea (phpAMA)
1174 CVE-2006-4083 (PHP remote file inclusion vulnerability in viewevent.php in myWebland ...)
1175 NOT-FOR-US: myEvent
1176 CVE-2006-4082 (Barracuda Spam Firewall (BSF), possibly 3.3.03.053, contains a ...)
1177 NOT-FOR-US: Barracuda Spam Firewall
1178 CVE-2006-4081 (preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through ...)
1179 NOT-FOR-US: Barracuda Spam Firewall
1180 CVE-2006-4080 (DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 ...)
1181 NOT-FOR-US: DeluxeBB
1182 CVE-2006-4079 (Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB ...)
1183 NOT-FOR-US: DeluxeBB
1184 CVE-2006-4078 (pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, ...)
1185 NOT-FOR-US: DeluxeBB
1186 CVE-2006-4077 (PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo ...)
1187 NOT-FOR-US: Comet WebFileManager
1188 CVE-2006-4076 (Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer ...)
1189 NOT-FOR-US: docpile: wim's edition
1190 CVE-2006-4075 (Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer ...)
1191 NOT-FOR-US: docpile: wim's edition
1192 CVE-2006-4074 (PHP remote file inclusion vulnerability in lib/tpl/default/main.php in ...)
1193 NOT-FOR-US: JD-Wiki Component (com_jd-wiki) for Joomla!
1194 CVE-2006-4073 (Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz ...)
1195 NOT-FOR-US: phpCC
1196 CVE-2006-4072 (Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 ...)
1197 NOT-FOR-US: Club-Nuke [XP]
1198 CVE-2006-4144 (Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick ...)
1199 - imagemagick <unfixed> (medium; bug #383314)
1200 - graphicsmagick 1.1.7-7 (medium; bug #383333)
1201 CVE-2006-XXXX [crash in the certificate verification logic]
1202 NOTE: GNUTLS-SA-2006-2
1203 - gnutls11 <unfixed> (low)
1204 - gnutls12 1.2.11-3 (low)
1205 - gnutls13 1.4.2-1 (low)
1206 CVE-2006-4071 (Sign extension vulnerability in the createBrushIndirect function in ...)
1207 NOT-FOR-US: Microsoft
1208 CVE-2006-4070 (Format string vulnerability in Imendio Planner 0.13 allows ...)
1209 NOT-FOR-US: Imendio Planner
1210 CVE-2006-4069 (Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino ...)
1211 NOT-FOR-US: Online Zone Journals (OZJournals)
1212 CVE-2006-4068 (The pswd.js script relies on the client to calculate whether a ...)
1213 NOT-FOR-US: pswd.js
1214 CVE-2006-4067 (Cross-site scripting (XSS) vulnerability in cake/libs/error.php in ...)
1215 NOT-FOR-US: CakePHP
1216 CVE-2006-4066 (The Graphical Device Interface Plus library (gdiplus.dll) in Microsoft ...)
1217 NOT-FOR-US: Microsoft
1218 CVE-2006-4065 (Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko ...)
1219 NOT-FOR-US: SAPID Gallery
1220 CVE-2006-4064 (SQL injection vulnerability in default.asp in YenerTurk Haber Script ...)
1221 NOT-FOR-US: YenerTurk Haber Script
1222 CVE-2006-4063 (Multiple PHP remote file inclusion vulnerabilities in Csaba Godor ...)
1223 NOT-FOR-US: SAPID Blog
1224 CVE-2006-4062 (PHP remote file inclusion vulnerability in ...)
1225 NOT-FOR-US: SAPID Shop
1226 CVE-2006-4061 (PHP remote file inclusion vulnerability in index.php in Thomas Pequet ...)
1227 NOT-FOR-US: phpPrintAnalyzer
1228 CVE-2006-4060 (PHP remote file inclusion vulnerability in calendar.php in Visual ...)
1229 NOT-FOR-US: Visual Events Calendar
1230 CVE-2006-4059 (Multiple PHP remote file inclusion vulnerabilities in USOLVED ...)
1231 NOT-FOR-US: USOLVED NEWSolved Lite
1232 CVE-2006-4058 (Cross-site scripting (XSS) vulnerability in archive.php in Simplog ...)
1233 NOT-FOR-US: Simplog
1234 CVE-2006-4057 (Buffer overflow in the preview_create function in gui.cpp in Mitch ...)
1235 NOT-FOR-US: Eremove
1236 CVE-2006-4056 (Multiple SQL injection vulnerabilities in the authentication process ...)
1237 NOT-FOR-US: katzlbt The Address Book
1238 CVE-2006-4055 (Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring ...)
1239 NOT-FOR-US: The Search Engine Project (TSEP)
1240 CVE-2006-4054 (Multiple PHP remote file inclusion vulnerabilities in ME Download ...)
1241 NOT-FOR-US: ME Download System
1242 CVE-2006-4053 (PHP remote file inclusion vulnerability in templates/header.php in ME ...)
1243 NOT-FOR-US: ME Download System
1244 CVE-2006-4052 (Multiple PHP remote file inclusion vulnerabilities in Turnkey Web ...)
1245 NOT-FOR-US: Turnkey Web Tools PHP Simple Shop
1246 CVE-2006-4051 (PHP remote file inclusion vulnerability in global.php in Turnkey Web ...)
1247 NOT-FOR-US: Turnkey Web Tools PHP Live Helper
1248 CVE-2006-4050 (PHP remote file inclusion vulnerability in auto_check_renewals.php in ...)
1249 NOT-FOR-US: phpAutoMembersArea (phpAMA)
1250 CVE-2006-4049 (Unspecified vulnerability in the utxconfig utility in Sun Ray Server ...)
1251 NOT-FOR-US: Sun
1252 CVE-2006-4048 (Netious CMS 0.4 initializes session IDs based on the client IP ...)
1253 NOT-FOR-US: Netious CMS
1254 CVE-2006-4047 (SQL injection vulnerability in index.php in Netious CMS 0.4 and ...)
1255 NOT-FOR-US: Netious CMS
1256 CVE-2006-4045 (PHP remote file inclusion vulnerability in news.php in Torbstoff News ...)
1257 NOT-FOR-US: Torbstoff News
1258 CVE-2006-4044 (PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad ...)
1259 NOT-FOR-US: phpCodeCabinet
1260 CVE-2006-4043 (index.php in myWebland myBloggie 2.1.4 and earlier allows remote ...)
1261 NOT-FOR-US: myWebland myBloggie
1262 CVE-2006-4042 (Multiple SQL injection vulnerabilities in trackback.php in myWebland ...)
1263 NOT-FOR-US: myWebland myBloggie
1264 CVE-2006-4041 (SQL injection vulnerability in Pike before 7.6.86, when using a ...)
1265 - pike7.6 7.6.86-1
1266 [sarge] - pike7.2 <unfixed> (bug #382607)
1267 CVE-2006-4040 (PHP remote file inclusion vulnerability in myevent.php in myWebland ...)
1268 NOT-FOR-US: myWebland myEvent
1269 CVE-2006-4039 (Multiple SQL injection vulnerabilities in eintragen.php in GaesteChaos ...)
1270 NOT-FOR-US: GaesteChaos
1271 CVE-2006-4038 (Multiple cross-site scripting (XSS) vulnerabilities in eintragen.php ...)
1272 NOT-FOR-US: GaesteChaos
1273 CVE-2006-4037 (Unspecified vulnerability in Fenestrae Faxination Server allows remote ...)
1274 NOT-FOR-US: Fenestrae Faxination Server
1275 CVE-2006-4036 (PHP remote file inclusion vulnerability in ...)
1276 NOT-FOR-US: ZoneX Publishers
1277 CVE-2006-4035 (SQL injection vulnerability in counterchaos.php in CounterChaos 0.48c ...)
1278 NOT-FOR-US: CounterChaos
1279 CVE-2006-4034 (PHP remote file inclusion vulnerability in include/html/config.php in ...)
1280 NOT-FOR-US: ModernGigabyte ModernBill
1281 CVE-2006-4033 (Heap-based buffer overflow in Lhaplus.exe in Lhaplus 1.52, and ...)
1282 NOT-FOR-US: Lhaplus
1283 CVE-2006-4032 (Unspecified vulnerability in Cisco IOS CallManager Express (CME) ...)
1284 NOT-FOR-US: Cisco
1285 CVE-2006-4031 (MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to ...)
1286 - mysql-dfsg-5.0 5.0.24-1 (bug #382415; low)
1287 - mysql-dfsg <removed> (bug #380271; low)
1288 [sarge] - mysql-dfsg-4.1 <no-dsa> (Now documented design error, no real fix feasible)
1289 [sarge] - mysql-dfsg <no-dsa> (Now documented design error, no real fix feasible)
1290 CVE-2006-4030 (Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and ...)
1291 {DSA-1148-1}
1292 - gallery 1.5.3-1
1293 TODO: check gallery2
1294 CVE-2006-4029 (Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 ...)
1295 NOT-FOR-US: AGEphone
1296 CVE-2006-4028 (Multiple unspecified vulnerabilities in WordPress before 2.0.4 have ...)
1297 - wordpress 2.0.4-1
1298 CVE-2006-4027
1299 RESERVED
1300 CVE-2006-XXXX [realtime-lsm-source: wrong permissions might lead to local root]
1301 - realtime-lsm 0.8.7-2 (bug #382161; low)
1302 [sarge] - realtime-lsm <not-affected>
1303 NOTE: only to user 1017 or group 1001 and only while root is building the module
1304 CVE-2006-4026 (PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows ...)
1305 NOT-FOR-US: SAPID CMS
1306 CVE-2006-4025 (SQL injection vulnerability in profile.php in XennoBB 2.1.0 and ...)
1307 NOT-FOR-US: XennoBB
1308 CVE-2006-4024 (The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through ...)
1309 - festalon <not-affected> (vuln. code introduced in 0.5.0)
1310 CVE-2006-4023 (The ip2long function in PHP 5.1.4 and earlier may incorrectly validate ...)
1311 - php5 <unfixed> (unimportant; bug #382257)
1312 - php4 <unfixed> (unimportant; bug #382270)
1313 NOTE: Not every lack of protection of programmer's flaws is a vulnerability
1314 NOTE: See notes by Sean for details
1315 NOTE: > the entry states that this is more likely a bug in any
1316 NOTE: > applications not performing further validation/sanitizing,
1317 NOTE: > and i tend to agree based on the php.net documentation, which
1318 NOTE: > states: "ip2long() should not be used as the sole form of IP
1319 NOTE: > validation. Combine it with long2ip()".
1320 CVE-2006-4022 (Intel 2100 PRO/Wireless Network Connection driver PROSet before ...)
1321 NOT-FOR-US: Intel Windows driver
1322 CVE-2006-4021 (The cryptographic module in ScatterChat 1.0.x allows attackers to ...)
1323 NOT-FOR-US: ScatterChat
1324 CVE-2006-4020 (scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows ...)
1325 - php5 5.1.6-1 (medium; bug #382256)
1326 - php4 4:4.4.4-1 (medium; bug #382261)
1327 CVE-2006-4019 (Dynamic variable evaluation vulnerability in compose.php in ...)
1328 {DSA-1154}
1329 - squirrelmail 2:1.4.8-1
1330 CVE-2006-4018 (Heap-based buffer overflow in the pefromupx function in ...)
1331 {DSA-1153}
1332 - clamav 0.88.4-1 (high; bug #382004; bug #382007)
1333 CVE-2006-4017 (Cross-site scripting (XSS) vulnerability in the search module in Inter ...)
1334 NOT-FOR-US: Inter Network Marketing (INM) CMS G3
1335 CVE-2006-4016 (Cross-site scripting (XSS) vulnerability in /toendaCMS in toendaCMS ...)
1336 NOT-FOR-US: toendaCMS
1337 CVE-2006-4015 (Hewlett-Packard (HP) ProCurve 3500yl, 6200yl, and 5400zl switches with ...)
1338 NOT-FOR-US: Hewlett-Packard
1339 CVE-2006-4014 (Symantec Brightmail AntiSpam (SBAS) before 6.0.4, when the Control ...)
1340 NOT-FOR-US: Symantec
1341 CVE-2006-4013 (Multiple directory traversal vulnerabilities in Symantec Brightmail ...)
1342 NOT-FOR-US: Symantec
1343 CVE-2006-4012 (Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb ...)
1344 NOT-FOR-US: circeOS SaveWeb
1345 CVE-2006-4011 (PHP remote file inclusion vulnerability in ...)
1346 NOT-FOR-US: Kayako eSupport
1347 CVE-2006-4010 (SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and ...)
1348 NOT-FOR-US: Virtual War
1349 CVE-2006-4009 (Cross-site scripting (XSS) vulnerability in war.php in Virtual War ...)
1350 NOT-FOR-US: Virtual War
1351 CVE-2006-4008 (PHP remote file inclusion vulnerability in index.php in Knusperleicht ...)
1352 NOT-FOR-US: Knusperleicht Guestbook
1353 CVE-2006-4007 (PHP remote file inclusion vulnerability in index.php in Knusperleicht ...)
1354 NOT-FOR-US: Knusperleicht Faq
1355 CVE-2006-4006 (The do_gameinfo functionin BomberClone 0.11.6 and earlier, and ...)
1356 - bomberclone 0.11.7-1 (bug #382082; medium)
1357 CVE-2006-4005 (BomberClone 0.11.6 and earlier allows remote attackers to cause a ...)
1358 - bomberclone 0.11.7-1 (bug #382082; medium)
1359 CVE-2006-4004 (Directory traversal vulnerability in index.php in vbPortal 3.0.2 ...)
1360 NOT-FOR-US: vbPortal
1361 CVE-2006-4003 (The config method in Henrik Storner Hobbit monitor before 4.1.2p2 ...)
1362 NOT-FOR-US: Henrik Storner Hobbit monitor
1363 CVE-2006-4002 (Cross-site scripting (XSS) vulnerability in user.module in Drupal 4.6 ...)
1364 {DSA-1147-1}
1365 - drupal 4.5.8-2 (bug #382087; medium)
1366 CVE-2006-4001 (Login.pm in Barracuda Spam Firewall (BSF) 3.3.01.001 through ...)
1367 NOT-FOR-US: Barracuda Spam Firewall
1368 CVE-2006-4000 (Directory traversal vulnerability in cgi-bin/preview_email.cgi in ...)
1369 NOT-FOR-US: Barracuda Spam Firewall
1370 CVE-2006-3999 (ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier ...)
1371 NOT-FOR-US: ISS BlackICE
1372 CVE-2006-3998 (PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka ...)
1373 NOT-FOR-US: WoWRoster
1374 CVE-2006-3997 (PHP remote file inclusion vulnerability in hsList.php in WoWRoster ...)
1375 NOT-FOR-US: WoWRoster
1376 CVE-2006-3996 (SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and ...)
1377 NOT-FOR-US: ATutor
1378 CVE-2006-3995 (Multiple PHP remote file inclusion vulnerabilities in (1) ...)
1379 NOT-FOR-US: UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo
1380 CVE-2006-3994 (SQL injection vulnerability in the u2u_send_recp function in ...)
1381 NOT-FOR-US: XMB (aka extreme message board)
1382 CVE-2006-3993 (PHP remote file inclusion vulnerability in copyright.php in Olaf ...)
1383 NOT-FOR-US: The Search Engine Project
1384 CVE-2006-3992 (Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) ...)
1385 NOT-FOR-US: Intel
1386 CVE-2006-3991 (PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh ...)
1387 NOT-FOR-US: Voodoo chat
1388 CVE-2006-3990 (Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones ...)
1389 - egroupware <unfixed> (bug #382207; medium)
1390 CVE-2006-3989 (PHP remote file inclusion vulnerability in index.php in Knusperleicht ...)
1391 NOT-FOR-US: Knusperleicht
1392 CVE-2006-3988 (PHP remote file inclusion vulnerability in index.php in Knusperleicht ...)
1393 NOT-FOR-US: Knusperleicht
1394 CVE-2006-3987 (Multiple PHP remote file inclusion vulnerabilities in index.php in ...)
1395 NOT-FOR-US: Knusperleicht
1396 CVE-2006-3986 (PHP remote file inclusion vulnerability in index.php in Knusperleicht ...)
1397 NOT-FOR-US: Knusperleicht
1398 CVE-2006-3985 (Stack-based buffer overflow in DZIPS32.DLL 6.0.0.4 in ConeXware ...)
1399 NOT-FOR-US: ConeXware
1400 CVE-2006-3984 (PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in ...)
1401 NOT-FOR-US: Phpauction
1402 CVE-2006-3983 (PHP remote file inclusion vulnerability in editprofile.php in ...)
1403 NOT-FOR-US: php(Reactor)
1404 CVE-2006-3982 (PHP remote file inclusion vulnerability in quickie.php in ...)
1405 NOT-FOR-US: Knusperleicht
1406 CVE-2006-3981 (PHP remote file inclusion vulnerability in about.mgm.php in Mambo ...)
1407 NOT-FOR-US: Mambo Gallery Manager for Mambo
1408 CVE-2006-3980 (PHP remote file inclusion vulnerability in ...)
1409 NOT-FOR-US: Mambo Gallery Manager for Mambo
1410 CVE-2006-3979 (The AdminAPI of ColdFusion MX 7 allows attackers to bypass ...)
1411 NOT-FOR-US: ColdFusion MX
1412 CVE-2006-3978
1413 RESERVED
1414 CVE-2006-3977 (Unspecified vulnerability in CA eTrust Antivirus WebScan before ...)
1415 NOT-FOR-US: CA eTrust Antivirus WebScan
1416 CVE-2006-3976 (Unspecified vulnerability in CA eTrust Antivirus WebScan before ...)
1417 NOT-FOR-US: CA eTrust Antivirus WebScan
1418 CVE-2006-3975 (Unspecified vulnerability in CA eTrust Antivirus WebScan allows remote ...)
1419 NOT-FOR-US: CA eTrust Antivirus WebScan
1420 CVE-2006-3974
1421 RESERVED
1422 CVE-2006-3973
1423 RESERVED
1424 CVE-2006-3972 (Directory traversal vulnerability in ...)
1425 NOT-FOR-US: Ajax Chat
1426 CVE-2006-3971 (Cross-site scripting (XSS) vulnerability in ...)
1427 NOT-FOR-US: Ajax Chat
1428 CVE-2006-XXXX [unspecified security issues in steam]
1429 - steam 2.2.16-1
1430 CVE-2006-XXXX [Buffer overflow in XML::Parser::Expat triggered by utf8]
1431 - libxml-parser-perl <unfixed> (bug #378411; high)
1432 CVE-2006-XXXX [Buffer overflow in XML::Parser::Expat triggered by deep nesting]
1433 - libxml-parser-perl 2.34-4.1 (bug #378412; high)
1434 CVE-2006-3970 (PHP remote file inclusion vulnerability in lmo.php in the LMO ...)
1435 NOT-FOR-US: LMO for joomla
1436 CVE-2006-3969 (PHP remote file inclusion vulnerability in ...)
1437 NOT-FOR-US: Colophon for joomla
1438 CVE-2006-3968 (The crypto provider in Sun Solaris 10 3/05 HW2 without patch ...)
1439 NOT-FOR-US: Solaris
1440 CVE-2006-3967 (PHP remote file inclusion vulnerability in ...)
1441 NOT-FOR-US: moskool
1442 CVE-2006-3966 (PHP remote file inclusion vulnerability in ...)
1443 NOT-FOR-US: MyNewsGroups
1444 CVE-2006-3965 (Banex PHP MySQL Banner Exchange 2.21 stores lib.inc under the web ...)
1445 NOT-FOR-US: Banex PHP MySQL Banner Exchange
1446 CVE-2006-3964 (PHP remote file inclusion vulnerability in members.php in Banex PHP ...)
1447 NOT-FOR-US: Banex PHP MySQL Banner Exchange
1448 CVE-2006-3963 (Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner ...)
1449 NOT-FOR-US: Banex PHP MySQL Banner Exchange
1450 CVE-2006-3962 (PHP remote file inclusion vulnerability in ...)
1451 NOT-FOR-US: com_bayesiannaivefilter for mambo
1452 CVE-2006-3961 (Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee ...)
1453 NOT-FOR-US: McAfee
1454 CVE-2006-3960 (SQL injection vulnerability in top.php in X-Scripts X-Poll, probably ...)
1455 NOT-FOR-US: X-Scripts X-Poll
1456 CVE-2006-3959 (SQL injection vulnerability in protect.php in X-Scripts X-Protection ...)
1457 NOT-FOR-US: X-Scripts X-Protection
1458 CVE-2006-3958 (Multiple unspecified cross-site scripting (XSS) vulnerabilities in ...)
1459 NOT-FOR-US: Taskjitsu
1460 CVE-2006-3957 (PHP remote file inclusion vulnerability in payment.php in BosDev ...)
1461 NOT-FOR-US: BosDates
1462 CVE-2006-3956 (Multiple cross-site scripting (XSS) vulnerabilities in contact.php in ...)
1463 NOT-FOR-US: Advanced Webhost Billing System
1464 CVE-2006-3955 (Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum ...)
1465 NOT-FOR-US: MiniBB Forum
1466 CVE-2006-3954 (Directory traversal vulnerability in usercp.php in MyBB (aka ...)
1467 NOT-FOR-US: mybb
1468 CVE-2006-3953 (Cross-site scripting (XSS) vulnerability in usercp.php in MyBB (aka ...)
1469 NOT-FOR-US: mybb
1470 CVE-2006-3952 (Stack-based buffer overflow in EFS Software Easy File Sharing FTP ...)
1471 NOT-FOR-US: EFS Software Easy File Sharing FTP
1472 CVE-2006-3951 (PHP remote file inclusion vulnerability in moodle.php in Mam-moodle ...)
1473 NOT-FOR-US: Mam-moodle alpha component (com_moodle) for Mambo
1474 CVE-2006-3950 (SQL injection vulnerability in x-statistics.php in X-Scripts ...)
1475 NOT-FOR-US: X-Statistics
1476 CVE-2006-3949 (PHP remote file inclusion vulnerability in artlinks.dispnew.php in the ...)
1477 NOT-FOR-US: com_artlinks for Mambo
1478 CVE-2006-3948 (Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke ...)
1479 NOT-FOR-US: php-nuke
1480 CVE-2006-3947 (PHP remote file inclusion vulnerability in ...)
1481 NOT-FOR-US: Mambatstaff
1482 CVE-2006-3946 (The KHTMLParser::popOneBlock function in Apple Safari 2.0.4 on Mac OS ...)
1483 NOT-FOR-US: Apple Safari 2.0.4
1484 NOTE: konqueror 3.5.x is not affected
1485 NOTE: PoC http://browserfun.blogspot.com/2006/07/mobb-31-safari-khtmlparserpoponeblock.html
1486 TODO: check sarge's konqueror (sf: pinged maintainers)
1487 CVE-2006-3945 (The CSS functionality in Opera 9 on Windows XP SP2 allows remote ...)
1488 NOT-FOR-US: Opera
1489 CVE-2006-3944 (Microsoft Internet Explorer 6 on Windows XP SP2 allows remote ...)
1490 NOT-FOR-US: Microsoft
1491 CVE-2006-3943 (Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet ...)
1492 NOT-FOR-US: Microsoft
1493 CVE-2006-3942 (The server driver (srv.sys) in Microsoft Windows 2000 SP4, Server 2003 ...)
1494 NOT-FOR-US: Microsoft
1495 CVE-2006-3941 (Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 ...)
1496 NOT-FOR-US: N1 Grid Engine
1497 CVE-2006-3940 (Multiple SQL injection vulnerabilities in phpbb-Auction allow remote ...)
1498 NOT-FOR-US: phpbb-Auction
1499 CVE-2006-3939 (ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform ...)
1500 NOT-FOR-US: ScriptsCenter ezUpload Pro
1501 CVE-2006-3938 (DotClear allows remote attackers to obtain sensitive information via a ...)
1502 NOT-FOR-US: DotClear
1503 CVE-2006-3937 (post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain ...)
1504 NOT-FOR-US: x_atrix xGuestBook
1505 CVE-2006-3936 (system/workplace/editors/editor.jsp in Alkacon OpenCms before 6.2.2 ...)
1506 NOT-FOR-US: Alkacon OpenCms
1507 CVE-2006-3935 (system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before ...)
1508 NOT-FOR-US: Alkacon OpenCms
1509 CVE-2006-3934 (Absolute path traversal vulnerability in downloadTrigger.jsp in ...)
1510 NOT-FOR-US: Alkacon OpenCms
1511 CVE-2006-3933 (Cross-site scripting (XSS) vulnerability in Alkacon OpenCms before ...)
1512 NOT-FOR-US: OpenCms
1513 CVE-2006-3932 (SQL injection vulnerability in links.php in Gonafish LinksCaffe 3.0 ...)
1514 NOT-FOR-US: LinksCaffe
1515 CVE-2006-3931 (Buffer overflow in the daemon function in midirecord.cc in Tuomas ...)
1516 NOT-FOR-US: Midirecord
1517 CVE-2006-3930 (PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php ...)
1518 NOT-FOR-US: a6mambohelpdesk Mambo Component 18RC1
1519 CVE-2006-3929 (Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin ...)
1520 NOT-FOR-US: Zyxel
1521 CVE-2006-3928 (PHP remote file inclusion vulnerability in index.php in WMNews 0.2a ...)
1522 NOT-FOR-US: WMNews
1523 CVE-2006-3927 (Cross-site scripting (XSS) vulnerability in auctionsearch.php in ...)
1524 NOT-FOR-US: PhpProBid
1525 CVE-2006-3926 (Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote ...)
1526 NOT-FOR-US: PhpProBid
1527 CVE-2006-3925 (Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control ...)
1528 NOT-FOR-US: ITIRecorder.MicRecorder ActiveX control
1529 CVE-2006-3924 (Multiple cross-site scripting (XSS) vulnerabilities in Dokeos before ...)
1530 NOT-FOR-US: Dokeos
1531 CVE-2006-3923 (Cross-site scripting (XSS) vulnerability in add.php in Fire-Mouse ...)
1532 NOT-FOR-US: Fire-Mouse Toplist
1533 CVE-2006-3922 (PHP remote file inclusion vulnerability in mod_membre/inscription.php ...)
1534 NOT-FOR-US: PortailPHP
1535 CVE-2006-3921 (Sun Java System Application Server (SJSAS) 7 through 8.1 and Web ...)
1536 NOT-FOR-US: Sun Java System Application Server
1537 CVE-2006-3920 (The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 ...)
1538 NOT-FOR-US: Sun Solaris
1539 CVE-2006-3919 (SQL injection vulnerability in index.php in SD Studio CMS allows ...)
1540 NOT-FOR-US: SD Studio CMS
1541 CVE-2006-3918 (http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 ...)
1542 {DSA-1167-1}
1543 - apache2 2.0.55-4.1 (bug #381376; medium)
1544 - apache 1.3.34-3 (bug #381381; medium)
1545 CVE-2006-3917 (PHP remote file inclusion vulnerability in inc/gabarits.php in R. ...)
1546 NOT-FOR-US: PHP Forge
1547 CVE-2006-3916 (Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka ...)
1548 NOT-FOR-US: Solucija News
1549 CVE-2006-3915 (Microsoft Internet Explorer 6 on Windows XP SP2 allows remote ...)
1550 NOT-FOR-US: Microsoft
1551 CVE-2006-3914 (Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite ...)
1552 NOT-FOR-US: Academic Suite
1553 CVE-2006-3913 (Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul ...)
1554 {DSA-1142-1}
1555 - freeciv 2.0.8-3 (bug #381378; medium)
1556 CVE-2006-3912 (Stack-based buffer overflow in the SFX module in WinRAR before 3.60 ...)
1557 NOT-FOR-US: WinRAR
1558 CVE-2006-3911 (PHP remote file inclusion vulnerability in OSI Codes PHP Live! 3.2.1 ...)
1559 NOT-FOR-US: PHP Live
1560 CVE-2006-3910 (Internet Explorer 6 on Windows XP SP2, when Outlook is installed, ...)
1561 NOT-FOR-US: Microsoft
1562 CVE-2006-3909 (Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads ...)
1563 NOT-FOR-US: WWWthreads
1564 CVE-2006-3908 (Format string vulnerability in the flush_output function in ...)
1565 NOT-FOR-US: Game Network Engine (GNE)
1566 CVE-2006-3907 (Siemens SpeedStream 2624 allows remote attackers to cause a denial of ...)
1567 NOT-FOR-US: Siemens
1568 CVE-2006-3906 (Internet Key Exchange (IKE) version 1 protocol, as implemented on ...)
1569 NOT-FOR-US: Cisco
1570 CVE-2006-3905 (SQL injection vulnerability in Webland MyBloggie 2.1.3 allows remote ...)
1571 NOT-FOR-US: Webland MyBloggie
1572 CVE-2006-3904 (SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 ...)
1573 NOT-FOR-US: Etomite CMS
1574 CVE-2006-3903 (CRLF injection vulnerability in (1) index.php and (2) admin.php in ...)
1575 NOT-FOR-US: Webland MyBloggie
1576 CVE-2006-3902 (Cross-site scripting (XSS) vulnerability in index.php in phpFaber ...)
1577 NOT-FOR-US: phpFaber TopSites
1578 CVE-2006-3901 (Multiple stack-based buffer overflows in Tumbleweed Email Firewall ...)
1579 NOT-FOR-US: Tumbleweed Email Firewall
1580 CVE-2006-3900 (Cross-site scripting (XSS) vulnerability in guestbook.php in TP-Book ...)
1581 NOT-FOR-US: TP-Book
1582 CVE-2006-3899 (Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote ...)
1583 NOT-FOR-US: Microsoft
1584 CVE-2006-3898 (Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote ...)
1585 NOT-FOR-US: Microsoft
1586 CVE-2006-3897 (Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows ...)
1587 NOT-FOR-US: Microsoft
1588 CVE-2006-3896
1589 RESERVED
1590 CVE-2006-3895
1591 RESERVED
1592 CVE-2006-3894
1593 RESERVED
1594 CVE-2006-3893
1595 RESERVED
1596 CVE-2006-3892
1597 RESERVED
1598 CVE-2006-3891
1599 RESERVED
1600 CVE-2006-3890
1601 RESERVED
1602 CVE-2006-3889
1603 RESERVED
1604 CVE-2006-3888
1605 RESERVED
1606 CVE-2006-3887
1607 RESERVED
1608 CVE-2006-3886 (SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier ...)
1609 NOT-FOR-US: Shalwan MusicBox
1610 CVE-2006-3885 (Directory traversal vulnerability in Check Point Firewall-1 R55W ...)
1611 NOT-FOR-US: Check Point Firewall-1
1612 CVE-2006-3884 (Multiple SQL injection vulnerabilities in links.php in Gonafish ...)
1613 NOT-FOR-US: Gonafish LinksCaffe
1614 CVE-2006-3883 (Multiple cross-site scripting (XSS) vulnerabilities in Gonafish ...)
1615 NOT-FOR-US: Gonafish LinksCaffe
1616 CVE-2006-3882 (Shalwan MusicBox 2.3.4 and earlier allows remote attackers to obtain ...)
1617 NOT-FOR-US: Shalwan MusicBox
1618 CVE-2006-3881 (Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and ...)
1619 NOT-FOR-US: Shalwan MusicBox
1620 CVE-2006-3880 (** DISPUTED ** ...)
1621 NOT-FOR-US: Zen Cart
1622 CVE-2006-3879 (Integer overflow in the loadChunk function in loaders/load_gt2.c in ...)
1623 - libmikmod2 <unfixed> (bug #381379)
1624 CVE-2006-3878 (Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql ...)
1625 NOT-FOR-US: Opsware Network Automation System
1626 CVE-2006-3877
1627 RESERVED
1628 CVE-2006-3876
1629 RESERVED
1630 CVE-2006-3875
1631 RESERVED
1632 CVE-2006-3874
1633 RESERVED
1634 CVE-2006-3873
1635 RESERVED
1636 CVE-2006-3872
1637 RESERVED
1638 CVE-2006-3871
1639 RESERVED
1640 CVE-2006-3870
1641 RESERVED
1642 CVE-2006-3869 (Heap-based buffer overflow in URLMON.DLL in Microsoft Internet ...)
1643 NOT-FOR-US: Microsoft
1644 CVE-2006-3868
1645 RESERVED
1646 CVE-2006-3867
1647 RESERVED
1648 CVE-2006-3866
1649 RESERVED
1650 CVE-2006-3865
1651 RESERVED
1652 CVE-2006-3864
1653 RESERVED
1654 CVE-2006-3863
1655 RESERVED
1656 CVE-2006-3862 (Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC5 through ...)
1657 NOT-FOR-US: IBM Informix Dynamic Server
1658 CVE-2006-3861 (IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before ...)
1659 NOT-FOR-US: IBM Informix Dynamic Server
1660 CVE-2006-3860 (IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before ...)
1661 NOT-FOR-US: IBM Informix Dynamic Server
1662 CVE-2006-3859 (IBM Informix Dynamic Server (IDS) allows remote authenticated users to ...)
1663 NOT-FOR-US: IBM Informix Dynamic Server
1664 CVE-2006-3858 (IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before ...)
1665 NOT-FOR-US: IBM Informix Dynamic Server
1666 CVE-2006-3857 (Multiple buffer overflows in IBM Informix Dynamic Server (IDS) before ...)
1667 NOT-FOR-US: IBM Informix Dynamic Server
1668 CVE-2006-3856 (IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before ...)
1669 NOT-FOR-US: IBM Informix Dynamic Server
1670 CVE-2006-3855 (The ifx_load_internal function in IBM Informix Dynamic Server (IDS) ...)
1671 NOT-FOR-US: IBM Informix Dynamic Server
1672 CVE-2006-3854 (Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, ...)
1673 NOT-FOR-US: IBM Informix Dynamic Server
1674 CVE-2006-3853 (Buffer overflow in IBM Informix Dynamic Server (IDS) before 9.40.TC7 ...)
1675 NOT-FOR-US: IBM Informix Dynamic Server
1676 CVE-2006-3852 (Cross-site scripting (XSS) vulnerability in index.php in Micro ...)
1677 NOT-FOR-US: Micro GuestBook
1678 CVE-2006-3851 (SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and ...)
1679 NOT-FOR-US: X7 Chat
1680 CVE-2006-3850 (** DISPUTED ** ...)
1681 NOT-FOR-US: Vanilla CMS
1682 CVE-2006-3849 (Stack-based buffer overflow in Warzone 2100 and Warzone Resurrection ...)
1683 NOT-FOR-US: Warzone
1684 CVE-2006-3848 (Cross-site scripting (XSS) vulnerability in CGI wrapper for IP ...)
1685 NOT-FOR-US: ipcalc <unfixed> (bug #381469; low)
1686 CVE-2006-3847 (PHP remote file inclusion vulnerability in (1) admin.php, and possibly ...)
1687 NOT-FOR-US: MoSpray
1688 CVE-2006-3846 (PHP remote file inclusion vulnerability in extadminmenus.class.php in ...)
1689 NOT-FOR-US: MultiBanners
1690 CVE-2006-3845 (Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 ...)
1691 NOT-FOR-US: WinRAR
1692 CVE-2006-3844 (Buffer overflow in Quick 'n Easy FTP Server 3.0 allows remote ...)
1693 NOT-FOR-US: Quick 'n Easy FTP Server
1694 CVE-2006-3843 (PHP remote file inclusion vulnerability in com_calendar.php in ...)
1695 NOT-FOR-US: Calendar Mambo Module
1696 CVE-2006-3842 (Cross-site scripting (XSS) vulnerability in Zoho Virtual Office 3.2 ...)
1697 NOT-FOR-US: Zoho Virtual Office
1698 CVE-2006-3841 (Cross-site scripting (XSS) vulnerability in WebScarab before ...)
1699 NOT-FOR-US: WebScarab
1700 CVE-2006-3840 (The SMB Mailslot parsing functionality in PAM in multiple ISS products ...)
1701 NOT-FOR-US: various ISS products
1702 CVE-2006-3839
1703 RESERVED
1704 CVE-2006-3838 (Multiple stack-based buffer overflows in eIQnetworks Enterprise ...)
1705 NOT-FOR-US: eIQnetworks Enterprise
1706 CVE-2006-XXXX [syslog-ng dos]
1707 - syslog-ng 2.0rc1-2 (low)
1708 [sarge] - syslog-ng <not-affected> (Vulnerable code not present)
1709 CVE-2006-XXXX [courier-authdaemon: wrong socket permissions may lead to password disclosure]
1710 - courier-authlib 0.58-3.1 (bug #378571; medium)
1711 [sarge] - courier-authlib <not-affected> (bug #378571; medium)
1712 CVE-2006-4046 (Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 ...)
1713 - ocp 0.1.10rc6-1 (medium; bug #381098)
1714 CVE-2006-XXXX [uqwk buffer overflow]
1715 - uqwk 2.21-13 (bug #376577; medium)
1716 CVE-2006-XXXX [Webalizer buffer overflows]
1717 - webalizer 2.01.10-30 (unknown)
1718 NOTE: 11_various_buffer_overflows should be reviewed for exploitability
1719 CVE-2006-3837 (delcookie.php in Professional Home Page Tools Guestbook changes the ...)
1720 NOT-FOR-US: Professional Home Page Tools Guestbook
1721 CVE-2006-3836 (Directory traversal vulnerability in index.php in UNIDOmedia Chameleon ...)
1722 NOT-FOR-US: UNIDOmedia Chameleon
1723 CVE-2006-3835 (Apache Tomcat 5 before 5.5.17 allows remote attackers to list ...)
1724 - tomcat5 <not-affected> (bug #380361; maintainter can't reproduce)
1725 - tomcat5.5 <not-affected> (bug #380376; maintainer can't reproduce)
1726 CVE-2006-3834 (EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to ...)
1727 NOT-FOR-US: EJ3 TOPo
1728 CVE-2006-3833 (index.php in EJ3 TOPo 2.2.178 allows remote attackers to overwrite ...)
1729 NOT-FOR-US: EJ3 TOPo
1730 CVE-2006-3832 (SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog ...)
1731 NOT-FOR-US: Gerrit van Aaken Loudblog
1732 CVE-2006-3831 (The Backup selection in Kailash Nadh boastMachine (formerly bMachine) ...)
1733 NOT-FOR-US: Kailash Nadh boastMachine (formerly bMachine)
1734 CVE-2006-3830 (The Languages selection in the admin interface in Kailash Nadh ...)
1735 NOT-FOR-US: Kailash Nadh boastMachine (formerly bMachine)
1736 CVE-2006-3829 (Cross-site request forgery (CSRF) vulnerability in bmc/admin.php in ...)
1737 NOT-FOR-US: Kailash Nadh boastMachine (formerly bMachine)
1738 CVE-2006-3828 (Incomplete blacklist vulnerability in Kailash Nadh boastMachine ...)
1739 NOT-FOR-US: Kailash Nadh boastMachine (formerly bMachine)
1740 CVE-2006-3827 (SQL injection vulnerability in bmc/Inc/core/admin/search.inc.php in ...)
1741 NOT-FOR-US: Kailash Nadh boastMachine (formerly bMachine)
1742 CVE-2006-3826 (Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh ...)
1743 NOT-FOR-US: Kailash Nadh boastMachine (formerly bMachine)
1744 CVE-2006-3825 (The IPv4 implementation in Sun Solaris 10 before 20060721 allows local ...)
1745 NOT-FOR-US: Solaris
1746 CVE-2006-3824 (systeminfo.c for Sun Solaris allows local users to read kernel memory ...)
1747 NOT-FOR-US: Solaris
1748 CVE-2006-3823 (SQL injection vulnerability in index.php in GeodesicSolutions (1) ...)
1749 NOT-FOR-US: GeodesicSolutions GeoAuctions Premier and GeoClassifieds Basic
1750 CVE-2006-3822 (SQL injection vulnerability in index.php in GeodesicSolutions ...)
1751 NOT-FOR-US: GeodesicSolutions GeoAuctions
1752 CVE-2006-3821 (Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 ...)
1753 NOT-FOR-US: ATutor
1754 CVE-2006-3820 (Cross-site scripting (XSS) vulnerability in loudblog/index.php in ...)
1755 NOT-FOR-US: Loudblog
1756 CVE-2006-3819 (Eval injection vulnerability in the configure script in TWiki 4.0.0 ...)
1757 - twiki <not-affected> (only 4.0.x is affected)
1758 CVE-2006-3818 (Cross-site scripting (XSS) vulnerability in the login page in Novell ...)
1759 NOT-FOR-US: Novell GroupWise WebAccess
1760 CVE-2006-3817 (Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess ...)
1761 NOT-FOR-US: Novell GroupWise WebAccess
1762 CVE-2006-3816 (Krusader 1.50-beta1 up to 1.70.0 stores passwords for remote ...)
1763 - krusader <not-affected> (bug #380063; file in directory with 0700 permissions)
1764 CVE-2006-3815 (heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a ...)
1765 {DSA-1128}
1766 - heartbeat 1.2.4-13 (bug #379904)
1767 CVE-2006-3814 (Buffer overflow in the Loader_XM::load_instrument_internal function in ...)
1768 {DSA-1166}
1769 - cheesetracker 0.9.9-6 (bug #380364; low)
1770 CVE-2006-3813 (A regression error in the Perl package for Red Hat Enterprise Linux 4 ...)
1771 NOT-FOR-US: Perl in Red Hat Enterprise Linux 4
1772 CVE-2006-3812 (Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and ...)
1773 NOTE: MFSA-2006-56
1774 [sarge] - mozilla <not-affected>
1775 - mozilla <unfixed> (medium)
1776 - xulrunner 1.8.0.5-1 (medium)
1777 [sarge] - mozilla-firefox <not-affected> (Only Firefox 1.5 is affected)
1778 - firefox 1.5.dfsg+1.5.0.5-1 (medium)
1779 - thunderbird <unfixed> (unimportant)
1780 [sarge] - mozilla-thunderbird <not-affected> (unimportant)
1781 CVE-2006-3811 (Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, ...)
1782 {DSA-1161}
1783 NOTE: MFSA-2006-55
1784 - mozilla <unfixed> (high)
1785 - xulrunner 1.8.0.5-1 (high)
1786 - mozilla-firefox <removed> (high)
1787 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1788 - thunderbird 1.5.0.5-1 (medium)
1789 - mozilla-thunderbird <removed> (medium)
1790 CVE-2006-3810 (Cross-site scripting (XSS) vulnerability in Mozilla Firefox 1.5 before ...)
1791 NOTE: MFSA-2006-54
1792 - mozilla <not-affected> (mozilla 1.7 not affected)
1793 - xulrunner 1.8.0.5-1 (high)
1794 - mozilla-firefox <not-affected> (only firefox >= 1.5)
1795 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1796 - thunderbird 1.5.0.5-1 (medium)
1797 - mozilla-thunderbird <not-affected>
1798 CVE-2006-3809 (Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and ...)
1799 {DSA-1161 DSA-1160 DSA-1159}
1800 NOTE: MFSA-2006-53
1801 - mozilla <unfixed> (medium)
1802 - xulrunner 1.8.0.5-1 (medium)
1803 - mozilla-firefox <removed> (medium)
1804 - firefox 1.5.dfsg+1.5.0.5-1 (medium)
1805 - thunderbird 1.5.0.5-1 (medium)
1806 - mozilla-thunderbird <removed> (medium)
1807 CVE-2006-3808 (Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows ...)
1808 {DSA-1161 DSA-1160 DSA-1159}
1809 NOTE: MFSA-2006-52
1810 - mozilla <unfixed> (medium)
1811 - xulrunner 1.8.0.5-1 (medium)
1812 - mozilla-firefox <removed> (medium)
1813 - firefox 1.5.dfsg+1.5.0.5-1 (medium)
1814 - thunderbird 1.5.0.5-1
1815 CVE-2006-3807 (Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and ...)
1816 {DSA-1161 DSA-1160 DSA-1159}
1817 NOTE: MFSA-2006-51
1818 - mozilla <unfixed> (high)
1819 - xulrunner 1.8.0.5-1 (high)
1820 - mozilla-firefox <removed> (high)
1821 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1822 - thunderbird 1.5.0.5-1 (medium)
1823 - mozilla-thunderbird <removed> (medium)
1824 CVE-2006-3806 (Multiple integer overflows in the Javascript engine in Mozilla Firefox ...)
1825 {DSA-1161 DSA-1160 DSA-1159}
1826 NOTE: MFSA-2006-50
1827 - mozilla <unfixed> (high)
1828 - xulrunner 1.8.0.5-1 (high)
1829 - mozilla-firefox <removed> (high)
1830 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1831 - thunderbird 1.5.0.5-1 (medium)
1832 - mozilla-thunderbird <removed> (medium)
1833 CVE-2006-3805 (The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird ...)
1834 {DSA-1161 DSA-1160 DSA-1159}
1835 NOTE: MFSA-2006-50
1836 - mozilla <unfixed> (high)
1837 - xulrunner 1.8.0.5-1 (high)
1838 - mozilla-firefox <removed> (high)
1839 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1840 - thunderbird 1.5.0.5-1 (medium)
1841 - mozilla-thunderbird <removed> (medium)
1842 CVE-2006-3804 (Heap-based buffer overflow in Mozilla Thunderbird before 1.5.0.5 and ...)
1843 NOTE: MFSA-2006-49
1844 - mozilla-firefox <not-affected> (only firefox >= 1.5)
1845 [sarge] - mozilla <not-affected> (mozilla 1.7 not affected)
1846 - mozilla <unfixed> (high)
1847 - thunderbird 1.5.0.5-1 (high)
1848 - mozilla-thunderbird <not-affected> (high)
1849 CVE-2006-3803 (Race condition in the JavaScript garbage collection in Mozilla Firefox ...)
1850 NOTE: MFSA-2006-48
1851 - mozilla <not-affected> (mozilla 1.7 not affected)
1852 - xulrunner 1.8.0.5-1 (high)
1853 - mozilla-firefox <not-affected> (only firefox >= 1.5)
1854 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1855 - thunderbird 1.5.0.5-1 (medium)
1856 - mozilla-thunderbird <not-affected>
1857 CVE-2006-3802 (Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and ...)
1858 NOTE: MFSA-2006-47
1859 - mozilla <not-affected> (mozilla 1.7 not affected)
1860 - xulrunner 1.8.0.5-1 (medium)
1861 - mozilla-firefox <not-affected> (only firefox >= 1.5)
1862 - firefox 1.5.dfsg+1.5.0.5-1 (medium)
1863 - thunderbird 1.5.0.5-1 (medium)
1864 - mozilla-thunderbird <not-affected>
1865 CVE-2006-3801 (Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not ...)
1866 NOTE: MFSA-2006-44
1867 - mozilla-firefox <not-affected> (only firefox >= 1.5)
1868 - mozilla-thunderbird <not-affected> (only firefox >= 1.5)
1869 - mozilla <not-affected> (mozilla 1.7 not affected)
1870 - firefox 1.5.dfsg+1.5.0.5-1 (high)
1871 - xulrunner 1.8.0.5-1 (high)
1872 - thunderbird 1.5.0.5-1 (medium)
1873 CVE-2006-3800 (Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce ...)
1874 NOT-FOR-US: AFCommerce
1875 CVE-2006-3799 (DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL ...)
1876 NOT-FOR-US: DeluxeBB
1877 CVE-2006-3798 (DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) ...)
1878 NOT-FOR-US: DeluxeBB
1879 CVE-2006-3797 (SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote ...)
1880 NOT-FOR-US: DeluxeBB
1881 CVE-2006-3796 (DeluxeBB 1.07 and earlier does not properly handle a username composed ...)
1882 NOT-FOR-US: DeluxeBB
1883 CVE-2006-3795 (Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before ...)
1884 NOT-FOR-US: DeluxeBB
1885 CVE-2006-3794 (** DISPUTED ** ...)
1886 NOT-FOR-US: AFCommerce
1887 CVE-2006-3793 (PHP remote file inclusion vulnerability in constants.php in SiteDepth ...)
1888 NOT-FOR-US: SiteDepth
1889 CVE-2006-3792 (SQL injection vulnerability in ServerClientUfo::recv_packet in ...)
1890 NOT-FOR-US: UFO2000
1891 CVE-2006-3791 (The decode_stringmap function in server_transport.cpp for UFO2000 svn ...)
1892 NOT-FOR-US: UFO2000
1893 CVE-2006-3790 (The decode_stringmap function in server_transport.cpp for UFO2000 svn ...)
1894 NOT-FOR-US: UFO2000
1895 CVE-2006-3789 (Multiple array index errors in the (1) recv_rules, (2) ...)
1896 NOT-FOR-US: UFO2000
1897 CVE-2006-3788 (Multiple buffer overflows in multiplay.cpp in UFO2000 svn 1057 allow ...)
1898 NOT-FOR-US: UFO2000
1899 CVE-2006-3787 (kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 ...)
1900 NOT-FOR-US: Sunbelt Kerio Personal Firewall
1901 CVE-2006-3786 (Symantec pcAnywhere 12.5 uses weak integrity protection for .cif (aka ...)
1902 NOT-FOR-US: Symantec pcAnywhere
1903 CVE-2006-3785 (Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox ...)
1904 NOT-FOR-US: Symantec pcAnywhere
1905 CVE-2006-3784 (Symantec pcAnywhere 12.5 uses weak default permissions for the ...)
1906 NOT-FOR-US: Symantec pcAnywhere
1907 CVE-2006-3783 (Sun Solaris 10 allows local users to cause a denial of service (panic) ...)
1908 NOT-FOR-US: Solaris
1909 CVE-2006-3782 (Unspecified vulnerability in the kernel debugger (kmdb) in Sun Solaris ...)
1910 NOT-FOR-US: Solaris
1911 CVE-2006-3781 (Unspecified vulnerability in Sun Solaris 10 allows context-dependent ...)
1912 NOT-FOR-US: Solaris
1913 CVE-2006-3780 (Keyifweb Keyif Portal 2.0 stores sensitive information under the web ...)
1914 NOT-FOR-US: Keyifweb Keyif Portal
1915 CVE-2006-3779 (Citrix MetaFrame up to XP 1.0 Feature 1, except when running on ...)
1916 NOT-FOR-US: Citrix
1917 CVE-2006-3778 (IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to ...)
1918 NOT-FOR-US: IBM
1919 CVE-2006-3777 (PHP remote file inclusion vulnerability in index.php in IDevSpot ...)
1920 NOT-FOR-US: IDevSpot PhpLinkExchange
1921 CVE-2006-3776 (PHP remote file inclusion vulnerability in order/index.php in IDevSpot ...)
1922 NOT-FOR-US: IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0
1923 CVE-2006-3775 (SQL injection vulnerability in class_session.php in MyBB (aka ...)
1924 NOT-FOR-US: MyBB
1925 CVE-2006-3774 (PHP remote file inclusion vulnerability in performs.php in the ...)
1926 NOT-FOR-US: perForms component (com_performs) for Joomla!
1927 CVE-2006-3773 (PHP remote file inclusion vulnerability in smf.php in the SMF-Forum ...)
1928 NOT-FOR-US: MF-Forum Bridge Component (com_smf) For Joomla! and Mambo
1929 CVE-2006-3772 (PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login ...)
1930 NOT-FOR-US: PHP-Post
1931 CVE-2006-3771 (Multiple PHP remote file inclusion vulnerabilities in component.php in ...)
1932 NOT-FOR-US: iManage CMS
1933 CVE-2006-3770 (Multiple SQL injection vulnerabilities in index.php in phpFaber ...)
1934 NOT-FOR-US: phpFaber TopSites
1935 CVE-2006-3769 (Multiple cross-site scripting (XSS) vulnerabilities in Top XL 1.1 and ...)
1936 NOT-FOR-US: Top XL
1937 CVE-2006-3768 (Integer underflow in filecpnt.exe in FileCOPA FTP Server 1.01 before ...)
1938 NOT-FOR-US: FileCOPA FTP Server
1939 CVE-2006-3767 (Cross-site scripting (XSS) vulnerability in showprofile.php in ...)
1940 NOT-FOR-US: Darren's $5 Script Archive osDate
1941 CVE-2006-3766 (Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to ...)
1942 NOT-FOR-US: Darren's $5 Script Archive osDate
1943 CVE-2006-3765 (Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher ...)
1944 NOT-FOR-US: uttenlocher Webdesign hwdeGUEST
1945 CVE-2006-3764 (Till Gerken phpPolls 1.0.3 allows remote attackers to create a new ...)
1946 NOT-FOR-US: phpPolls
1947 CVE-2006-3763 (SQL injection vulnerability in category.php in Diesel Joke Site allows ...)
1948 NOT-FOR-US: Diesel Joke Site
1949 CVE-2006-3762 (The Touch Control ActiveX control 2.0.0.55 allows remote attackers to ...)
1950 NOT-FOR-US: Touch Control ActiveX control
1951 CVE-2006-3761 (Cross-site scripting (XSS) vulnerability in inc/function_post.php in ...)
1952 NOT-FOR-US: MyBB
1953 CVE-2006-3760 (Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) ...)
1954 NOT-FOR-US: MyBB
1955 CVE-2006-3759 (Unspecified vulnerability in MyBB (aka MyBulletinBoard) 1.1.4, related ...)
1956 NOT-FOR-US: MyBB
1957 CVE-2006-3758 (inc/init.php in Archive Mode (Light) in MyBB (aka MyBulletinBoard) ...)
1958 NOT-FOR-US: MyBB
1959 CVE-2006-3757 (index.php in Zen Cart 1.3.0.2 allows remote attackers to obtain ...)
1960 NOT-FOR-US: Zen Cart
1961 CVE-2006-3756 (Cross-site scripting (XSS) vulnerability in Geeklog 1.4.0sr4 and ...)
1962 NOT-FOR-US: Geeklog
1963 CVE-2006-3755 (PHP remote file inclusion vulnerability in ...)
1964 NOT-FOR-US: FlushCMS
1965 CVE-2006-3754 (PHP remote file inclusion vulnerability in ...)
1966 NOT-FOR-US: FlushCMS
1967 CVE-2006-3753 (setcookie.php for tthe administration login in Professional Home Page ...)
1968 NOT-FOR-US: Professional Home Page Tools Guestbook
1969 CVE-2006-3752 (Multiple SQL injection vulnerabilities in class.php in Professional ...)
1970 NOT-FOR-US: Professional Home Page Tools Guestbook
1971 CVE-2006-3751 (PHP remote file inclusion vulnerability in ...)
1972 NOT-FOR-US: HTMLArea3
1973 CVE-2006-3750 (PHP remote file inclusion vulnerability in server.php in the Hashcash ...)
1974 NOT-FOR-US: Hashcash Component (com_hashcash) for Joomla
1975 CVE-2006-3749 (PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap ...)
1976 NOT-FOR-US: Sitemap component (com_sitemap) for Mambo
1977 CVE-2006-3748 (PHP remote file inclusion vulnerability in ...)
1978 NOT-FOR-US: LoudMouth Component for Mambo
1979 CVE-2006-3747 (Off-by-one error in the ldap scheme handling in the Rewrite module ...)
1980 {DSA-1132-1 DSA-1131-1}
1981 - apache 1.3.34-3 (medium; bug #380231)
1982 - apache2 2.0.55-4.1 (medium; bug #380182)
1983 CVE-2006-3746 (Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote ...)
1984 {DSA-1141-1 DSA-1140-1}
1985 - gnupg 1.4.5-1 (medium)
1986 - gnupg2 1.9.20-2 (medium)
1987 CVE-2006-3745 (Unspecified vulnerability in the sctp_make_abort_user function in the ...)
1988 - linux-2.6 2.6.17-7
1989 - linux-2.6.16 <unfixed>
1990 CVE-2006-3744 (Multiple integer overflows in ImageMagick before 6.2.9 allows ...)
1991 {DSA-1168-1}
1992 - imagemagick <unfixed> (bug #385062)
1993 CVE-2006-3743 (Multiple buffer overflows in ImageMagick before 6.2.9 allow ...)
1994 {DSA-1168-1}
1995 - imagemagick <unfixed> (bug #385062)
1996 CVE-2006-3742 (The KDE PAM configuration shipped with Fedora Core 5 causes KDM ...)
1997 TODO: check
1998 CVE-2006-3741
1999 RESERVED
2000 CVE-2006-3740
2001 RESERVED
2002 CVE-2006-3739
2003 RESERVED
2004 CVE-2006-3738
2005 RESERVED
2006 CVE-2006-XXXX [htdig: several unspecified security problems]
2007 - htdig 1:3.2.0b6-1
2008 CVE-2006-XXXX [ldap account manager sets trivial password instead of disabling it]
2009 - ldap-account-manager 1.0.2-1.1 (bug #368804; medium)
2010 [sarge] - ldap-account-manager <not-affected>
2011 CVE-2006-XXXX [ldap account manager wrongly unlocks some passwords]
2012 - ldap-account-manager 1.0.3-1 (bug #375453; medium)
2013 [sarge] - ldap-account-manager <not-affected>
2014 CVE-2006-3737 (Cross-site scripting (XSS) vulnerability in ...)
2015 NOT-FOR-US: Plesk
2016 CVE-2006-3736 (PHP remote file inclusion vulnerability in core/videodb.class.xml.php ...)
2017 NOT-FOR-US: VideoDB for Mambo
2018 CVE-2006-3735 (Multiple PHP remote file inclusion vulnerabilities in Mail2Forum ...)
2019 NOT-FOR-US: Mail2Forum
2020 CVE-2006-3734 (Multiple unspecified vulnerabilities in the Command Line Interface ...)
2021 NOT-FOR-US: CS-MARS
2022 CVE-2006-3733 (jmx-console/HtmlAdaptor in the jmx-console in the JBoss web ...)
2023 NOT-FOR-US: Cisco / JBoss
2024 CVE-2006-3732 (Cisco Security Monitoring, Analysis and Response System (CS-MARS) ...)
2025 NOT-FOR-US: CS-MARS
2026 CVE-2006-3731 (Mozilla Firefox 1.5.0.4 and earlier allows remote user-assisted ...)
2027 - firefox 1.5.dfsg+1.5.0.6-1 (bug #379050; low)
2028 [sarge] - mozilla-firefox <not-affected> (Unreproducible on Sarge)
2029 CVE-2006-3730 (Microsoft Internet Explorer 6 on Windows XP SP2 allows remote ...)
2030 NOT-FOR-US: MSIE
2031 CVE-2006-3729 (DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office ...)
2032 NOT-FOR-US: MSIE
2033 CVE-2006-3728 (Unspecified vulnerability in the kernel in Solaris 10 with patch ...)
2034 NOT-FOR-US: Solaris
2035 CVE-2006-3727 (Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow ...)
2036 NOT-FOR-US: Eskolar CMS
2037 CVE-2006-3726 (Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th ...)
2038 NOT-FOR-US: FileCOPA FTP Server
2039 CVE-2006-3725 (Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a ...)
2040 NOT-FOR-US: Norton Personal Firewall
2041 CVE-2006-3724 (Unspecified vulnerability in JD Edwards HTML Server for Oracle ...)
2042 NOT-FOR-US: Oracle
2043 CVE-2006-3723 (Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle ...)
2044 NOT-FOR-US: Oracle
2045 CVE-2006-3722 (Unspecified vulnerability in PeopleSoft Enterprise Portal for Oracle ...)
2046 NOT-FOR-US: Oracle
2047 CVE-2006-3721 (Multiple unspecified vulnerabilities in Oracle Management Service for ...)
2048 NOT-FOR-US: Oracle
2049 CVE-2006-3720 (Unspecified vulnerability in Enterprise Config Management for Oracle ...)
2050 NOT-FOR-US: Oracle
2051 CVE-2006-3719 (Unspecified vulnerability in CORE: Repository for Oracle Enterprise ...)
2052 NOT-FOR-US: Oracle
2053 CVE-2006-3718 (Multiple unspecified vulnerabilities in Oracle Exchange for Oracle ...)
2054 NOT-FOR-US: Oracle
2055 CVE-2006-3717 (Multiple unspecified vulnerabilities in Oracle E-Business Suite and ...)
2056 NOT-FOR-US: Oracle
2057 CVE-2006-3716 (Multiple unspecified vulnerabilities in Oracle E-Business Suite and ...)
2058 NOT-FOR-US: Oracle
2059 CVE-2006-3715 (Unspecified vulnerability in Calendar for Oracle Collaboration Suite ...)
2060 NOT-FOR-US: Oracle
2061 CVE-2006-3714 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2062 NOT-FOR-US: Oracle
2063 CVE-2006-3713 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2064 NOT-FOR-US: Oracle
2065 CVE-2006-3712 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2066 NOT-FOR-US: Oracle
2067 CVE-2006-3711 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2068 NOT-FOR-US: Oracle
2069 CVE-2006-3710 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2070 NOT-FOR-US: Oracle
2071 CVE-2006-3709 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2072 NOT-FOR-US: Oracle
2073 CVE-2006-3708 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2074 NOT-FOR-US: Oracle
2075 CVE-2006-3707 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2076 NOT-FOR-US: Oracle
2077 CVE-2006-3706 (Unspecified vulnerability in OC4J for Oracle Application Server ...)
2078 NOT-FOR-US: Oracle
2079 CVE-2006-3705 (Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have ...)
2080 NOT-FOR-US: Oracle
2081 CVE-2006-3704 (Unspecified vulnerability in the Oracle ODBC Driver for Oracle ...)
2082 NOT-FOR-US: Oracle
2083 CVE-2006-3703 (Unspecified vulnerability in InterMedia for Oracle Database 9.0.1.5, ...)
2084 NOT-FOR-US: Oracle
2085 CVE-2006-3702 (Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, ...)
2086 NOT-FOR-US: Oracle
2087 CVE-2006-3701 (Unspecified vulnerability in the Dictionary component in Oracle ...)
2088 NOT-FOR-US: Oracle
2089 CVE-2006-3700 (Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and ...)
2090 NOT-FOR-US: Oracle
2091 CVE-2006-3699 (Unspecified vulnerability in the Core RDBMS component in Oracle ...)
2092 NOT-FOR-US: Oracle
2093 CVE-2006-3698 (Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have ...)
2094 NOT-FOR-US: Oracle
2095 CVE-2006-3697 (Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft ...)
2096 NOT-FOR-US: Outpost Firewall Pro
2097 CVE-2006-3696 (filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows ...)
2098 NOT-FOR-US: Outpost Firewall Pro
2099 CVE-2006-3694 (Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote ...)
2100 {DSA-1157 DSA-1139-1}
2101 - ruby1.8 1.8.4-3 (bug #378029; medium)
2102 - ruby1.9 1.9.0+20060609-1 (medium)
2103 CVE-2006-3693 (Rocks Clusters 4.1 and earlier allows local users to gain privileges ...)
2104 NOT-FOR-US: Rocks Clusters
2105 CVE-2006-3692 (** DISPUTED ** ...)
2106 NOT-FOR-US: ListMessenger
2107 CVE-2006-3691 (Multiple SQL injection vulnerabilities in VBZooM 1.11 and earlier ...)
2108 NOT-FOR-US: VBZooM
2109 CVE-2006-3690 (Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum ...)
2110 NOT-FOR-US: MiniBB
2111 CVE-2006-3689 (** DISPUTED ** ...)
2112 NOT-FOR-US: Codeworks Gnomedia SubberZ[Lite]
2113 CVE-2006-3688 (SQL injection vulnerability in Room.php in Francisco Charrua ...)
2114 NOT-FOR-US: Francisco Charrua Photo-Gallery
2115 CVE-2006-3687 (Stack-based buffer overflow in the Universal Plug and Play (UPnP) ...)
2116 NOT-FOR-US: D-Link
2117 CVE-2006-3686 (Unspecified vulnerability in [SYSEXE]SMPUTIL.EXE in HP OpenVMS 7.3-2 ...)
2118 NOT-FOR-US: HP OpenVMS
2119 CVE-2006-3685 (PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 ...)
2120 NOT-FOR-US: CzarNews
2121 CVE-2006-3684 (PHP remote file inclusion vulnerability in calendar.php in SoftComplex ...)
2122 NOT-FOR-US: SoftComplex PHP Event Calendar
2123 CVE-2006-3683 (PHP remote file inclusion vulnerability in poll.php in Flipper Poll ...)
2124 NOT-FOR-US: Flipper Poll
2125 CVE-2006-3682 (awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote ...)
2126 - awstats 6.5-2 (bug #378960; low)
2127 [sarge] - awstats 6.4-1sarge3
2128 NOTE: A previous DSA introduced a fix that renders this vulnerability in ineffective
2129 CVE-2006-3681 (Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in ...)
2130 - awstats 6.5-2 (bug #378960; unimportant)
2131 NOTE: Path disclosure is not an issue for Debian
2132 CVE-2006-3680 (Cross-site scripting (XSS) vulnerability in photocycle in Photocycle ...)
2133 NOT-FOR-US: Photocycle
2134 CVE-2006-3679 (FatWire Content Server 5.5.0 allows remote attackers to bypass access ...)
2135 NOT-FOR-US: FatWire Content Server
2136 CVE-2006-3678 (TippingPoint IPS running the TippingPoint Operating System (TOS) ...)
2137 NOT-FOR-US: TippingPoint
2138 CVE-2006-3677 (Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows ...)
2139 NOTE: MFSA-2006-45
2140 - mozilla <not-affected> (mozilla 1.7 not affected)
2141 - xulrunner 1.8.0.5-1 (high)
2142 - mozilla-firefox <not-affected> (only firefox >= 1.5)
2143 - firefox 1.5.dfsg+1.5.0.5-1 (high)
2144 - thunderbird <not-affected>
2145 - mozilla-thunderbird <not-affected>
2146 CVE-2006-3676 (admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote ...)
2147 NOT-FOR-US: planetGallery
2148 CVE-2006-3675 (Password Safe 2.11, 2.16 and 3.0BETA1 does not respect the ...)
2149 TODO: check
2150 CVE-2006-3674 (nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote ...)
2151 - armagetron <unfixed> (bug #379062; medium)
2152 CVE-2006-3673 (nNetObject.cpp in Armagetron Advanced 2.8.2 and earlier allows remote ...)
2153 - armagetron <unfixed> (bug #379062; medium)
2154 CVE-2006-3672 (KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a ...)
2155 - kdelibs 4:3.5.4-1 (bug #378962; low)
2156 [sarge] - kdelibs <not-affected> (Doesn't trigger a crash on Sarge)
2157 CVE-2006-3671 (Cross-site request forgery (CSRF) vulnerability in the communicate ...)
2158 - hyperestraier 1.3.3-1 (bug #379060; low)
2159 CVE-2006-3670 (Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to ...)
2160 NOT-FOR-US: Winlpd
2161 CVE-2006-3669 (Mercury Messenger, possibly 1.7.1.1 and other versions, when running ...)
2162 NOT-FOR-US: Mercury Messenger
2163 CVE-2006-3668 (Heap-based buffer overflow in the it_read_envelope function in Dynamic ...)
2164 {DSA-1123}
2165 - libdumb 1:0.9.3-5 (bug #379064; medium)
2166 CVE-2006-3667 (Unspecified vulnerability in Sybase/Financial Fusion Consumer Banking ...)
2167 NOT-FOR-US: Sybase/Financial Fusion Consumer Banking Suite
2168 CVE-2006-3666 (SQL injection vulnerability in AjaxPortal 3.0, with magic_quotes_gpc ...)
2169 NOT-FOR-US: AjaxPortal
2170 CVE-2006-3665 (SquirrelMail 1.4.6 and earlier, with register_globals enabled, allows ...)
2171 - squirrelmail 2:1.4.7-1 (low)
2172 [sarge] - squirrelmail <no-dsa> (Operation with registers_globals not supported)
2173 CVE-2006-3664 (Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 ...)
2174 NOT-FOR-US: Sun Solaris
2175 CVE-2006-3663 (Finjan Vital Security Appliance 5100/8100 NG 8.3.5 stores passwords in ...)
2176 NOT-FOR-US: Finjan Appliance
2177 CVE-2006-3662 (** DISPUTED ** ...)
2178 NOT-FOR-US: ATutor
2179 CVE-2006-3661 (Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews ...)
2180 NOT-FOR-US: CuteNews
2181 CVE-2006-3660 (Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown ...)
2182 NOT-FOR-US: Microsoft PowerPoint
2183 CVE-2006-3659 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2184 NOT-FOR-US: Microsoft Internet Explorer
2185 CVE-2006-3658 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2186 NOT-FOR-US: Microsoft Internet Explorer
2187 CVE-2006-3657 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2188 NOT-FOR-US: Microsoft Internet Explorer
2189 CVE-2006-3656 (Unspecified vulnerability in Microsoft PowerPoint 2003 allows ...)
2190 NOT-FOR-US: Microsoft PowerPoint
2191 CVE-2006-3655 (Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 ...)
2192 NOT-FOR-US: Microsoft PowerPoint
2193 CVE-2006-3654 (Buffer overflow in wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet ...)
2194 NOT-FOR-US: Microsoft Works Spreadsheet
2195 CVE-2006-3653 (wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote ...)
2196 NOT-FOR-US: Microsoft Works Spreadsheet
2197 CVE-2006-3652 (Microsoft Internet Security and Acceleration (ISA) Server 2004 allows ...)
2198 NOT-FOR-US: Microsoft Internet Security and Acceleration Server
2199 CVE-2006-3651
2200 RESERVED
2201 CVE-2006-3650
2202 RESERVED
2203 CVE-2006-3649 (Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK ...)
2204 NOT-FOR-US: Microsoft
2205 CVE-2006-3648 (Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and ...)
2206 NOT-FOR-US: Microsoft
2207 CVE-2006-3647
2208 RESERVED
2209 CVE-2006-3646
2210 RESERVED
2211 CVE-2006-3645
2212 RESERVED
2213 CVE-2006-3644
2214 RESERVED
2215 CVE-2006-3643 (Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and ...)
2216 NOT-FOR-US: Microsoft
2217 CVE-2006-3642
2218 RESERVED
2219 CVE-2006-3641
2220 RESERVED
2221 CVE-2006-3640 (Microsoft Internet Explorer 5.01 and 6 allows certain script to ...)
2222 NOT-FOR-US: Microsoft
2223 CVE-2006-3639 (Microsoft Internet Explorer 5.01 and 6 does not properly identify the ...)
2224 NOT-FOR-US: Microsoft
2225 CVE-2006-3638 (Microsoft Internet Explorer 5.01 and 6 does not properly handle ...)
2226 NOT-FOR-US: Microsoft
2227 CVE-2006-3637 (Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle ...)
2228 NOT-FOR-US: Microsoft
2229 CVE-2006-3636 (Multiple cross-site scripting (XSS) vulnerabilities in Mailman before ...)
2230 TODO: check
2231 CVE-2006-3635
2232 RESERVED
2233 CVE-2006-3634 (The (1) __futex_atomic_op and (2) futex_atomic_cmpxchg_inatomic ...)
2234 - linux-2.6 2.6.17-1 (medium)
2235 - linux-2.6.16 <not-affected> (introduced in 2.6.17-rc4)
2236 CVE-2006-3633 (OSSP shiela 1.1.5 and earlier allows remote authenticated users to ...)
2237 NOT-FOR-US: shiela
2238 CVE-2006-3632 (Buffer overflow in Wireshark (aka Ethereal) 0.8.16 to 0.99.0 ...)
2239 {DSA-1127}
2240 - ethereal <removed> (bug #378745; high)
2241 - wireshark 0.99.2-1 (high)
2242 CVE-2006-3631 (Unspecified vulnerability in the SSH dissector in Wireshark (aka ...)
2243 {DSA-1127}
2244 - ethereal <removed> (bug #378745; high)
2245 - wireshark 0.99.2-1 (high)
2246 CVE-2006-3630 (Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to ...)
2247 {DSA-1127}
2248 - ethereal <removed> (bug #378745; high)
2249 - wireshark 0.99.2-1 (high)
2250 CVE-2006-3629 (Unspecified vulnerability in the MOUNT dissector in Wireshark ...)
2251 {DSA-1127}
2252 - ethereal <removed> (bug #378745; high)
2253 - wireshark 0.99.2-1 (high)
2254 CVE-2006-3628 (Multiple format string vulnerabilities in Wireshark (aka Ethereal) ...)
2255 {DSA-1127}
2256 - ethereal <removed> (bug #378745; high)
2257 - wireshark 0.99.2-1 (high)
2258 CVE-2006-3627 (Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark ...)
2259 - ethereal <removed> (bug #378745; high)
2260 - wireshark 0.99.2-1 (high)
2261 [sarge] - ethereal <no-dsa> (Vulnerable code not present)
2262 CVE-2006-3625 (FLV Players 8 allows remote attackers to obtain sensitive information ...)
2263 NOT-FOR-US: FLV Players
2264 CVE-2006-3624 (Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 ...)
2265 NOT-FOR-US: FLV Players
2266 CVE-2006-3623 (Directory traversal vulnerability in Framework Service component in ...)
2267 NOT-FOR-US: McAfee ePolicy Orchestrator
2268 CVE-2006-3622 (The showtopic module in Koobi Pro CMS 5.6 allows remote attackers to ...)
2269 NOT-FOR-US: Koobi Pro CMS
2270 CVE-2006-3621 (SQL injection vulnerability in the showtopic module in Koobi Pro CMS ...)
2271 NOT-FOR-US: Koobi Pro CMS
2272 CVE-2006-3620 (Cross-site scripting (XSS) vulnerability in the showtopic module in ...)
2273 NOT-FOR-US: Koobi Pro CMS
2274 CVE-2006-3619 (Directory traversal vulnerability in FastJar 0.93, as used in Gnu GCC ...)
2275 {DSA-1170}
2276 - gcc-4.1 4.1.1-11 (bug #368397; low)
2277 CVE-2006-3618 (SQL injection vulnerability in pblguestbook.php in Pixelated By Lev ...)
2278 NOT-FOR-US: Pixelated By Lev (PBL) Guestbook
2279 CVE-2006-3617 (Cross-site scripting (XSS) vulnerability in pblguestbook.php in ...)
2280 NOT-FOR-US: Pixelated By Lev (PBL) Guestbook
2281 CVE-2006-3616 (Multiple cross-site scripting (XSS) vulnerabilities in Carbonize ...)
2282 NOT-FOR-US: Carbonize Lazarus Guestbook
2283 CVE-2006-3615 (Multiple PHP remote file inclusion vulnerabilities in Phorum 5.1.14, ...)
2284 NOT-FOR-US: Phorum
2285 CVE-2006-3614 (index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to ...)
2286 NOT-FOR-US: Orbitcoders OrbitMATRIX
2287 CVE-2006-3613 (Multiple cross-site scripting (XSS) vulnerabilities in Chamberland ...)
2288 NOT-FOR-US: Chamberland Technology ezWaiter
2289 CVE-2006-3612 (Cross-site scripting (XSS) vulnerability in Phorum 5.1.14 allows ...)
2290 NOT-FOR-US: Phorum
2291 CVE-2006-3611 (Directory traversal vulnerability in pm.php in Phorum 5 allows remote ...)
2292 NOT-FOR-US: Phorum
2293 CVE-2006-3610 (index.php in Orbitcoders OrbitMATRIX 1.0 allows remote attackers to ...)
2294 NOT-FOR-US: Orbitcoders OrbitMATRIX
2295 CVE-2006-3609 (Cross-site scripting (XSS) vulnerability in index.php in Orbitcoders ...)
2296 NOT-FOR-US: Orbitcoders OrbitMATRIX
2297 CVE-2006-3608 (The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when ...)
2298 NOT-FOR-US: Simone Vellei Flatnuke
2299 CVE-2006-3607 (Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner ...)
2300 NOT-FOR-US: Softbiz Banner Exchange Script (aka Banner Exchange Network Script)
2301 CVE-2006-3606 (Unspecified vulnerability in Sun Solaris X Inter Client Exchange ...)
2302 NOTE: Debian has a libice - is it the same one?
2303 TODO: check
2304 CVE-2006-3605 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2305 NOT-FOR-US: Microsoft Internet Explorer
2306 CVE-2006-3604 (Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and ...)
2307 NOT-FOR-US: FlexWATCH Network Camera
2308 CVE-2006-3603 (Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH ...)
2309 NOT-FOR-US: FlexWATCH Network Camera
2310 CVE-2006-3602 (Directory traversal vulnerability in ...)
2311 TODO: check wordpress, moodle
2312 - knowledgeroot <not-affected> (fixed before first upload; see bug #381912)
2313 CVE-2006-3601 (** UNVERIFIABLE ** ...)
2314 NOT-FOR-US: DotNetNuke
2315 CVE-2006-3600 (Multiple stack-based buffer overflows in the LookupTRM::lookup ...)
2316 {DSA-1135-1}
2317 - libtunepimp 0.4.2-3.0etch1 (bug #378091; medium)
2318 CVE-2006-3599 (SQL injection vulnerability in the Nuke Advanced Classifieds module ...)
2319 NOT-FOR-US: Nuke Advanced Classifieds module for PHP-Nuke
2320 CVE-2006-3598 (SQL injection vulnerability in the Sections module for PHP-Nuke allows ...)
2321 NOT-FOR-US: Sections module for PHP-Nuke
2322 CVE-2006-3597 (passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password ...)
2323 - shadow <not-affected> (fix for a mistake in the Ubuntu installer)
2324 CVE-2006-3596 (The device driver for Intel-based gigabit network adapters in Cisco ...)
2325 NOT-FOR-US: Cisco
2326 CVE-2006-3595 (The default configuration of IOS HTTP server in Cisco Router Web Setup ...)
2327 NOT-FOR-US: Cisco
2328 CVE-2006-3594 (Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through ...)
2329 NOT-FOR-US: Cisco
2330 CVE-2006-3593 (The command line interface (CLI) in Cisco Unified CallManager (CUCM) ...)
2331 NOT-FOR-US: Cisco
2332 CVE-2006-3592 (Unspecified vulnerability in the command line interface (CLI) in Cisco ...)
2333 NOT-FOR-US: Cisco
2334 CVE-2006-3591 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2335 NOT-FOR-US: Microsoft Internet Explorer
2336 CVE-2006-3626 (Race condition in Linux kernel 2.6.17.4 and earlier allows local users ...)
2337 {DSA-1111}
2338 - linux-2.6.16 2.6.16-17 (high)
2339 - linux-2.6 2.6.17-4 (high)
2340 CVE-2006-XXXX [insufficient form variable escaping]
2341 - webauth 3.5.2-1
2342 CVE-2006-3590 (mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows ...)
2343 NOT-FOR-US: Microsoft PowerPoint
2344 CVE-2006-3589 (vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure ...)
2345 NOT-FOR-US: VMware
2346 CVE-2006-3588 (Unspecified vulnerability in Macromedia Flash Player 8.0.24.0 allows ...)
2347 NOT-FOR-US: Macromedia Flash Player 8
2348 CVE-2006-3587 (Unspecified vulnerability in Macromedia Flash Player 8.0.24.0 allows ...)
2349 NOT-FOR-US: Macromedia Flash Player 8
2350 CVE-2006-3586 (SQL injection vulnerability in Jetbox CMS 2.1 SR1 allows remote ...)
2351 NOT-FOR-US: Jetbox CMS
2352 CVE-2006-3585 (Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS 2.1 ...)
2353 NOT-FOR-US: Jetbox CMS
2354 CVE-2006-3584 (Dynamic variable evaluation vulnerability in index.php in Jetbox CMS ...)
2355 NOT-FOR-US: Jetbox CMS
2356 CVE-2006-3583 (Session fixation vulnerability in Jetbox CMS 2.1 SR1 allows remote ...)
2357 NOT-FOR-US: Jetbox CMS
2358 CVE-2006-3582 (Multiple heap-based buffer overflows in Audacious AdPlug 2.0 and ...)
2359 - adplug 2.0.1-1 (bug #378279; medium)
2360 CVE-2006-3581 (Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and ...)
2361 - adplug 2.0.1-1 (bug #378279; medium)
2362 CVE-2006-3580 (SQL injection vulnerability in pages.asp in ASP Stats Generator before ...)
2363 NOT-FOR-US: ASP Stats Generator
2364 CVE-2006-3579 (Cross-site scripting (XSS) vulnerability in Fujitsu ServerView 2.50 up ...)
2365 NOT-FOR-US: Fujitsu ServerView
2366 CVE-2006-3578 (Directory traversal vulnerability in Fujitsu ServerView 2.50 up to ...)
2367 NOT-FOR-US: Fujitsu ServerView
2368 CVE-2006-3577 (SQL injection vulnerability in index.php in LifeType 1.0.5 allows ...)
2369 NOT-FOR-US: LifeType
2370 CVE-2006-3576 (SQL injection vulnerability in Search.PHP in SenseSites CommonSense ...)
2371 NOT-FOR-US: SenseSites CommonSense
2372 CVE-2006-3575 (Unknown vulnerability in the Buffer Overflow Protection in McAfee ...)
2373 NOT-FOR-US: McAfee VirusScan Enterprise
2374 CVE-2006-3574 (Multiple cross-site scripting (XSS) vulnerabilities in Hitachi ...)
2375 NOT-FOR-US: Hitachi Groupmax Collaboration Portal and Web Client and uCosminexus Collaboration Portal and Forum/File Sharing
2376 CVE-2006-3573 (Format string vulnerability in agl_text.cpp in Milan Mimica Sparklet ...)
2377 NOT-FOR-US: Milan Mimica Sparklet
2378 CVE-2006-3572 (SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and ...)
2379 NOT-FOR-US: Papoo
2380 CVE-2006-3571 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
2381 NOT-FOR-US: Papoo
2382 CVE-2006-3570 (Cross-site scripting (XSS) vulnerability in the webform module in ...)
2383 - drupal <not-affected> (webform module is not in Debian Drupal 4.5 package)
2384 CVE-2006-3569 (Unspecified vulnerability in NetApp Data ONTAP 7.0x through 7.0.4P8D9, ...)
2385 NOT-FOR-US: IBM Data ONTAP
2386 CVE-2006-3568 (Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php ...)
2387 NOT-FOR-US: Fantastic Guestbook
2388 CVE-2006-3567 (Cross-site scripting (XSS) vulnerability in the web administration ...)
2389 NOT-FOR-US: Juniper
2390 CVE-2006-3566 (search.results.php in HiveMail 3.1 and earlier allows remote attackers ...)
2391 NOT-FOR-US: HiveMail
2392 CVE-2006-3565 (SQL injection vulnerability in search.results.php in HiveMail 1.3 and ...)
2393 NOT-FOR-US: HiveMail
2394 CVE-2006-3564 (Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 ...)
2395 NOT-FOR-US: HiveMail
2396 CVE-2006-3563 (Cross-site scripting (XSS) vulnerability in gallery/thumb.php in ...)
2397 NOT-FOR-US: Winged Gallery
2398 CVE-2006-3562 (PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow ...)
2399 NOT-FOR-US: Plume CMS
2400 CVE-2006-3561 (BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and ...)
2401 NOT-FOR-US: BT Voyager
2402 CVE-2006-3560 (SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums ...)
2403 NOT-FOR-US: Blue Dojo Graffiti Forums
2404 CVE-2006-3559 (Multiple SQL injection vulnerabilities in Arif Supriyanto auraCMS 1.62 ...)
2405 NOT-FOR-US: auraCMS
2406 CVE-2006-3558 (Multiple cross-site scripting (XSS) vulnerabilities in Arif Supriyanto ...)
2407 NOT-FOR-US: auraCMS
2408 CVE-2006-3557 (MT Orumcek Toplist 2.2 stores DB/orumcektoplist.mdb under the web root ...)
2409 NOT-FOR-US: MT Orumcek Toplist
2410 CVE-2006-3556 (PHP remote file inclusion vulnerability in extcalendar.php in Mohamed ...)
2411 NOT-FOR-US: Mohamed Moujami ExtCalendar
2412 CVE-2006-3555 (Multiple cross-site scripting (XSS) vulnerabilities in submit.php in ...)
2413 NOT-FOR-US: PHP-Fusion
2414 CVE-2006-3554 (Directory traversal vulnerability in index.php in MKPortal 1.0.1 Final ...)
2415 NOT-FOR-US: MKPortal
2416 CVE-2006-3553 (PlaNet Concept planetNews allows remote attackers to bypass ...)
2417 NOT-FOR-US: planetNews
2418 CVE-2006-3552 (Premium Anti-Spam in Ipswitch IMail Secure Server 2006 and ...)
2419 NOT-FOR-US: Ipswitch IMail Secure Server 2006 and Collaboration Suite 2006 Premium
2420 CVE-2006-3551 (NCP Secure Enterprise Client (aka VPN/PKI client) 8.30 Build 59, and ...)
2421 NOT-FOR-US: NCP VPN/PKI Client (apparently nothing to do with Novell)
2422 CVE-2006-3550 (Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks ...)
2423 NOT-FOR-US: F5 Netowrks FirePass
2424 CVE-2006-3549 (services/go.php in Horde Application Framework 3.0.0 through 3.0.10 ...)
2425 - horde3 3.1.2-1 (bug #378281; low)
2426 CVE-2006-3548 (Multiple cross-site scripting (XSS) vulnerabilities in Horde ...)
2427 - horde3 3.1.2-1 (bug #378281; low)
2428 CVE-2006-3547 (** DISPUTED ** ...)
2429 NOT-FOR-US: EMC VMware Player
2430 CVE-2006-3546 (Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote ...)
2431 NOT-FOR-US: Patrice Freydiere ImgSvr
2432 CVE-2006-3545 (** DISPUTED ** Microsoft Internet Explorer 7.0 Beta allows remote ...)
2433 NOT-FOR-US: Microsoft Internet Explorer
2434 CVE-2006-3544 (** DISPUTED ** ...)
2435 NOT-FOR-US: Invision Power Board
2436 CVE-2006-3543 (** DISPUTED ** ...)
2437 NOT-FOR-US: Invision Power Board
2438 CVE-2006-3542 (Multiple cross-site scripting (XSS) vulnerabilities in Garry Glendown ...)
2439 NOT-FOR-US: Garry Glendown Shopping Cart
2440 CVE-2006-3541 (SQL injection vulnerability in Meine Links (aka My Links) in Kyberna ...)
2441 NOT-FOR-US: Meine Links (aka My Links) in Kyberna ky2help
2442 CVE-2006-3540 (Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, ...)
2443 NOT-FOR-US: Check Point Zone Labs ZoneAlarm Internet Security Suite
2444 CVE-2006-3539 (Multiple cross-site scripting (XSS) vulnerabilities in DKScript.com ...)
2445 NOT-FOR-US: DKScript.com Dragon's Kingdom Script
2446 CVE-2006-3538 (Multiple cross-site scripting (XSS) vulnerabilities in demo.php in ...)
2447 NOT-FOR-US: BeatificFaith Eprayer
2448 CVE-2006-3537 (PHP remote file inclusion vulnerability in index.php in Randshop ...)
2449 NOT-FOR-US: Randshop
2450 CVE-2006-3536 (Direct static code injection vulnerability in code/class_db_text.php ...)
2451 NOT-FOR-US: EJ3 TOPo
2452 CVE-2006-3535 (Directory traversal vulnerability in Nullsoft SHOUTcast DSP before ...)
2453 NOT-FOR-US: Nullsoft SHOUTcast DSP
2454 CVE-2006-3534 (Directory traversal vulnerability in Nullsoft SHOUTcast DSP before ...)
2455 NOT-FOR-US: Nullsoft SHOUTcast DSP
2456 CVE-2006-3533 (Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 ...)
2457 NOT-FOR-US: Pivot
2458 CVE-2006-3532 (PHP file inclusion vulnerability in includes/edit_new.php in Pivot ...)
2459 NOT-FOR-US: Pivot
2460 CVE-2006-3531 (includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates ...)
2461 NOT-FOR-US: Pivot
2462 CVE-2006-3530 (PHP remote file inclusion vulnerability in ...)
2463 NOT-FOR-US: PccookBook Component for Mambo and Joomla
2464 CVE-2003-1304 (EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under ...)
2465 NOT-FOR-US: EarlyImpact ProductCart
2466 CVE-2006-3529 (Memory leak in Juniper JUNOS 6.4 through 8.0, built before May 10, ...)
2467 NOT-FOR-US: Juniper JUNOS
2468 CVE-2006-3528 (Multiple PHP remote file inclusion vulnerabilities in Simpleboard ...)
2469 NOT-FOR-US: Simpleboard Mambo module
2470 CVE-2006-3527 (Multiple PHP remote file inclusion vulnerabilities in BosClassifieds ...)
2471 NOT-FOR-US: BosClassifieds Classified Ads
2472 CVE-2006-3526 (Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php ...)
2473 NOT-FOR-US: Sport-slo Advanced Guestbook
2474 CVE-2006-3525 (SQL injection vulnerability in category.php in PHCDownload 1.0.0 Final ...)
2475 NOT-FOR-US: PHCDownload
2476 CVE-2006-3524 (Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows ...)
2477 NOT-FOR-US: SIPfoundry sipXtapi
2478 CVE-2006-3523 (Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote ...)
2479 NOT-FOR-US: Clearswift MIMEsweeper
2480 CVE-2006-3522 (Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for ...)
2481 NOT-FOR-US: Clearswift MIMEsweeper
2482 CVE-2006-3521 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
2483 NOT-FOR-US: SiteForge Collaborative Development Platform
2484 CVE-2006-3520 (PHP remote file inclusion vulnerability in ...)
2485 NOT-FOR-US: Sabdrimer Pro
2486 CVE-2006-3519 (Multiple cross-site scripting (XSS) vulnerabilities in The Banner ...)
2487 NOT-FOR-US: The Banner Engine
2488 CVE-2006-3518 (SQL injection vulnerability in SayfalaAltList.asp in Webvizyon Portal ...)
2489 NOT-FOR-US: Webvizyon Portal
2490 CVE-2006-3517 (PHP remote file inclusion vulnerability in stats.php in RW::Download, ...)
2491 NOT-FOR-US: RW::Download
2492 CVE-2006-3516 (Multiple SQL injection vulnerabilities in FreeHost allow remote ...)
2493 NOT-FOR-US: FreeHost
2494 CVE-2006-3515 (SQL injection vulnerability in the loginADP function in ajaxp.php in ...)
2495 NOT-FOR-US: AjaxPortal
2496 CVE-2006-3514 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
2497 NOT-FOR-US: PHP-Blogger
2498 CVE-2006-3513 (danim.dll in Microsoft Internet Explorer 6 allows remote attackers to ...)
2499 NOT-FOR-US: Microsoft Internet Explorer
2500 CVE-2006-3512 (Internet Explorer 6 on Windows XP allows remote attackers to cause a ...)
2501 NOT-FOR-US: Microsoft Internet Explorer
2502 CVE-2006-3511 (Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause ...)
2503 NOT-FOR-US: Microsoft Internet Explorer
2504 CVE-2006-3510 (The Remote Data Service Object (RDS.DataControl) in Microsoft Internet ...)
2505 NOT-FOR-US: Microsoft Internet Explorer
2506 CVE-2006-3509
2507 RESERVED
2508 CVE-2006-3508
2509 RESERVED
2510 CVE-2006-3507
2511 RESERVED
2512 CVE-2006-3506 (Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and ...)
2513 NOT-FOR-US: Mac OS X
2514 CVE-2006-3505 (WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to ...)
2515 NOT-FOR-US: Apple Mac OS
2516 CVE-2006-3504 (The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 ...)
2517 NOT-FOR-US: Apple Mac OS
2518 CVE-2006-3503 (Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows ...)
2519 NOT-FOR-US: Apple Mac OS
2520 CVE-2006-3502 (Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows ...)
2521 NOT-FOR-US: Apple Mac OS
2522 CVE-2006-3501 (Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows ...)
2523 NOT-FOR-US: Apple Mac OS
2524 CVE-2006-3500 (The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users ...)
2525 NOT-FOR-US: Apple Mac OS
2526 CVE-2006-3499 (The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users ...)
2527 NOT-FOR-US: Apple Mac OS
2528 CVE-2006-3498 (Stack-based buffer overflow in bootpd in the DHCP component for Apple ...)
2529 NOT-FOR-US: Apple Mac OS
2530 CVE-2006-3497 (Unspecified vulnerability in the &quot;compression state handling&quot; in Bom ...)
2531 NOT-FOR-US: Apple Mac OS
2532 CVE-2006-3496 (AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers ...)
2533 NOT-FOR-US: Apple Mac OS
2534 CVE-2006-3495 (AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys ...)
2535 NOT-FOR-US: Apple Mac OS
2536 CVE-2006-3494 (Multiple cross-site scripting (XSS) vulnerabilities in Buddy Zone ...)
2537 NOT-FOR-US: Buddy Zone
2538 CVE-2006-3493 (Buffer overflow in LsCreateLine function (mso_203) in mso.dll and ...)
2539 NOT-FOR-US: Microsoft Office
2540 CVE-2006-3492 (The CORBA::ORBInvokeRec::set_answer_invoke function in orb.cc in MICO ...)
2541 NOT-FOR-US: MICO
2542 CVE-2006-3491 (Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows ...)
2543 NOT-FOR-US: Kaillera Server
2544 CVE-2006-3490 (F-Secure Anti-Virus 2003 through 2006 and other versions, Internet ...)
2545 NOT-FOR-US: F-Secure Anti-Virus
2546 CVE-2006-3489 (F-Secure Anti-Virus 2003 through 2006 and other versions, Internet ...)
2547 NOT-FOR-US: F-Secure Anti-Virus
2548 CVE-2006-3488 (Absolute path traversal vulnerability in administrador.asp in ...)
2549 NOT-FOR-US: VirtuaStore
2550 CVE-2006-3487 (VirtuaStore 2.0 stores sensitive files under the web root with ...)
2551 NOT-FOR-US: VirtuaStore
2552 CVE-2006-3485 (Multiple SQL injection vulnerabilities in AstroDog Press Some Chess ...)
2553 NOT-FOR-US: AstroDog Press Some Chess
2554 CVE-2006-3484 (Multiple cross-site scripting (XSS) vulnerabilities in ATutor before ...)
2555 NOT-FOR-US: ATutor
2556 CVE-2006-3483 (PHPMailList 1.8.0 stores sensitive information under the web document ...)
2557 NOT-FOR-US: PHPMailList
2558 CVE-2006-3482 (Cross-site scripting (XSS) vulnerability in maillist.php in ...)
2559 NOT-FOR-US: PHPMailList
2560 CVE-2006-3481 (Multiple SQL injection vulnerabilities in Joomla! before 1.0.10 allow ...)
2561 - joomla <itp> (bug #326398)
2562 CVE-2006-3480 (Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before ...)
2563 - joomla <itp> (bug #326398)
2564 CVE-2006-3479 (Cross-site request forgery (CSRF) vulnerability in the del_block ...)
2565 NOT-FOR-US: Nuked-Klan
2566 CVE-2006-3478 (PHP remote file inclusion vulnerability in ...)
2567 NOT-FOR-US: MyPHP CMS
2568 CVE-2006-3477 (Unspecified vulnerability in the POP service in Stalker CommuniGate ...)
2569 NOT-FOR-US: Stalker CommuniGate Pro
2570 CVE-2006-3476 (Cross-site scripting (XSS) vulnerability in comments.php in ...)
2571 NOT-FOR-US: PhpWebGallery
2572 CVE-2006-3475 (Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 ...)
2573 NOT-FOR-US: QBoard
2574 CVE-2006-3474 (Multiple SQL injection vulnerabilities in Belchior Foundry vCard PRO ...)
2575 NOT-FOR-US: Belchior Foundry vCard PRO
2576 CVE-2006-3473 (CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 ...)
2577 - drupal <not-affected> (form_mail Module not in debian)
2578 CVE-2006-3472 (Microsoft Internet Explorer 6.0 and 6.0 SP1 allows remote attackers to ...)
2579 NOT-FOR-US: Microsoft Internet Explorer
2580 CVE-2006-3471 (Microsoft Internet Explorer 6 on Windows XP allows remote attackers to ...)
2581 NOT-FOR-US: Microsoft Internet Explorer
2582 CVE-2006-3470 (The Dell Openmanage CD launches X11 and SSH daemons that do not ...)
2583 NOT-FOR-US: Dell Openmanage CD
2584 CVE-2006-3469 (Format string vulnerability in time.cc in MySQL Server 4.1 before ...)
2585 {DSA-1112}
2586 - mysql-dfsg-5.0 5.0.22-1
2587 CVE-2006-3468 (Linux kernel 2.6.x, when using both NFS and EXT3, allows remote ...)
2588 - linux-2.6 <unfixed>
2589 - linux-2.6.16 2.6.16-18
2590 CVE-2006-3467 (Integer overflow in FreeType before 2.2 allows remote attackers to ...)
2591 - freetype 2.2.1-1 (bug #379920; medium)
2592 - libxfont 1:1.2.0-2 (medium; bug #383353)
2593 [sarge] - xfree86 <unfixed> (medium)
2594 CVE-2006-3466
2595 REJECTED
2596 CVE-2006-3465 (Unspecified vulnerability in the custom tag support for the TIFF ...)
2597 {DSA-1137-1}
2598 - tiff 3.8.2-6
2599 CVE-2006-3464 (TIFF library (libtiff) before 3.8.2 allows context-dependent attackers ...)
2600 {DSA-1137-1}
2601 - tiff 3.8.2-6
2602 CVE-2006-3463 (The EstimateStripByteCounts function in TIFF library (libtiff) before ...)
2603 {DSA-1137-1}
2604 - tiff 3.8.2-6
2605 CVE-2006-3462 (Heap-based buffer overflow in the NeXT RLE decoder in the TIFF library ...)
2606 {DSA-1137-1}
2607 - tiff 3.8.2-6
2608 CVE-2006-3461 (Heap-based buffer overflow in the PixarLog decoder in the TIFF library ...)
2609 {DSA-1137-1}
2610 - tiff 3.8.2-6
2611 CVE-2006-3460 (Heap-based buffer overflow in the JPEG decoder in the TIFF library ...)
2612 {DSA-1137-1}
2613 - tiff 3.8.2-6
2614 CVE-2006-3459 (Multiple stack-based buffer overflows in the TIFF library (libtiff) ...)
2615 {DSA-1137-1}
2616 - tiff 3.8.2-6
2617 CVE-2006-3486 (** DISPUTED ** ...)
2618 - mysql-dfsg-5.0 5.0.22-4 (unimportant)
2619 [sarge] - mysql-dfsg-4.1 <not-affected> (Vulnerable code not present)
2620 [sarge] - mysql-dfsg <not-affected> (Vulnerable code not present)
2621 NOTE: Only DoS possible, only root can trigger this -> non-issue
2622 CVE-2006-3457 (Symantec On-Demand Agent (SODA) before 2.5 MR2 Build 2157, and the ...)
2623 NOT-FOR-US: Symantec
2624 CVE-2006-3456
2625 RESERVED
2626 CVE-2006-3455
2627 RESERVED
2628 CVE-2006-3454
2629 RESERVED
2630 CVE-2006-3453 (Buffer overflow in Adobe Acrobat 6.0 to 6.0.4 allows remote attackers ...)
2631 NOT-FOR-US: Adobe acrobat
2632 CVE-2006-3452 (Adobe Reader and Acrobat 6.0.4 and earlier, on Mac OSX, has insecure ...)
2633 NOT-FOR-US: Adobe acrobat
2634 CVE-2006-3451 (Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage ...)
2635 NOT-FOR-US: Microsoft
2636 CVE-2006-3450 (Microsoft Internet Explorer 6 allows remote attackers to execute ...)
2637 NOT-FOR-US: Microsoft
2638 CVE-2006-3449 (Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, ...)
2639 NOT-FOR-US: Microsoft
2640 CVE-2006-3448
2641 RESERVED
2642 CVE-2006-3447
2643 RESERVED
2644 CVE-2006-3446
2645 RESERVED
2646 CVE-2006-3445
2647 RESERVED
2648 CVE-2006-3444 (Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, ...)
2649 NOT-FOR-US: Microsoft
2650 CVE-2006-3443 (Untrusted search path vulnerability in Winlogon in Microsoft Windows ...)
2651 NOT-FOR-US: Microsoft
2652 CVE-2006-3442
2653 RESERVED
2654 CVE-2006-3441 (Buffer overflow in the DNS Client service in Microsoft Windows 2000 ...)
2655 NOT-FOR-US: Microsoft
2656 CVE-2006-3440 (Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP ...)
2657 NOT-FOR-US: Microsoft
2658 CVE-2006-3439 (Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, ...)
2659 NOT-FOR-US: Microsoft
2660 CVE-2006-3438 (Unspecified vulnerability in Microsoft Hyperlink Object Library ...)
2661 NOT-FOR-US: Microsoft
2662 CVE-2006-3437
2663 RESERVED
2664 CVE-2006-3436
2665 RESERVED
2666 CVE-2006-3435
2667 RESERVED
2668 CVE-2006-3434
2669 RESERVED
2670 CVE-2006-3433
2671 RESERVED
2672 CVE-2006-3432
2673 RESERVED
2674 CVE-2006-3431 (Buffer overflow in certain Asian language versions of Microsoft Excel ...)
2675 NOT-FOR-US: Microsoft Excel
2676 CVE-2006-3430 (SQL injection vulnerability in checkprofile.asp in (1) PatchLink ...)
2677 NOT-FOR-US: Novell PatchLink Update Server
2678 CVE-2006-3429 (Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows ...)
2679 NOT-FOR-US: TTCalc
2680 CVE-2006-3428 (Cross-site scripting (XSS) vulnerability in TigerTom TTCalc 1.0 allows ...)
2681 NOT-FOR-US: TTCalc
2682 CVE-2006-3427 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2683 NOT-FOR-US: Microsoft Internet Explorer
2684 CVE-2006-3426 (Directory traversal vulnerability in (a) PatchLink Update Server ...)
2685 NOT-FOR-US: Novell PatchLink Update Server
2686 CVE-2006-3425 (FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and ...)
2687 NOT-FOR-US: Novell PatchLink Update Server
2688 CVE-2006-3424 (Multiple buffer overflows in WebEx Downloader ActiveX Control, ...)
2689 NOT-FOR-US: WebEx Downloader ActiveX Control
2690 CVE-2006-3423 (WebEx Downloader ActiveX Control and WebEx Downloader Java before ...)
2691 NOT-FOR-US: WebEx Downloader ActiveX Control
2692 CVE-2006-3422 (PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows ...)
2693 NOT-FOR-US: WonderEdit Pro CMS
2694 CVE-2006-3421 (PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and ...)
2695 NOT-FOR-US: SmartSiteCMS
2696 CVE-2006-3420 (Cross-site request forgery (CSRF) vulnerability in editpost.php in ...)
2697 NOT-FOR-US: MyBB
2698 CVE-2006-3419 (Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes ...)
2699 - tor 0.1.1.20-1
2700 CVE-2006-3418 (Tor before 0.1.1.20 does not validate that a server descriptor's ...)
2701 - tor 0.1.1.20-1
2702 CVE-2006-3417 (Tor client before 0.1.1.20 prefers entry points based on is_fast or ...)
2703 - tor 0.1.1.20-1
2704 CVE-2006-3416 (** DISPUTED ** ...)
2705 - tor 0.1.1.20-1
2706 CVE-2006-3415 (Tor before 0.1.1.20 uses improper logic to validate the &quot;OR&quot; ...)
2707 - tor 0.1.1.20-1
2708 CVE-2006-3414 (Tor before 0.1.1.20 supports server descriptors that contain hostnames ...)
2709 - tor 0.1.1.20-1
2710 CVE-2006-3413 (The privoxy configuration file in Tor before 0.1.1.20, when run on ...)
2711 - tor 0.1.1.20-1
2712 CVE-2006-3412 (Tor before 0.1.1.20 does not sufficiently obey certain firewall ...)
2713 - tor 0.1.1.20-1
2714 CVE-2006-3411 (TLS handshakes in Tor before 0.1.1.20 generate public-private keys ...)
2715 - tor 0.1.1.20-1
2716 CVE-2006-3410 (Tor before 0.1.1.20 creates &quot;internal circuits&quot; primarily consisting ...)
2717 - tor 0.1.1.20-1
2718 CVE-2006-3409 (Integer overflow in Tor before 0.1.1.20 allows remote attackers to ...)
2719 - tor 0.1.1.20-1
2720 CVE-2006-3408 (Unspecified vulnerability in the directory server (dirserver) in Tor ...)
2721 - tor 0.1.1.20-1
2722 CVE-2006-3407 (Tor before 0.1.1.20 allows remote attackers to spoof log entries or ...)
2723 - tor 0.1.1.20-1
2724 CVE-2006-3406 (Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 ...)
2725 NOT-FOR-US: QTOFileManager
2726 CVE-2006-3405 (Cross-site scripting (XSS) vulnerability in qtofm.php in ...)
2727 NOT-FOR-US: QTOFileManager
2728 CVE-2006-3403 (The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote ...)
2729 {DSA-1110}
2730 - samba 3.0.23a-1 (bug #378070)
2731 CVE-2006-3402 (SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers ...)
2732 NOT-FOR-US: VirtuaStore
2733 CVE-2006-3401 (Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: ...)
2734 - quake3 <itp> (bug #337937)
2735 CVE-2006-3400 (Stack-based buffer overflow in the CG_ServerCommand function in Quake ...)
2736 NOT-FOR-US: Soldier of Fortune 2
2737 CVE-2006-3399 (Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki ...)
2738 NOT-FOR-US: MoniWiki
2739 CVE-2006-3398 (The &quot;change password forms&quot; in Taskjitsu before 2.0.1 includes ...)
2740 NOT-FOR-US: Taskjitsu
2741 CVE-2006-3397 (Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu ...)
2742 NOT-FOR-US: Taskjitsu
2743 CVE-2006-3396 (PHP remote file inclusion vulnerability in galleria.html.php in ...)
2744 NOT-FOR-US: Galleria Mambo Module
2745 CVE-2006-3395 (PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX ...)
2746 NOT-FOR-US: SiteBuilder-FX
2747 CVE-2006-3394 (SQL injection vulnerability in the files mod in index.php in BXCP ...)
2748 NOT-FOR-US: BXCP
2749 CVE-2006-3393 (Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and ...)
2750 NOT-FOR-US: Papyrus NASCAR Racing
2751 CVE-2006-3392 (Webmin before 1.290 and Usermin before 1.220 calls the simplify_path ...)
2752 - webmin <removed> (medium; bug #381537)
2753 CVE-2006-3391 (The Execute function in iMBCContents ActiveX Control before 2.0.0.59 ...)
2754 NOT-FOR-US: iMBCContents
2755 CVE-2006-3390 (WordPress 2.0.3 allows remote attackers to obtain the installation ...)
2756 - wordpress <unfixed> (unimportant)
2757 CVE-2006-3389 (index.php in WordPress 2.0.3 allows remote attackers to obtain ...)
2758 - wordpress <unfixed> (unimportant)
2759 CVE-2006-3388 (Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 ...)
2760 - phpmyadmin 4:2.8.2-0.1 (bug #377748; low)
2761 [sarge] - phpmyadmin <not-affected> (Vulnerable code not present)
2762 CVE-2006-3387 (Directory traversal vulnerability in sources/post.php in Fusion News ...)
2763 NOT-FOR-US: Fusion News
2764 CVE-2006-3386 (index.php in Vincent Leclercq News 5.2 allows remote attackers to ...)
2765 NOT-FOR-US: Vincent Leclercq News
2766 CVE-2006-3385 (Cross-site scripting (XSS) vulnerability in divers.php in Vincent ...)
2767 NOT-FOR-US: Vincent Leclercq News
2768 CVE-2006-3384 (SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 ...)
2769 NOT-FOR-US: Vincent Leclercq News
2770 CVE-2006-3383 (Cross-site scripting (XSS) vulnerability in index.php in mAds 1.0 ...)
2771 NOT-FOR-US: mAds
2772 CVE-2006-3382 (Cross-site scripting (XSS) vulnerability in search.php in mAds 1.0 ...)
2773 NOT-FOR-US: mAds
2774 CVE-2006-3381 (SturGeoN Upload allows remote attackers to execute arbitrary PHP code ...)
2775 NOT-FOR-US: SturGeoN
2776 CVE-2006-3380 (Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 ...)
2777 NOT-FOR-US: FreeStyle Wiki
2778 CVE-2006-3379 (Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 ...)
2779 {DSA-1119}
2780 - hiki 0.8.6-1 (bug #378059; low)
2781 CVE-2006-3378 (passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called ...)
2782 {DSA-1150-1}
2783 - shadow 1:4.0.14-1
2784 CVE-2006-3377 (Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP ...)
2785 NOT-FOR-US: JMB Software AutoRank PHP
2786 CVE-2006-3376 (Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple ...)
2787 - libwmf 0.2.8.4-2 (bug #381538; medium)
2788 CVE-2006-3375 (PHP remote file inclusion vulnerability in includes/header.inc.php in ...)
2789 NOT-FOR-US: Randshop
2790 CVE-2006-3374 (PHP remote file inclusion vulnerability in index.php in Randshop 1.2 ...)
2791 NOT-FOR-US: Randshop
2792 CVE-2006-3373 (Unspecified vulnerability in the client/bin/logfetch script in Hobbit ...)
2793 NOT-FOR-US: Hobbit
2794 CVE-2006-3372 (Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of ...)
2795 NOT-FOR-US: Apple Safari
2796 CVE-2006-3371 (Eupla Foros 1.0 stores the inc/config.inc file under the web document ...)
2797 NOT-FOR-US: Eupla Foros
2798 CVE-2006-3370 (Blueboy 1.0.3 stores bb_news_config.inc under the web document root ...)
2799 NOT-FOR-US: Blueboy
2800 CVE-2006-3369 (Kamikaze-QSCM 0.1 stores config.inc under the web document root with ...)
2801 NOT-FOR-US: Kamikaze-QSCM
2802 CVE-2006-3368 (Efone 20000723 stores config.inc under the web document root with ...)
2803 NOT-FOR-US: Efone
2804 CVE-2006-3367 (Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web ...)
2805 NOT-FOR-US: Mp3NetBox
2806 CVE-2006-3366 (Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow ...)
2807 NOT-FOR-US: V3 Chat
2808 CVE-2006-3365 (mail/index.php in V3 Chat allows remote attackers to obtain the ...)
2809 NOT-FOR-US: V3 Chat
2810 CVE-2006-3364 (SQL injection vulnerability in index.php in the NP_SEO plugin in ...)
2811 NOT-FOR-US: BLOG:CMS
2812 CVE-2006-3363 (PHP remote file inclusion vulnerability in index.php in the Glossaire ...)
2813 NOT-FOR-US: Glossaire for Xoops
2814 CVE-2006-3362 (connectors/php/connector.php in FCKeditor mcpuk file manager, as used ...)
2815 - knowledgeroot <not-affected> (fixed before first upload; see bug #381912)
2816 CVE-2006-3361 (PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and ...)
2817 NOT-FOR-US: Stud.IP
2818 CVE-2006-3360 (Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 ...)
2819 - phpsysinfo <unfixed> (low)
2820 - egroupware <unfixed> (low)
2821 - phpgroupware <unfixed> (low)
2822 CVE-2006-3359 (Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 ...)
2823 NOT-FOR-US: NewsPHP
2824 CVE-2006-3358 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
2825 NOT-FOR-US: NewsPHP
2826 CVE-2006-3357 (Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) ...)
2827 NOT-FOR-US: HTML Help ActiveX control
2828 CVE-2006-3356 (The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and ...)
2829 NOT-FOR-US: Apple
2830 CVE-2006-3355 (Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll ...)
2831 - mpg123 <unfixed> (bug #377264; medium)
2832 [sarge] - mpg123 <no-dsa> (Non-free not supported)
2833 CVE-2006-3354 (Microsoft Internet Explorer 6 allows remote attackers to cause a ...)
2834 NOT-FOR-US: Microsoft Internet Explorer
2835 CVE-2006-3353 (Opera 9 allows remote attackers to cause a denial of service (crash) ...)
2836 NOT-FOR-US: Opera
2837 CVE-2006-3352 (** DISPUTED ** ...)
2838 NOTE: firefox, but invalid
2839 CVE-2006-3351 (Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and ...)
2840 NOT-FOR-US: Windows Explorer
2841 CVE-2006-3695 (Trac before 0.9.6 does not disable the &quot;raw&quot; or &quot;include&quot; commands ...)
2842 {DSA-1152}
2843 - trac 0.9.6-1 (medium)
2844 [sarge] - trac 0.8.1-3sarge5
2845 CVE-2006-3458 (Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does ...)
2846 {DSA-1113}
2847 - zope2.7 <removed> (bug #377285; medium)
2848 - zope2.8 2.8.7-2 (bug #377277; medium)
2849 - zope2.9 2.9.3-3 (bug #377286; medium)
2850 CVE-2006-3404 (Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c ...)
2851 {DSA-1116}
2852 - gimp 2.2.11-3.1 (bug #377049; medium)
2853 CVE-2006-3350 (Stack-based buffer overflow in AutoVue SolidModel Professional Desktop ...)
2854 NOT-FOR-US: AutoVue SolidModel Professional Desktop
2855 CVE-2006-3349 (Multiple SQL injection vulnerabilities in SmS Script allow remote ...)
2856 NOT-FOR-US: SmS Script
2857 CVE-2006-3348 (Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 ...)
2858 NOT-FOR-US: HSPcomplete
2859 CVE-2006-3347 (SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP ...)
2860 NOT-FOR-US: deV!Lz Clanportal DZCP
2861 CVE-2006-3346 (SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows ...)
2862 NOT-FOR-US: MyNewsGroups
2863 CVE-2006-3345 (Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and ...)
2864 NOT-FOR-US: AliPAGER
2865 CVE-2006-3344 (Siemens Speedstream Wireless Router 2624 allows local users to bypass ...)
2866 NOT-FOR-US: Siemens Speedstream Wireless Router
2867 CVE-2006-3343 (PHP remote file inclusion vulnerability in recipe/cookbook.php in ...)
2868 NOT-FOR-US: CrisoftRicette
2869 CVE-2006-3342 (Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 ...)
2870 NOT-FOR-US: Arctic
2871 CVE-2006-3341 (SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp ...)
2872 NOT-FOR-US: MyAds module for Xoops
2873 CVE-2006-3340 (Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo ...)
2874 NOT-FOR-US: Pearl For Mambo
2875 CVE-2006-3339 (secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-#156 allows ...)
2876 NOT-FOR-US: Atlassian
2877 CVE-2006-3338 (Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 ...)
2878 NOT-FOR-US: Atlassian
2879 CVE-2006-3337 (Cross-site scripting (XSS) vulnerability in ...)
2880 NOT-FOR-US: cPanel (not the Chinese language tool in Debian)
2881 CVE-2006-3336 (TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the ...)
2882 - twiki <unfixed> (low; bug #381907)
2883 NOTE: only in some server configurations
2884 CVE-2006-3335 (Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, ...)
2885 NOT-FOR-US: HP-UX
2886 CVE-2006-3334 (Buffer overflow in the png_decompress_chunk function in pngrutil.c in ...)
2887 - libpng 1.2.8rel-5.2 (bug #377298; unimportant)
2888 NOTE: A static 50 char array consumes 13 machine words on 32bit archs, so the overflow
2889 NOTE: cannot overwrite other memory sections
2890 CVE-2006-3333 (Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum ...)
2891 NOT-FOR-US: Zorum Forum
2892 CVE-2006-3332 (SQL injection vulnerability in index.php in Zorum Forum 3.5 allows ...)
2893 NOT-FOR-US: Zorum Forum
2894 CVE-2006-3331 (Opera before 9.0 does not reset the SSL security bar after displaying ...)
2895 NOT-FOR-US: Opera
2896 CVE-2006-3330 (Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL ...)
2897 NOT-FOR-US: PHP/MySQL Classifieds
2898 CVE-2006-3329 (SQL injection vulnerability in search.php in PHP/MySQL Classifieds ...)
2899 NOT-FOR-US: PHP/MySQL Classifieds
2900 CVE-2006-3328 (new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal ...)
2901 NOT-FOR-US: Hostflow
2902 CVE-2006-3327 (Cross-site scripting (XSS) vulnerability in Custom dating biz dating ...)
2903 NOT-FOR-US: Custom dating biz dating script
2904 CVE-2006-3326 (Directory traversal vulnerability in QuickZip 3.06.3 allows remote ...)
2905 NOT-FOR-US: QuickZip
2906 CVE-2006-3325 (client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus ...)
2907 - quake3 <itp> (bug #337937)
2908 CVE-2006-3324 (The Automatic Downloading option in the id3 Quake 3 Engine and the ...)
2909 - quake3 <itp> (bug #337937)
2910 CVE-2006-3323 (PHP remote file inclusion vulnerability in admin/admin.php in MF ...)
2911 NOT-FOR-US: MF Piadas
2912 CVE-2006-3322 (SQL injection vulnerability in includes/functions_logging.php in ...)
2913 NOT-FOR-US: phpRaid
2914 CVE-2006-3321 (Multiple cross-site scripting (XSS) vulnerabilities in openforum.asp ...)
2915 NOT-FOR-US: OpenForum
2916 CVE-2006-3320 (Cross-site scripting (XSS) vulnerability in command.php in SiteBar ...)
2917 {DSA-1130-1}
2918 - sitebar 3.3.8-1.1 (bug #377299; low)
2919 CVE-2006-3319 (Cross-site scripting (XSS) vulnerability in rss/index.php in PHP ...)
2920 NOT-FOR-US: PHP iCalendar
2921 CVE-2006-3318 (SQL injection vulnerability in register.php for phpRaid 3.0.6 and ...)
2922 NOT-FOR-US: phpRaid
2923 CVE-2006-3317 (PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote ...)
2924 NOT-FOR-US: phpRaid
2925 CVE-2006-3316 (Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.5 ...)
2926 NOT-FOR-US: phpRaid
2927 CVE-2006-3315 (PHP remote file inclusion vulnerability in page.php in an unspecified ...)
2928 NOT-FOR-US: "unspecified RahnemaCo.com product, possibly eShop"
2929 CVE-2006-3314 (PHP remote file inclusion vulnerability in page.php in an unspecified ...)
2930 NOT-FOR-US: "unspecified RahnemaCo.com product, possibly eShop"
2931 CVE-2006-3313 (Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft ...)
2932 NOT-FOR-US: Netsoft smartNet
2933 CVE-2006-3312 (Multiple cross-site scripting (XSS) vulnerabilities in ashmans and ...)
2934 NOT-FOR-US: QaTraq
2935 CVE-2006-3311
2936 RESERVED
2937 CVE-2006-3310
2938 RESERVED
2939 CVE-2006-3309 (SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal ...)
2940 NOT-FOR-US: Scout Portal
2941 CVE-2006-3308 (Unspecified vulnerability in the wpprop code for Project EROS ...)
2942 NOT-FOR-US: bbsengine
2943 CVE-2006-3307 (Multiple SQL injection vulnerabilities in Project EROS bbsengine ...)
2944 NOT-FOR-US: bbsengine
2945 CVE-2006-3306 (Cross-site scripting (XSS) vulnerability in the preparestring funtion ...)
2946 NOT-FOR-US: bbsengine
2947 CVE-2006-3305 (Multiple cross-site scripting (XSS) vulnerabilities in UebiMiau ...)
2948 NOT-FOR-US: UebiMiau
2949 CVE-2006-3304 (SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier ...)
2950 NOT-FOR-US: DeluxeBB
2951 CVE-2006-3303 (Multiple cross-site scripting (XSS) vulnerabilities in pm.php in ...)
2952 NOT-FOR-US: DeluxeBB
2953 CVE-2006-3302 (PHP remote file inclusion vulnerability in mod_cbsms.php in CBSMS ...)
2954 NOT-FOR-US: CBSMS Mambo module
2955 CVE-2006-3301 (Multiple cross-site scripting (XSS) vulnerabilities in phpQLAdmin ...)
2956 - phpqladmin <unfixed> (bug #376442; low)
2957 CVE-2006-3300 (PHP remote file inclusion vulnerability in sms_config/gateway.php in ...)
2958 NOT-FOR-US: phpmysms
2959 CVE-2006-3299 (Cross-site scripting (XSS) vulnerability in index.php in Usenet Script ...)
2960 NOT-FOR-US: Usenet Script
2961 CVE-2006-3298 (Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to ...)
2962 NOT-FOR-US: Offical Yahoo! Messenger client
2963 CVE-2006-3297 (Cross-site scripting (XSS) vulnerability in error.php in UebiMiau ...)
2964 NOT-FOR-US: UebiMiau
2965 CVE-2006-3296 (SQL injection vulnerability in view.php in Open Guestbook 0.5 allows ...)
2966 NOT-FOR-US: Open Guestbook
2967 CVE-2006-3295 (Cross-site scripting (XSS) vulnerability in header.php in Open ...)
2968 NOT-FOR-US: Open Guestbook
2969 CVE-2006-3294 (PHP remote file inclusion vulnerability in mod_cbsms_messages.php in ...)
2970 NOT-FOR-US: CBSMS Mambo module
2971 CVE-2006-3293 (parse_notice (TiCPU) in EnergyMech (emech) before 3.0.2 allows remote ...)
2972 NOT-FOR-US: EnergyMech
2973 CVE-2006-3292 (SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows ...)
2974 NOT-FOR-US: Jaws
2975 CVE-2006-3291 (The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on ...)
2976 NOT-FOR-US: Cisco
2977 CVE-2006-3290 (HTTP server in Cisco Wireless Control System (WCS) for Linux and ...)
2978 NOT-FOR-US: Cisco
2979 CVE-2006-3289 (Cross-site scripting (XSS) vulnerability in the login page of the HTTP ...)
2980 NOT-FOR-US: Cisco
2981 CVE-2006-3288 (Unspecified vulnerability in the TFTP server in Cisco Wireless Control ...)
2982 NOT-FOR-US: Cisco
2983 CVE-2006-3287 (Cisco Wireless Control System (WCS) for Linux and Windows 4.0(1) and ...)
2984 NOT-FOR-US: Cisco
2985 CVE-2006-3286 (The internal database in Cisco Wireless Control System (WCS) for Linux ...)
2986 NOT-FOR-US: Cisco
2987 CVE-2006-3285 (The internal database in Cisco Wireless Control System (WCS) for Linux ...)
2988 NOT-FOR-US: Cisco
2989 CVE-2006-3284 (Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1 ...)
2990 NOT-FOR-US: Dating Agent PRO
2991 CVE-2006-3283 (SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote ...)
2992 NOT-FOR-US: Dating Agent PRO
2993 CVE-2006-3282 (requirements.php in Dating Agent PRO 4.7.1 allows remote attackers to ...)
2994 NOT-FOR-US: Dating Agent PRO
2995 CVE-2006-3281 (Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop ...)
2996 NOT-FOR-US: Microsoft Internet Explorer
2997 CVE-2006-3280 (Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows ...)
2998 NOT-FOR-US: Microsoft Internet Explorer
2999 CVE-2006-3279 (Cross-site scripting (XSS) vulnerability in aeDating 4.1 allows remote ...)
3000 NOT-FOR-US: aeDating
3001 CVE-2006-3278 (Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and ...)
3002 NOT-FOR-US: H-Sphere
3003 CVE-2006-3277 (The SMTP service of MailEnable Standard 1.92 and earlier, Professional ...)
3004 NOT-FOR-US: MailEnable
3005 CVE-2006-3276 (Heap-based buffer overflow in RealNetworks Helix DNA Server 10.0 and ...)
3006 NOT-FOR-US: Helix DNA Server
3007 CVE-2006-3275 (SQL injection vulnerability in profile.php in YaBB SE 1.5.5 and ...)
3008 NOT-FOR-US: YaBB
3009 CVE-2006-3274 (Directory traversal vulnerability in Webmin before 1.280, when run on ...)
3010 - webmin <not-affected> (only windows)
3011 CVE-2006-3273 (Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 ...)
3012 NOT-FOR-US: Some Chess
3013 CVE-2006-3272 (Cross-site request forgery (CSRF) vulnerability in menu.php in Some ...)
3014 NOT-FOR-US: Some Chess
3015 CVE-2006-3271 (Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow ...)
3016 NOT-FOR-US: Softbiz Dating
3017 CVE-2006-3270 (SQL injection vulnerability in cms_admin.php in THoRCMS 1.3.1 allows ...)
3018 NOT-FOR-US: THoRCMS
3019 CVE-2006-3269 (PHP remote file inclusion vulnerability in includes/functions_cms.php ...)
3020 NOT-FOR-US: THoRCMS
3021 CVE-2006-3268 (Unspecified vulnerability in the Windows Client API in Novell ...)
3022 NOT-FOR-US: Novell GroupWise
3023 CVE-2006-3267 (SQL injection vulnerability in index.php in Infinite Core Technologies ...)
3024 NOT-FOR-US: Infinite Core Technologies
3025 CVE-2006-3266 (Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite ...)
3026 NOT-FOR-US: Bee-hive
3027 CVE-2006-3265 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
3028 NOT-FOR-US: Qdig
3029 CVE-2006-3264 (Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo ...)
3030 NOT-FOR-US: Namo DeepSearch
3031 CVE-2006-3263 (SQL injection vulnerability in the Weblinks module (weblinks.php) in ...)
3032 - mambo 4.5.3h-2 (medium)
3033 CVE-2006-3262 (SQL injection vulnerability in the Weblinks module (weblinks.php) in ...)
3034 - mambo 4.5.3h-2 (medium)
3035 CVE-2006-3261 (Cross-site scripting (XSS) vulnerability in Trend Micro Control ...)
3036 NOT-FOR-US: Trend Micro Control Manager
3037 CVE-2006-3260 (Cross-site scripting (XSS) vulnerability in index.php in vlbook 1.02 ...)
3038 NOT-FOR-US: vlbook
3039 CVE-2006-3259 (Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 ...)
3040 NOT-FOR-US: e107
3041 CVE-2006-3258 (Multiple cross-site scripting (XSS) vulnerabilities in index.html in ...)
3042 NOT-FOR-US: BNBT TrinEdit and EasyTracker
3043 CVE-2006-3257 (Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.7.7 ...)
3044 NOT-FOR-US: Claroline
3045 CVE-2006-3256 (SQL injection vulnerability in report.php in Woltlab Burning Board ...)
3046 NOT-FOR-US: Woltlab Burning Board
3047 CVE-2006-3255 (SQL injection vulnerability in showmods.php in Woltlab Burning Board ...)
3048 NOT-FOR-US: Woltlab Burning Board
3049 CVE-2006-3254 (SQL injection vulnerability in newthread.php in Woltlab Burning Board ...)
3050 NOT-FOR-US: Woltlab Burning Board
3051 CVE-2006-3253 (** DISPUTED ** ...)
3052 NOT-FOR-US: vBulletin
3053 CVE-2006-3252 (Buffer overflow in the Online Registration Facility for Algorithmic ...)
3054 NOT-FOR-US: Algorithmic Research PrivateWire VPN
3055 CVE-2006-3251 (Heap-based buffer overflow in the array_push function in hashcash.c ...)
3056 {DSA-1114}
3057 - hashcash 1.21
3058 CVE-2006-3250 (Heap-based buffer overflow in Windows Live Messenger 8.0 allows ...)
3059 NOT-FOR-US: Windows Live Messenger
3060 CVE-2006-3249 (** DISPUTED ** ...)
3061 NOT-FOR-US: Phorum
3062 CVE-2006-3248 (SQL injection vulnerability in calendar.php in Codewalkers PHP Event ...)
3063 NOT-FOR-US: PHP Event Calendar
3064 CVE-2006-3247 (Multiple cross-site scripting (XSS) vulnerabilities in show.php in ...)
3065 NOT-FOR-US: GL-SH Deaf Forum
3066 CVE-2006-3246 (Cross-site scripting (XSS) vulnerability in show.php in GL-SH Deaf ...)
3067 NOT-FOR-US: GL-SH Deaf Forum
3068 CVE-2006-3245 (Multiple cross-site scripting (XSS) vulnerabilities in activatemember ...)
3069 NOT-FOR-US: mvnForum
3070 CVE-2006-3244 (Multiple SQL injection vulnerabilities in Anthill 0.2.6 and earlier ...)
3071 NOT-FOR-US: Anthill
3072 CVE-2006-3243 (SQL injection vulnerability in usercp.php in MyBB (MyBulletinBoard) ...)
3073 NOT-FOR-US: MyBB
3074 CVE-2006-3242 (Stack-based buffer overflow in the browse_get_namespace function in ...)
3075 {DSA-1108}
3076 - mutt 1.5.11+cvs20060403-2 (low; bug #375828)
3077 CVE-2006-3241 (Cross-site scripting (XSS) vulnerability in messages.php in XennoBB ...)
3078 NOT-FOR-US: XennoBB
3079 CVE-2006-3240 (Cross-site scripting (XSS) vulnerability in classes/ui.class.php in ...)
3080 NOT-FOR-US: dotProject
3081 CVE-2006-3239 (SQL injection vulnerability in message.php in VBZooM 1.11 and earlier ...)
3082 NOT-FOR-US: VBZooM
3083 CVE-2006-3238 (Multiple SQL injection vulnerabilities in VBZooM 1.00 and earlier ...)
3084 NOT-FOR-US: VBZooM
3085 CVE-2006-3237 (Cross-site scripting (XSS) vulnerability in index.php in Enterprise ...)
3086 NOT-FOR-US: Enterprise Groupware System
3087 CVE-2006-3236 (Multiple SQL injection vulnerabilities in thinkWMS 1.0 and earlier ...)
3088 NOT-FOR-US: thinkWMS
3089 CVE-2006-3235 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
3090 NOT-FOR-US: FineShop
3091 CVE-2006-3234 (Multiple SQL injection vulnerabilities in index.php in FineShop 3.0 ...)
3092 NOT-FOR-US: FineShop
3093 CVE-2006-3233 (Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in ...)
3094 NOT-FOR-US: OpenWebMail
3095 CVE-2006-3232 (Unspecified vulnerability in IBM WebSphere Application Server before ...)
3096 NOT-FOR-US: IBM WebSphere
3097 CVE-2006-3231 (Unspecified vulnerability in IBM WebSphere Application Server before ...)
3098 NOT-FOR-US: IBM WebSphere
3099 CVE-2006-3230 (Cross-site scripting (XSS) vulnerability in index.tmpl in Azureus ...)
3100 NOT-FOR-US: Azureus plugin that isn't distributed by default
3101 CVE-2006-3229 (Cross-site scripting (XSS) vulnerability in OpenWebMail (OWM) 2.52, ...)
3102 NOT-FOR-US: OpenWebMail
3103 CVE-2006-3228 (Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including ...)
3104 NOT-FOR-US: WinAmp
3105 CVE-2006-3227 (Interpretation conflict between Internet Explorer and other web ...)
3106 NOT-FOR-US: Internet Explorer
3107 CVE-2006-3226 (Cisco Secure Access Control Server (ACS) 4.x for Windows uses the ...)
3108 NOT-FOR-US: Cisco Secure Access Control Server
3109 CVE-2006-3225 (Cross-site scripting (XSS) vulnerability in Sun ONE Application Server ...)
3110 NOT-FOR-US: Sun ONE Application Server
3111 CVE-2006-3224 (Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote ...)
3112 NOT-FOR-US: Apple Safari
3113 CVE-2006-3223 (Format string vulnerability in CA Integrated Threat Management (ITM), ...)
3114 NOT-FOR-US: CA Integrated Threat Management (ITM), eTrust Antivirus (eAV), and eTrust PestPatrol (ePP)
3115 CVE-2006-3222 (The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 ...)
3116 NOT-FOR-US: Fortinet FortiOS
3117 CVE-2006-3221 (SQL injection vulnerability in index.php in DataLife Engine 4.1 and ...)
3118 NOT-FOR-US: DataLife
3119 CVE-2006-3220 (SQL injection vulnerability in studienplatztausch.php in Woltlab ...)
3120 NOT-FOR-US: Woltlab Burning Board
3121 CVE-2006-3219 (SQL injection vulnerability in thread.php in Woltlab Burning Board ...)
3122 NOT-FOR-US: Woltlab Burning Board
3123 CVE-2006-3218 (SQL injection vulnerability in profile.php in Woltlab Burning Board ...)
3124 NOT-FOR-US: Woltlab Burning Board
3125 CVE-2006-3217 (JaguarEditControl (JEdit) ActiveX Control 1.1.0.20 and earlier allows ...)
3126 NOT-FOR-US: JaguarEditControl
3127 CVE-2006-3216 (Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for ...)
3128 NOT-FOR-US: MAILsweeper
3129 CVE-2006-3215 (Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for ...)
3130 NOT-FOR-US: MAILsweeper
3131 CVE-2006-3214 (Unspecified vulnerability in Hitachi Groupmax Address Server 7 and ...)
3132 NOT-FOR-US: Hitachi Groupmax
3133 CVE-2006-3213 (SQL injection vulnerability in WeBBoA Hosting 1.1 allows remote ...)
3134 NOT-FOR-US: WeBBoA Hosting
3135 CVE-2006-3212 (Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook ...)
3136 NOT-FOR-US: cjGuestbook
3137 CVE-2006-3211 (Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook ...)
3138 NOT-FOR-US: cjGuestbook
3139 CVE-2006-3210 (Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when ...)
3140 NOT-FOR-US: Ralf Image Gallery
3141 CVE-2006-3209 (** DISPUTED ** The Task scheduler (at.exe) on Microsoft Windows XP ...)
3142 NOT-FOR-US: Microsoft Windows
3143 CVE-2006-3208 (Direct static code injection vulnerability in Ultimate PHP Board (UPB) ...)
3144 NOT-FOR-US: Ultimate PHP Board
3145 CVE-2006-3207 (Directory traversal vulnerability in newpost.php in Ultimate PHP Board ...)
3146 NOT-FOR-US: Ultimate PHP Board
3147 CVE-2006-3206 (register.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows ...)
3148 NOT-FOR-US: Ultimate PHP Board
3149 CVE-2006-3205 (Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to ...)
3150 NOT-FOR-US: Ultimate PHP Board
3151 CVE-2006-3204 (Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically ...)
3152 NOT-FOR-US: Ultimate PHP Board
3153 CVE-2006-3203 (The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier ...)
3154 NOT-FOR-US: Ultimate PHP Board
3155 CVE-2006-3202 (The ip6_savecontrol function in NetBSD 2.0 through 3.0, under certain ...)
3156 NOT-FOR-US: NetBSD's KAME stack
3157 CVE-2006-3201 (Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and ...)
3158 NOT-FOR-US: HP-UX
3159 CVE-2006-3200 (Unspecified versions of Internet Explorer allow remote attackers to ...)
3160 NOT-FOR-US: Internet Explorer
3161 CVE-2006-3199 (Opera 9 allows remote attackers to cause a denial of service (crash) ...)
3162 NOT-FOR-US: Opera
3163 CVE-2006-3198 (Integer overflow in Opera 8.54 and earlier allows remote attackers to ...)
3164 NOT-FOR-US: Opera
3165 CVE-2006-3197 (Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) ...)
3166 NOT-FOR-US: Invision Power Board
3167 CVE-2006-3196 (index.php in singapore 0.10.0 and earlier allows remote attackers to ...)
3168 NOT-FOR-US: singapore
3169 CVE-2006-3195 (Cross-site scripting (XSS) vulnerability in index.php in singapore ...)
3170 NOT-FOR-US: singapore
3171 CVE-2006-3194 (Directory traversal vulnerability in index.php in singapore 0.10.0 and ...)
3172 NOT-FOR-US: singapore
3173 CVE-2006-3193 (Multiple PHP remote file inclusion vulnerabilities in Grayscale ...)
3174 NOT-FOR-US: BandSite
3175 CVE-2006-3192 (PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows ...)
3176 NOT-FOR-US: Ad Manager
3177 CVE-2006-3191 (Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 ...)
3178 NOT-FOR-US: MPCS
3179 CVE-2006-3190 (SQL injection vulnerability in administration/includes/login/auth.php ...)
3180 NOT-FOR-US: HotPlug CMS
3181 CVE-2006-3189 (Cross-site scripting (XSS) vulnerability in ...)
3182 NOT-FOR-US: HotPlug CMS
3183 CVE-2006-3188 (Multiple SQL injection vulnerabilities in Sharky e-shop 3.05 and ...)
3184 NOT-FOR-US: Sharky e-shop
3185 CVE-2006-3187 (Multiple cross-site scripting (XSS) vulnerabilities in Sharky e-shop ...)
3186 NOT-FOR-US: Sharky e-shop
3187 CVE-2006-3186 (Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon ...)
3188 NOT-FOR-US: CMS Faethon
3189 CVE-2006-3185 (PHP remote file inclusion vulnerability in data/header.php in CMS ...)
3190 NOT-FOR-US: CMS Faethon
3191 CVE-2006-3184 (Direct static code injection vulnerability in ASP Stats Generator ...)
3192 NOT-FOR-US: ASP Stats Generator
3193 CVE-2006-3183 (Cross-site scripting (XSS) vulnerability in index.php in MobeScripts ...)
3194 NOT-FOR-US: Mobile Space Community
3195 CVE-2006-3182 (Directory traversal vulnerability in index.php in MobeScripts Mobile ...)
3196 NOT-FOR-US: Mobile Space Community
3197 CVE-2006-3181 (SQL injection vulnerability in index.php in MobeScripts Mobile Space ...)
3198 NOT-FOR-US: Mobile Space Community
3199 CVE-2006-3180 (Cross-site scripting (XSS) vulnerability in ftp_index.php in Confixx ...)
3200 NOT-FOR-US: Confixx Pro
3201 CVE-2006-3179 (Cross-site scripting (XSS) vulnerability in tools_ftp_pwaendern.php in ...)
3202 NOT-FOR-US: Confixx Pro
3203 CVE-2006-3178 (Directory traversal vulnerability in extract_chmLib example program in ...)
3204 {DSA-1144-1}
3205 - chmlib 0.38-1 (bug #374085; low)
3206 CVE-2006-3177 (PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The ...)
3207 NOT-FOR-US: The Bible Portal Project
3208 CVE-2006-3176 (SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 ...)
3209 NOT-FOR-US: xarancms
3210 CVE-2006-3175 (Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 ...)
3211 NOT-FOR-US: mcGuestbook
3212 CVE-2006-3174 (Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail ...)
3213 - squirrelmail 2:1.4.7-1 (bug #375782; low)
3214 [sarge] - squirrelmail <no-dsa> (Operation with registers_globals not supported)
3215 CVE-2006-3173 (Multiple PHP remote file inclusion vulnerabilities in Content*Builder ...)
3216 NOT-FOR-US: Content*Builder
3217 CVE-2006-3172 (Multiple PHP remote file inclusion vulnerabilities in Content*Builder ...)
3218 NOT-FOR-US: Content*Builder
3219 CVE-2006-3171 (CRLF injection vulnerability in CS-Forum before 0.82 allows remote ...)
3220 NOT-FOR-US: CS-Forum
3221 CVE-2006-3170 (CS-Forum before 0.82 allows remote attackers to obtain sensitive ...)
3222 NOT-FOR-US: CS-Forum
3223 CVE-2006-3169 (Multiple cross-site scripting (XSS) vulnerabilities in CS-Forum 0.81 ...)
3224 NOT-FOR-US: CS-Forum
3225 CVE-2006-3168 (SQL injection vulnerability in CS-Forum before 0.82 allows remote ...)
3226 NOT-FOR-US: CS-Forum
3227 CVE-2006-3167 (Free Realty before 2.9 allows remote attackers to obtain the full path ...)
3228 NOT-FOR-US: Free Realty
3229 CVE-2006-3166 (Cross-site scripting (XSS) vulnerability in propview.php in Free ...)
3230 NOT-FOR-US: Free Realty
3231 CVE-2006-3165 (SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and ...)
3232 NOT-FOR-US: Free Realty
3233 CVE-2006-3164 (SQL injection vulnerability in category.php in TPL Design tplShop 2.0 ...)
3234 NOT-FOR-US: tplShop
3235 CVE-2006-3163 (Multiple SQL injection vulnerabilities in galeria.php in IMGallery 2.4 ...)
3236 NOT-FOR-US: IMGallery
3237 CVE-2006-3162 (PHP remote file inclusion vulnerability in include/inc_foot.php in ...)
3238 NOT-FOR-US: SmartSiteCMS
3239 CVE-2006-3161 (SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier ...)
3240 NOT-FOR-US: SaphpLesson
3241 CVE-2006-3160 (Cross-site scripting (XSS) vulnerability in fm.php in ONEdotOH Simple ...)
3242 NOT-FOR-US: Simple File Manager
3243 CVE-2006-3159 (pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built ...)
3244 NOT-FOR-US: Sun ONE/iPlanet Messaging Server
3245 CVE-2006-3158 (index.php in Eduha Meeting does not properly restrict file extensions ...)
3246 NOT-FOR-US: Eduha Meeting
3247 CVE-2006-3157 (Cross-site scripting (XSS) vulnerability in index.php in Thinkfactory ...)
3248 NOT-FOR-US: UltimateGoogle
3249 CVE-2006-3156 (Cross-site scripting (XSS) vulnerability in index.cgi in Ultimate ...)
3250 NOT-FOR-US: Ultimate eShop
3251 CVE-2006-3155 (Multiple cross-site scripting (XSS) vulnerabilities in Ultimate ...)
3252 NOT-FOR-US: Ultimate Auction
3253 CVE-2006-3154 (SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and ...)
3254 NOT-FOR-US: Ultimate Estate
3255 CVE-2006-3153 (Cross-site scripting (XSS) vulnerability in index.pl in Ultimate ...)
3256 NOT-FOR-US: Ultimate Estate
3257 CVE-2006-3152 (Multiple SQL injection vulnerabilities in phpTRADER 4.9 SP5 and ...)
3258 NOT-FOR-US: phpTRADER
3259 CVE-2006-3151 (Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD ...)
3260 NOT-FOR-US: AssoCIateD
3261 CVE-2006-3150 (SQL injection vulnerability in index.php in CavoxCms 1.0.16 and ...)
3262 NOT-FOR-US: CavoxCms
3263 CVE-2006-3149 (Cross-site scripting (XSS) vulnerability in topic.php in phpMyForum ...)
3264 NOT-FOR-US: phpMyForum
3265 CVE-2006-3148 (SQL injection vulnerability, possibly in search.inc.php, in ...)
3266 NOT-FOR-US: Open-Realty
3267 CVE-2006-3147 (Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix ...)
3268 NOT-FOR-US: Hosting Controller
3269 CVE-2006-3146 (The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.23 and earlier ...)
3270 NOT-FOR-US: Toshiba drivers for Windows
3271 CVE-2006-3145 (Buffer overflow in pamtofits of NetPBM 10.30 through 10.33 allows ...)
3272 - netpbm-free <not-affected> (Debian's version is too old; affects 10.30 to 10.33 only)
3273 CVE-2006-3144 (PHP remote file inclusion vulnerability in microcms-include.php in IBD ...)
3274 NOT-FOR-US: IBD Micro CMS
3275 CVE-2006-3143 (Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus ...)
3276 NOT-FOR-US: Maximus SchoolMAX
3277 CVE-2006-3142 (SQL injection vulnerability in Forum.php in VBZooM 1.11 allows remote ...)
3278 NOT-FOR-US: VBZooM
3279 CVE-2006-3141 (Cross-site scripting (XSS) vulnerability in details.cfm in Tradingeye ...)
3280 NOT-FOR-US: Tradingeye Shop
3281 CVE-2006-3140 (SQL injection vulnerability in index.php in openCI 1.0 BETA 0.20.1 and ...)
3282 NOT-FOR-US: openCI
3283 CVE-2006-3139 (Multiple SQL injection vulnerabilities in war.php in Virtual War 1.5.0 ...)
3284 NOT-FOR-US: Virtual War
3285 CVE-2006-3138 (Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory ...)
3286 NOT-FOR-US: phpMyDirectory
3287 CVE-2006-3137 (Cross-site scripting (XSS) vulnerability in productDetail.asp in Edge ...)
3288 NOT-FOR-US: Edge eCommerce Shop
3289 CVE-2006-3136 (** DISPUTED ** ...)
3290 NOT-FOR-US: Nucleus
3291 CVE-2006-3135 (Multiple SQL injection vulnerabilities in CMS Mundo 1.0 build 008, and ...)
3292 NOT-FOR-US: CMS Mundo
3293 CVE-2006-3134 (Buffer overflow in GraceNote CDDBControl ActiveX Control, as used by ...)
3294 NOT-FOR-US: GraceNote ActiveX Control
3295 CVE-2006-3133
3296 RESERVED
3297 CVE-2006-3132 (Cross-site scripting (XSS) vulnerability in qtofm.php4 in ...)
3298 NOT-FOR-US: QTOFileManager
3299 CVE-2006-3131 (Multiple cross-site scripting (XSS) vulnerabilities in Clubpage allow ...)
3300 NOT-FOR-US: Clubpage
3301 CVE-2006-3130 (SQL injection vulnerability in index.php in Clubpage allows remote ...)
3302 NOT-FOR-US: Clubpage
3303 CVE-2006-3129 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC ...)
3304 NOT-FOR-US: LinkList
3305 CVE-2006-3128 (choose_file.php in easy-CMS 0.1.2, when mod_mime is installed, does ...)
3306 NOT-FOR-US: easy-CMS
3307 CVE-2006-3127 (Memory leak in Network Security Services (NSS) 3.11, as used in Sun ...)
3308 - mozilla <not-affected> (SunSolve claims it is only in 3.11; latest released is 3.10)
3309 CVE-2006-3126 (c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute ...)
3310 {DSA-1165}
3311 - capi4hylafax 1:01.03.00.99.svn.300-3
3312 CVE-2006-3125 (Array index error in tetrinet.c in gtetrinet 0.7.8 and earlier allows ...)
3313 {DSA-1163}
3314 - getrinet 0.7.10-1
3315 CVE-2006-3124 (Buffer overflow in the HTTP header parsing in Streamripper before ...)
3316 {DSA-1158}
3317 - streamripper 1.61.25-2
3318 CVE-2006-3123 (Multiple integer overflows in the (1) dodecrypt and (2) doencrypt ...)
3319 {DSA-1138-1}
3320 - cfs 1.4.1-17
3321 CVE-2006-3122 (The supersede_lease function in memory.c in ISC DHCP (dhcpd) server ...)
3322 {DSA-1143-1}
3323 CVE-2006-3121 (The peel_netstring function in cl_netstring.c in the heartbeat ...)
3324 {DSA-1151-1}
3325 - heartbeat-2 2.0.6-2
3326 - heartbeat 1.2.4-14
3327 CVE-2006-3120 (Format string vulnerability in Brian Wotring Osiris before 4.2.1 ...)
3328 {DSA-1129}
3329 - osiris 4.2.0-2 (medium)
3330 CVE-2006-3119 (The fbgs framebuffer Postscript/PDF viewer in fbi before 2.01 has a ...)
3331 {DSA-1124}
3332 - fbi 2.05-1
3333 CVE-2006-3118 (spread uses a temporary file with a static filename based on the port ...)
3334 - spread <unfixed> (bug #375617; low)
3335 [sarge] - spread <no-dsa> (Minimal security implications)
3336 CVE-2006-3117 (Heap-based buffer overflow in OpenOffice.org (aka StarOffice) 1.1.x up ...)
3337 {DSA-1104}
3338 - openoffice.org 2.0.3-1
3339 CVE-2006-3116 (Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.4 ...)
3340 NOT-FOR-US: phpRaid
3341 CVE-2006-3115 (SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly ...)
3342 NOT-FOR-US: phpRaid
3343 CVE-2006-3114 (PC Tools AntiVirus 2.1.0.51 uses insecure default permissions on the ...)
3344 NOT-FOR-US: PC Tools AntiVirus
3345 CVE-2006-3113 (Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and ...)
3346 NOTE: MFSA-2006-46
3347 - mozilla <not-affected> (mozilla 1.7 not affected)
3348 - xulrunner 1.8.0.5-1 (high)
3349 - mozilla-firefox <not-affected> (only firefox >= 1.5)
3350 - firefox 1.5.dfsg+1.5.0.5-1 (high)
3351 - thunderbird 1.5.0.5-1 (medium)
3352 - mozilla-thunderbird <not-affected>
3353 CVE-2006-3112 (Chipmailer 1.09 allows remote attackers to obtain sensitive ...)
3354 NOT-FOR-US: Chipmailer
3355 CVE-2006-3111 (Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 ...)
3356 NOT-FOR-US: Chipmailer
3357 CVE-2006-3110 (Cross-site scripting (XSS) vulnerability in main.php in Chipmailer ...)
3358 NOT-FOR-US: Chipmailer
3359 CVE-2006-3109 (Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 ...)
3360 NOT-FOR-US: Cisco CallManager
3361 CVE-2006-3108 (Cross-site scripting (XSS) vulnerability in EmailArchitect Email ...)
3362 NOT-FOR-US: EmailArchitect
3363 CVE-2006-3107 (Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and ...)
3364 NOT-FOR-US: Docebo
3365 CVE-2006-3106 (Cross-site scripting (XSS) vulnerability in index.php in ...)
3366 NOT-FOR-US: phpMyDesktop
3367 CVE-2006-3105 (CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers ...)
3368 NOT-FOR-US: Bitweaver
3369 CVE-2006-3104 (users/index.php in Bitweaver 1.3 allows remote attackers to obtain ...)
3370 NOT-FOR-US: Bitweaver
3371 CVE-2006-3103 (Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows ...)
3372 NOT-FOR-US: Bitweaver
3373 CVE-2006-3102 (Race condition in articles/BitArticle.php in Bitweaver 1.3, when run ...)
3374 NOT-FOR-US: Bitweaver
3375 CVE-2006-3101 (Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco ...)
3376 NOT-FOR-US: Cisco Secure ACS
3377 CVE-2006-3099
3378 RESERVED
3379 CVE-2006-3098
3380 RESERVED
3381 CVE-2006-3097 (Unspecified vulnerability in Support Tools Manager (xstm, cstm, and ...)
3382 NOT-FOR-US: HP-UX Support Tools Manager
3383 CVE-2006-3096 (Multiple SQL injection vulnerabilities in iPostMX 2005 2.0 and earlier ...)
3384 NOT-FOR-US: iPostMX
3385 CVE-2006-3095 (Multiple cross-site scripting (XSS) vulnerabilities in iPostMX 2005 ...)
3386 NOT-FOR-US: iPostMX
3387 CVE-2006-3094 (Multiple SQL injection vulnerabilities in Calendarix Basic ...)
3388 NOT-FOR-US: Calendarix Basic
3389 CVE-2006-3093 (Multiple unspecified vulnerabilities in Adobe Acrobat Reader ...)
3390 NOT-FOR-US: Adobe Reader
3391 CVE-2006-3092 (PhpMyFactures 1.2 and earlier allows remote attackers to bypass ...)
3392 NOT-FOR-US: PhpMyFactures
3393 CVE-2006-3091 (PhpMyFactures 1.0, and possibly 1.2 and earlier, allows remote ...)
3394 NOT-FOR-US: PhpMyFactures
3395 CVE-2006-3090 (Multiple SQL injection vulnerabilities in PhpMyFactures 1.0, and ...)
3396 NOT-FOR-US: PhpMyFactures
3397 CVE-2006-3089 (Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFactures ...)
3398 NOT-FOR-US: PhpMyFactures
3399 CVE-2006-3088 (Cross-site scripting (XSS) vulnerability in index.php in Car ...)
3400 NOT-FOR-US: Car Classifieds
3401 CVE-2006-3087 (Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 ...)
3402 NOT-FOR-US: EZGallery
3403 CVE-2006-3086 (Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName ...)
3404 NOT-FOR-US: Microsoft
3405 CVE-2006-3084 (The (1) ftpd and (2) ksu programs in MIT Kerberos 5 (krb5) up to 1.5, ...)
3406 {DSA-1146-1}
3407 - krb5 1.4.3-9 (medium)
3408 CVE-2006-3083 (The (1) krshd and (2) v4rcp applications in MIT Kerberos 5 (krb5) up ...)
3409 {DSA-1146-1}
3410 - krb5 1.4.3-9 (medium)
3411 CVE-2006-3082 (parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, ...)
3412 {DSA-1115 DSA-1107}
3413 - gnupg 1.4.3-2 (bug #375052; low)
3414 - gnupg2 1.9.20-1.1 (bug #375053; low)
3415 CVE-2006-3081 (mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x ...)
3416 {DSA-1112}
3417 - mysql-server-5.0 5.0.19-1 (bug #373913; high)
3418 CVE-2006-3100 [termnetd buffer overflow]
3419 RESERVED
3420 - termnetd 3.3-7 (bug #358028; medium)
3421 CVE-2006-3085 (xt_sctp in netfilter for Linux kernel before 2.6.17.1 allows attackers ...)
3422 - linux-2.6 2.6.16-15
3423 CVE-2006-XXXX [webalizer-stonesteps XSS]
3424 - webalizer-stonesteps 2.4.1.2-1
3425 CVE-2006-3080 (Cross-site scripting (XSS) vulnerability in viewposts.cfm in ...)
3426 NOT-FOR-US: aXentForum
3427 CVE-2006-3079 (Cross-site scripting (XSS) vulnerability in index.cfm in SSPwiz Plus ...)
3428 NOT-FOR-US: SSPwiz Plus
3429 CVE-2006-3078 (Multiple SQL injection vulnerabilities in APBoard 2.2-r3 and earlier ...)
3430 NOT-FOR-US: APBoard
3431 CVE-2006-3077 (Cross-site scripting (XSS) vulnerability in guestbook.cfm in ...)
3432 NOT-FOR-US: aXentGuestbook
3433 CVE-2006-3076 (PHP remote file inclusion vulnerability in ...)
3434 NOT-FOR-US: PhpBlueDragon
3435 CVE-2006-3075 (Multiple PHP remote file inclusion vulnerabilities in PictureDis ...)
3436 NOT-FOR-US: PictureDis Professional
3437 CVE-2006-3074 (klif.sys in Kaspersky Anti-Virus 6.0.0.300 and earlier, Internet ...)
3438 NOT-FOR-US: Several Kaspersky products
3439 CVE-2006-3073 (Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN ...)
3440 NOT-FOR-US: Cisco VPN products
3441 CVE-2006-3072 (M4 Macro Library in Symantec Security Information Manager before ...)
3442 NOT-FOR-US: Symantec Security Information Manager
3443 CVE-2006-3071 (Cross-site scripting (XSS) vulnerability in index.php in MP3 ...)
3444 NOT-FOR-US: MP3 Search/Archive
3445 CVE-2006-3070 (write_ok.php in Zeroboard 4.1 pl8, when installed on Apache with ...)
3446 NOT-FOR-US: Zeroboard
3447 CVE-2006-3069 (PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when ...)
3448 NOT-FOR-US: DoubleSpeak
3449 CVE-2006-3068 (IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote ...)
3450 NOT-FOR-US: IBM DB2
3451 CVE-2006-3067 (Multiple unspecified vulnerabilities in IBM DB2 Universal Database ...)
3452 NOT-FOR-US: IBM DB2
3453 CVE-2006-3066 (Buffer overflow in the TCP/IP listener in IBM DB2 Universal Database ...)
3454 NOT-FOR-US: IBM DB2
3455 CVE-2006-3065 (SQL injection vulnerability in engine/shards/blog.php in blur6ex ...)
3456 NOT-FOR-US: blur6ex
3457 CVE-2006-3064 (SQL injection vulnerability in include/function.inc.php in Coppermine ...)
3458 NOT-FOR-US: Coppermine Photo Gallery
3459 CVE-2006-3063 (Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook ...)
3460 NOT-FOR-US: myPHP Guestbook
3461 CVE-2006-3062 (Cross-site scripting (XSS) vulnerability in index.php in myPHP ...)
3462 NOT-FOR-US: myPHP Guestbook
3463 CVE-2006-3061 (Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review ...)
3464 NOT-FOR-US: 5 Star Review
3465 CVE-2006-3060 (Cross-site scripting (XSS) vulnerability in P.A.I.D 2.2 allows remote ...)
3466 NOT-FOR-US: P.A.I.D
3467 CVE-2006-3059 (Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows ...)
3468 NOT-FOR-US: Microsoft Excel
3469 CVE-2006-3058
3470 RESERVED
3471 CVE-2006-3057 (Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) ...)
3472 - dhcdbd 1.14-1
3473 CVE-2006-3056 (SQL injection vulnerability in language.php in VBZooM 1.01 allows ...)
3474 NOT-FOR-US: VBZooM
3475 CVE-2006-3055 (Multiple SQL injection vulnerabilities in VBZooM 1.02 allow remote ...)
3476 NOT-FOR-US: VBZooM
3477 CVE-2006-3054 (Multiple SQL injection vulnerabilities in VBZooM 1.11 allow remote ...)
3478 NOT-FOR-US: VBZooM
3479 CVE-2006-3053 (** DISPUTED ** ...)
3480 NOT-FOR-US: PHORUM
3481 CVE-2006-3052 (Cross-site scripting (XSS) vulnerability in Event Registration allows ...)
3482 NOT-FOR-US: Event Registration
3483 CVE-2006-3051 (Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, ...)
3484 NOT-FOR-US: SixCMS
3485 CVE-2006-3050 (Directory traversal vulnerability in detail.php in SixCMS 6.0, and ...)
3486 NOT-FOR-US: SixCMS
3487 CVE-2006-3049 (Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in ...)
3488 NOT-FOR-US: Mole Group Ticket Booking Script
3489 CVE-2006-3048 (SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier ...)
3490 - tikiwiki 1.9.4-1 (medium)
3491 CVE-2006-3047 (Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and ...)
3492 - tikiwiki 1.9.4-1 (medium)
3493 CVE-2006-3046 (Unspecified vulnerability in the admin login feature in Subtext 1.5, ...)
3494 NOT-FOR-US: Subtext
3495 CVE-2006-3045 (PHP remote file inclusion vulnerability in manage_songs.php in Foing ...)
3496 NOT-FOR-US: Foing
3497 CVE-2006-3044 (Cross-site scripting (XSS) vulnerability in LogiSphere 1.6.0 allows ...)
3498 NOT-FOR-US: LogiSphere
3499 CVE-2006-3043 (Cross-site scripting (XSS) vulnerability in search.cfm in CreaFrameXe ...)
3500 NOT-FOR-US: CFXe-CMS
3501 CVE-2006-3042 (** DISPUTED ** ...)
3502 NOT-FOR-US: ISPConfig
3503 CVE-2006-3041 (** DISPUTED ** ...)
3504 NOT-FOR-US: Codewalkers Ltwcalendar
3505 CVE-2006-3040 (** DISPUTED ** ...)
3506 NOT-FOR-US: Amr Talkbox
3507 CVE-2006-3039 (Cross-site scripting (XSS) vulnerability in index.php in Cescripts ...)
3508 NOT-FOR-US: Cescripts Realty Home Rent
3509 CVE-2006-3038 (Cross-site scripting (XSS) vulnerability in index.php in Cescripts ...)
3510 NOT-FOR-US: Cescripts Realty Home Rent
3511 CVE-2006-3037 (Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ...)
3512 NOT-FOR-US: ST AdManager Lite
3513 CVE-2006-3036 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
3514 NOT-FOR-US: 35mmslidegallery
3515 CVE-2006-3035 (Multiple cross-site scripting (XSS) vulnerabilities in addwords.php in ...)
3516 NOT-FOR-US: MyScrapbook
3517 CVE-2006-3034 (MyScrapbook 3.1 allows remote attackers to obtain sensitive ...)
3518 NOT-FOR-US: MyScrapbook
3519 CVE-2006-3033 (Cross-site scripting (XSS) vulnerability in MyScrapbook 3.1 allows ...)
3520 NOT-FOR-US: MyScrapbook
3521 CVE-2006-3032 (Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP ...)
3522 NOT-FOR-US: Xtreme ASP Photo Gallery
3523 CVE-2006-3031 (Multiple cross-site scripting (XSS) vulnerabilities in index.asp in ...)
3524 NOT-FOR-US: fipsCMS
3525 CVE-2006-3030 (Multiple cross-site scripting (XSS) vulnerabilities in DwZone Shopping ...)
3526 NOT-FOR-US: DwZone Shopping Cart
3527 CVE-2006-3029 (Cross-site scripting (XSS) vulnerability in default.asp in ClickTech ...)
3528 NOT-FOR-US: ClickTech Clickcart
3529 CVE-2006-3028 (PHP remote file inclusion vulnerability in ...)
3530 NOT-FOR-US: Minerva
3531 CVE-2006-3027 (Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and ...)
3532 NOT-FOR-US: Enthrallwebe ePhotos
3533 CVE-2006-3026 (Multiple cross-site scripting (XSS) vulnerabilities in ClickGallery ...)
3534 NOT-FOR-US: ClickGallery
3535 CVE-2006-3025 (Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea ...)
3536 NOT-FOR-US: Chris Lea Lucid Calendar
3537 CVE-2006-3024 (Multiple cross-site scripting (XSS) vulnerabilities in EvGenius ...)
3538 NOT-FOR-US: EvGenius Counter
3539 CVE-2006-3023 (Multiple cross-site scripting (XSS) vulnerabilities in thumbnails.asp ...)
3540 NOT-FOR-US: Uapplication Uphotogallery
3541 CVE-2006-3022 (Cross-site scripting (XSS) vulnerability in zoom.php in fipsGallery ...)
3542 NOT-FOR-US: fipsGallery
3543 CVE-2006-3021 (Multiple cross-site scripting (XSS) vulnerabilities in BlueCollar ...)
3544 NOT-FOR-US: BlueCollar i-Gallery
3545 CVE-2006-3020 (Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp ...)
3546 NOT-FOR-US: WS-Album
3547 CVE-2006-3019 (Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 ...)
3548 NOT-FOR-US: phpCMS
3549 CVE-2006-3018 (Unspecified vulnerability in the session extension functionality in ...)
3550 - php5 5.1.4-0.1 (medium)
3551 - php4 <unfixed> (medium)
3552 CVE-2006-3017 (zend_hash_del_key_or_index in zend_hash.c in PHP before 4.4.3 and 5.x ...)
3553 - php5 5.1.4-0.1 (medium)
3554 - php4 4:4.4.4-1 (medium; bug #381998)
3555 CVE-2006-3016 (Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown ...)
3556 - php5 5.1.4-0.1 (medium)
3557 - php4 4:4.4.4-1 (medium; bug #382259)
3558 CVE-2006-3015 (Argument injection vulnerability in WinSCP 3.8.1 build 328 allows ...)
3559 NOT-FOR-US: WinSCP
3560 CVE-2006-3014 (Microsoft Excel allows user-assisted attackers to execute arbitrary ...)
3561 NOT-FOR-US: Microsoft Excel
3562 CVE-2006-3013 (Interpretation conflict in resetpw.php in phpBannerExchange before 2.0 ...)
3563 NOT-FOR-US: phpBannerExchange
3564 CVE-2006-3012 (SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 ...)
3565 NOT-FOR-US: phpBannerExchange
3566 CVE-2006-3011 (The error_log function in basic_functions.c in PHP before 4.4.4 and ...)
3567 - php4 4:4.4.4-1 (low)
3568 - php5 5.1.6-1 (low)
3569 [sarge] - php4 <no-dsa> (Safe mode not supported)
3570 NOTE: only safe mode bypass
3571 CVE-2003-1303 (Buffer overflow in the imap_fetch_overview function in the IMAP ...)
3572 NOT-FOR-US: Microsoft Internet Explore
3573 CVE-2003-1302 (The IMAP functionality in PHP before 4.3.1 allows remote attackers to ...)
3574 - php4 4:4.3.2+rc3-1
3575 CVE-2002-2215 (The imap_header function in the IMAP functionality for PHP before ...)
3576 - php4 4:4.3.2+rc3-1
3577 CVE-2002-2214 (The php_if_imap_mime_header_decode function in the IMAP functionality ...)
3578 - php4 4:4.3.2+rc3-1
3579 CVE-1999-1589 (Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users ...)
3580 NOT-FOR-US: IBM AIX
3581 CVE-2006-3010 (Multiple SQL injection vulnerabilities in Open Business Management ...)
3582 NOT-FOR-US: not packaged for Debian
3583 CVE-2006-3009 (Multiple cross-site scripting (XSS) vulnerabilities in Open Business ...)
3584 NOT-FOR-US: not packaged for Debian
3585 CVE-2006-3008 (SQL injection vulnerability in index.php in Particle Links 1.2.2 ...)
3586 NOT-FOR-US: Particle Links
3587 CVE-2006-3007 (Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 ...)
3588 NOT-FOR-US: not packaged for Debian
3589 CVE-2006-3006 (Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly ...)
3590 NOT-FOR-US: iFoto
3591 CVE-2006-3005 (The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is ...)
3592 - libjpeg62 <not-affected> (--maxmem is set during configure)
3593 - libjpeg-mmx <removed> (bug #373672; low)
3594 [sarge] - libjpeg-mmx <no-dsa> (If this poses a threat, the admin can apply resource limits)
3595 CVE-2006-3004 (Multiple cross-site scripting (XSS) vulnerabilities in Ez Ringtone ...)
3596 NOT-FOR-US: Ez Ringtone
3597 CVE-2006-3003 (details.php in Easy Ad-Manager allows remote attackers to obtain the ...)
3598 NOT-FOR-US: not packaged for Debian
3599 CVE-2006-3002 (Cross-site scripting (XSS) vulnerability in details.php in Easy ...)
3600 NOT-FOR-US: not packaged for Debian
3601 CVE-2006-3001 (Cross-site scripting (XSS) vulnerability in search.php in OkScripts ...)
3602 NOT-FOR-US: not packaged for Debian
3603 CVE-2006-3000 (Cross-site scripting (XSS) vulnerability in search.php in OkScripts ...)
3604 NOT-FOR-US: not packaged for Debian
3605 CVE-2006-2999 (Cross-site scripting (XSS) vulnerability in search.php in OkScripts ...)
3606 NOT-FOR-US: not packaged for Debian
3607 CVE-2006-2998 (PHP remote file inclusion vulnerability in board/post.php in free ...)
3608 NOT-FOR-US: not packaged for Debian
3609 CVE-2006-2997 (Cross-site scripting (XSS) vulnerability in ZMS 2.9 and earlier, when ...)
3610 - zope-zms <unfixed> (bug #373667; unimportant)
3611 [sarge] - zope-zms <no-dsa> (Only exploitable with register_globals)
3612 NOTE: register_globals is an unsupported mode of operation in Debian
3613 CVE-2006-2996 (PHP remote file inclusion vulnerability in inc/design.inc.php in ...)
3614 NOT-FOR-US: aePartner
3615 CVE-2006-2995 (Multiple PHP remote file inclusion vulnerabilities in WebprojectDB ...)
3616 NOT-FOR-US: WebprojectDB
3617 CVE-2006-2994 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
3618 NOT-FOR-US: phazizGuestbook
3619 CVE-2006-2993 (Multiple SQL injection vulnerabilities in My Photo Scrapbook 1.0 and ...)
3620 NOT-FOR-US: My Photo Scrapbook
3621 CVE-2006-2992 (Cross-site scripting (XSS) vulnerability in display.asp in My Photo ...)
3622 NOT-FOR-US: My Photo Scrapbook
3623 CVE-2006-2991 (Multiple cross-site scripting (XSS) vulnerabilities in Ringlink 3.2 ...)
3624 NOT-FOR-US: Ringlink
3625 CVE-2006-2990 (Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft ...)
3626 NOT-FOR-US: VanillaSoft
3627 CVE-2006-2989 (Cross-site scripting (XSS) vulnerability in listpics.asp in ASP ...)
3628 NOT-FOR-US: ASP ListPics
3629 CVE-2006-2988 (Cross-site scripting (XSS) vulnerability in dictionary.php in Chemical ...)
3630 NOT-FOR-US: Chemical Dictionary
3631 CVE-2006-2987 (Multiple SQL injection vulnerabilities in Dominios Europa PICRATE (aka ...)
3632 NOT-FOR-US: PICRATE
3633 CVE-2006-2986 (Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie ...)
3634 NOT-FOR-US: vSCAL and vsREAL
3635 CVE-2006-2985 (SQL injection vulnerability in index.php in IntegraMOD 1.4.0 and ...)
3636 NOT-FOR-US: IntegraMOD
3637 CVE-2006-2984 (Cross-site scripting (XSS) vulnerability in index.php in IntegraMOD ...)
3638 NOT-FOR-US: IntegraMOD
3639 CVE-2006-2983 (PHP remote file inclusion vulnerability in Enterprise Timesheet and ...)
3640 NOT-FOR-US: Enterprise Timesheet and Payroll Systems (EPS)
3641 CVE-2006-2982 (Multiple PHP remote file inclusion vulnerabilities in Enterprise ...)
3642 NOT-FOR-US: Enterprise Timesheet and Payroll Systems (EPS)
3643 CVE-2006-2981 (SQL injection vulnerability in vs_search.php in Arantius Vice Stats ...)
3644 NOT-FOR-US: Arantius Vice Stats
3645 CVE-2006-2980 (SQL injection vulnerability in block_forum_topic_new.php in ViArt Shop ...)
3646 NOT-FOR-US: ViArt
3647 CVE-2006-2979 (Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Free ...)
3648 NOT-FOR-US: ViArt
3649 CVE-2006-2978 (Mafia Moblog 0.6M1 and earlier allows remote attackers to obtain the ...)
3650 NOT-FOR-US: Moblog
3651 CVE-2006-2977 (SQL injection vulnerability in big.php in Mafia Moblog 0.6M1 and ...)
3652 NOT-FOR-US: Moblog
3653 CVE-2006-2976 (Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery ...)
3654 NOT-FOR-US: Coppermine
3655 CVE-2006-2975 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
3656 NOT-FOR-US: PBL Guestbook
3657 CVE-2006-2974 (Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect ...)
3658 NOT-FOR-US: EmailArchitect
3659 CVE-2006-2973 (Multiple SQL injection vulnerabilities in month.php in PHP Lite ...)
3660 NOT-FOR-US: PHP Lite Calendar
3661 CVE-2006-2972 (SQL injection vulnerability in vs_resource.php in Arantius Vice Stats ...)
3662 NOT-FOR-US: Arantius Vice Stats
3663 CVE-2006-2971 (Integer overflow in the recv_packet function in 0verkill 0.16 allows ...)
3664 - overkill 0.16-9 (bug #373687; medium)
3665 CVE-2006-2970 (videoPage.php in L0j1k tinyMuw 0.1.0 allows remote attackers to obtain ...)
3666 NOT-FOR-US: tinyMuw
3667 CVE-2006-2969 (Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow ...)
3668 NOT-FOR-US: tinyMuw
3669 CVE-2006-2968 (Cross-site scripting (XSS) vulnerability in search.php in PHP Labware ...)
3670 NOT-FOR-US: LabWiki
3671 CVE-2006-2967 (Syworks SafeNET allows local users to bypass restrictions on network ...)
3672 NOT-FOR-US: SafeNET
3673 CVE-2006-2966 (Cross-site scripting (XSS) vulnerability in Particle Soft Particle ...)
3674 NOT-FOR-US: Particle Wiki
3675 CVE-2006-2965 (Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft ...)
3676 NOT-FOR-US: Particle Whois
3677 CVE-2006-2964 (Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts ...)
3678 NOT-FOR-US: Xtreme Downloads
3679 CVE-2006-2963 (Cross-site scripting (XSS) vulnerability in Suchergebnisse.asp in ...)
3680 NOT-FOR-US: Cabacos Web CMS
3681 CVE-2006-2962 (PHP remote file inclusion vulnerability in sql_fcnsOLD.php in ...)
3682 NOT-FOR-US: Empris
3683 CVE-2006-2961 (Stack-based buffer overflow in CesarFTP 0.99g and earlier allows ...)
3684 NOT-FOR-US: CesarFTP
3685 CVE-2006-2960 (PHP remote file inclusion vulnerability in includes/joomla.php in ...)
3686 - joomla <itp> (bug #326398)
3687 CVE-2006-2959 (SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 ...)
3688 NOT-FOR-US: Snitz Forum
3689 CVE-2006-2958 (Directory traversal vulnerability in FilZip 3.05 allows remote ...)
3690 NOT-FOR-US: FilZip
3691 CVE-2006-2957 (Cross-site scripting (XSS) vulnerability in i.List 1.5 beta and ...)
3692 NOT-FOR-US: i.List
3693 CVE-2006-2956 (Multiple cross-site scripting (XSS) vulnerabilities in i.List 1.5 beta ...)
3694 NOT-FOR-US: i.List
3695 CVE-2006-2955 (Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice ...)
3696 NOT-FOR-US: KAPhotoservice
3697 CVE-2006-2954 (SQL injection vulnerability in files.asp in OfficeFlow 2.6 and earlier ...)
3698 NOT-FOR-US: OfficeFlow
3699 CVE-2006-2953 (Cross-site scripting (XSS) vulnerability in default.asp in OfficeFlow ...)
3700 NOT-FOR-US: OfficeFlow
3701 CVE-2006-2952 (Directory traversal vulnerability in Net Portal Dynamic System (NPDS) ...)
3702 NOT-FOR-US: NPDS
3703 CVE-2006-2951 (Multiple cross-site scripting (XSS) vulnerabilities in Net Portal ...)
3704 NOT-FOR-US: NPDS
3705 CVE-2006-2950 (Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote ...)
3706 NOT-FOR-US: NPDS
3707 CVE-2006-2949 (Cross-site scripting (XSS) vulnerability in private.php in MyBB 1.1.2 ...)
3708 NOT-FOR-US: MyBB
3709 CVE-2006-2948 (A-CART 2.0 stores the acart2_0.mdb file under the web document root ...)
3710 NOT-FOR-US: A-CART
3711 CVE-2006-2947 (Dmx Forum 2.1a allows remote attackers to obtain username and password ...)
3712 NOT-FOR-US: Dmx Forum
3713 CVE-2006-2946 (Dmx Forum 2.1a stores _includes/bd.inc under the web root with ...)
3714 NOT-FOR-US: Dmx Forum
3715 CVE-2006-2945 (Unspecified vulnerability the user profile change functionality in ...)
3716 - dokuwiki 0.0.20060309-4 (bug #373689; low)
3717 CVE-2006-2944 (Unspecified vulnerability in CGI-RESCUE FORM2MAIL 1.21 and earlier ...)
3718 NOT-FOR-US: FORM2MAIL
3719 CVE-2006-2943 (Unspecified vulnerability in CGI-RESCUE WebFORM 4.1 and earlier allows ...)
3720 NOT-FOR-US: WebFORM
3721 CVE-2006-2942 (TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki ...)
3722 - twiki <not-affected> (Debian's version is old and does not include affected file)
3723 CVE-2006-2941 (Mailman before 2.1.9rc1 allows remote attackers to cause a denial of ...)
3724 TODO: check
3725 CVE-2006-2940
3726 RESERVED
3727 CVE-2006-2939
3728 RESERVED
3729 CVE-2006-2938
3730 RESERVED
3731 CVE-2006-2937
3732 RESERVED
3733 CVE-2006-2936 (The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up ...)
3734 - linux-2.6 2.6.17-5 (low)
3735 - linux-2.6.16 <unfixed> (low)
3736 CVE-2006-2935 (The dvd_read_bca function in the DVD handling code in ...)
3737 - linux-2.6 2.6.17-5 (low)
3738 - linux-2.6.16 <unfixed> (low)
3739 CVE-2006-2934 (SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux ...)
3740 - linux-2.6 2.6.17-3
3741 - linux-2.6.16 2.6.16-17
3742 CVE-2006-2933 (kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat ...)
3743 [sarge] - kdebase <not-affected> (Only KDE < 3.2 vulnerable)
3744 CVE-2006-2932 (A regression error in the restore_all code path of the 4/4GB split ...)
3745 TODO: check
3746 CVE-2006-2931 (CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, ...)
3747 NOT-FOR-US: CMS Mundo
3748 CVE-2006-2930 (Unspecified vulnerability in Sun Grid Engine 5.3 and Sun N1 Grid ...)
3749 NOT-FOR-US: Sun
3750 CVE-2006-2929 (PHP remote file inclusion vulnerability in ...)
3751 NOT-FOR-US: OpenEMR
3752 CVE-2006-2928 (Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 ...)
3753 NOT-FOR-US: CMS-Bandits
3754 CVE-2006-2927 (Multiple cross-site scripting (XSS) vulnerabilities in post.asp in ...)
3755 NOT-FOR-US: CAForum
3756 CVE-2006-2926 (Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate ...)
3757 NOT-FOR-US: Qbik
3758 CVE-2006-2925 (Cross-site scripting (XSS) vulnerability in the web interface in ...)
3759 NOT-FOR-US: Ingate
3760 CVE-2006-2924 (Ingate Firewall in the SIP module before 4.4.1 and SIParator before ...)
3761 NOT-FOR-US: Ingate
3762 CVE-2006-2923 (The iax_net_read function in the iaxclient open source library, as ...)
3763 - iaxclient 0.0+svn20060520-2
3764 CVE-2006-2922 (Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie ...)
3765 NOT-FOR-US: MiraksGalerie
3766 CVE-2006-2921 (PHP remote file inclusion vulnerability in cmpro_header.inc.php in ...)
3767 NOT-FOR-US: CMPro
3768 CVE-2006-2920 (Sylpheed-Claws before 2.2.2 and Sylpheed before 2.2.6 allow remote ...)
3769 - sylpheed 2.2.6-1 (low)
3770 - sylpheed-gtk1 1.0.6-3 (bug #373187; low)
3771 - sylpheed-claws 1.0.5-3 (bug #372891; low)
3772 - sylpheed-claws-gtk2 2.3.0-1 (bug #372889; low)
3773 CVE-2006-2919 (Unspecified vulnerability in Microsoft NetMeeting 3.01 allows remote ...)
3774 NOT-FOR-US: Microsoft
3775 CVE-2006-2918 (The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores ...)
3776 NOT-FOR-US: Lanap BotDetect APS.NET CAPTCHA component
3777 CVE-2006-2917 (Directory traversal vulnerability in the IMAP server in WinGate ...)
3778 NOT-FOR-US: WinGate
3779 CVE-2006-2916 (artswrapper in aRts, when running setuid root on Linux 2.6.0 or later ...)
3780 - arts 1.5.3-2 (bug #374003; low)
3781 [sarge] - arts <not-affected> (Not setuid root in Debian)
3782 NOTE: artswrapper is not suid root by default, but README.Debian describes it
3783 CVE-2006-2915 (Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote ...)
3784 NOT-FOR-US: DeluxeBB
3785 CVE-2006-2914 (PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote ...)
3786 NOT-FOR-US: DeluxeBB
3787 CVE-2006-2913 (Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows ...)
3788 NOT-FOR-US: SelectaPix
3789 CVE-2006-2912 (Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote ...)
3790 NOT-FOR-US: SelectaPix
3791 CVE-2006-2911 (SQL injection vulnerability in controlpanel/index.php in CMS Mundo before 1.0 ...)
3792 NOT-FOR-US: CMS Mundo
3793 CVE-2006-2910 (Buffer overflow in jetAudio 6.2.6.8330 (Basic), and possibly other ...)
3794 NOT-FOR-US: jetAudio
3795 CVE-2006-2909 (Stack-based buffer overflow in the info tip shell extension ...)
3796 NOT-FOR-US: PicoZip
3797 CVE-2006-2908 (The domecode function in inc/functions_post.php in MyBulletinBoard ...)
3798 NOT-FOR-US: MyBB
3799 CVE-2006-2907
3800 RESERVED
3801 CVE-2006-2906 (The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas ...)
3802 {DSA-1117}
3803 - libgd2 2.0.33-5 (bug #372912; low)
3804 CVE-2006-2905 (Partial Links 1.2.2 allows remote attackers to obtain sensitive ...)
3805 NOT-FOR-US: Partial Links
3806 CVE-2006-2904 (SQL injection vulnerability in index.php in Partial Links 1.2.2 allows ...)
3807 NOT-FOR-US: Partial Links
3808 CVE-2006-2903 (Cross-site scripting (XSS) vulnerability in admin.php in Particle ...)
3809 NOT-FOR-US: Partial Links
3810 CVE-2006-2902 (Directory traversal vulnerability in Particle Links 1.2.2 might allow ...)
3811 NOT-FOR-US: Partial Links
3812 CVE-2006-2901 (The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware ...)
3813 NOT-FOR-US: D-Link
3814 CVE-2006-2900 (Internet Explorer 6 allows user-assisted remote attackers to read ...)
3815 NOT-FOR-US: Microsoft
3816 CVE-2006-2899 (Unspecified vulnerability in ESTsoft InternetDISK versions before ...)
3817 NOT-FOR-US: ESTsoft InternetDISK
3818 CVE-2006-2898 (The IAX2 channel driver (chan_iax2) for Asterisk 1.2.x before 1.2.9 ...)
3819 {DSA-1126}
3820 - asterisk 1:1.2.10.dfsg-2 (bug #380054)
3821 - iax 0.2.2-5
3822 [sarge] - iax <not-affected> (Vulnerable code not present)
3823 - iaxmodem 0.1.8.dfsg-2
3824 CVE-2006-2897 (Cross-site scripting (XSS) vulnerability in FunkBoard 0.71 allows ...)
3825 NOT-FOR-US: Funkboard
3826 CVE-2006-2896 (profile.php in FunkBoard CF0.71 allows remote attackers to change ...)
3827 NOT-FOR-US: Funkboard
3828 CVE-2006-2895 (Cross-site scripting (XSS) vulnerability in MediaWiki 1.6.0 up to ...)
3829 - mediawiki <not-affected> (Affects only 1.6.0-1.6.6)
3830 CVE-2006-2894 (Mozilla Firefox 1.5.0.4, Mozilla Suite 1.7.13, Mozilla SeaMonkey ...)
3831 NOTE: There are very few scenarios, where this could be exploited
3832 NOTE: We can probably ignore this
3833 TODO: check further
3834 CVE-2006-2893 (index.php in GANTTy 1.0.3 allows remote attackers to obtain the full ...)
3835 NOT-FOR-US: GANTTy
3836 CVE-2006-2892 (Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 ...)
3837 NOT-FOR-US: GANTTy
3838 CVE-2006-2891 (Cross-site scripting (XSS) vulnerability in admin/index.php for ...)
3839 NOT-FOR-US: Pixelpost
3840 CVE-2006-2890 (Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, ...)
3841 NOT-FOR-US: Pixelpost
3842 CVE-2006-2889 (Multiple SQL injection vulnerabilities in index.php in Pixelpost ...)
3843 NOT-FOR-US: Pixelpost
3844 CVE-2006-2888 (PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig ...)
3845 NOT-FOR-US: Wikiwig
3846 CVE-2006-2887 (Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and ...)
3847 NOT-FOR-US: myNewsletter
3848 CVE-2006-2886 (view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote ...)
3849 - knowledgetree <unfixed> (bug #373137; low)
3850 CVE-2006-2885 (Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree ...)
3851 - knowledgetree <unfixed> (bug #373137; low)
3852 CVE-2006-2884 (SQL injection vulnerability in index.php in Kmita FAQ 1.0 allows ...)
3853 NOT-FOR-US: Kmita
3854 CVE-2006-2883 (Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ ...)
3855 NOT-FOR-US: Kmita
3856 CVE-2006-2882 (Multiple cross-site scripting (XSS) vulnerabilities submit.asp in ...)
3857 NOT-FOR-US: ASPScriptz
3858 CVE-2006-2881 (Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 ...)
3859 NOT-FOR-US: DreamAccount
3860 CVE-2006-2880 (Cross-site scripting (XSS) vulnerability in the Contributed Packages ...)
3861 NOT-FOR-US: pyblosxom package doesn't ship plugins
3862 CVE-2006-2879 (SQL injection vulnerability in newscomments.php in Alex News-Engine ...)
3863 NOT-FOR-US: Alex News-Engine
3864 CVE-2006-2878 (The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier ...)
3865 - dokuwiki 0.0.20060309-4 (bug #370369; high)
3866 CVE-2006-2877 (PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and ...)
3867 NOT-FOR-US: Bookmark4U
3868 CVE-2006-2876 (Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish ...)
3869 NOT-FOR-US: PHP Pro Publish
3870 CVE-2006-2875 (Stack-based buffer overflow in the CL_ParseDownload function of Quake ...)
3871 - quake3 <itp> (bug #337937)
3872 CVE-2006-2874 (Unspecified vulnerability in OSADS Alliance Database before 1.4 has ...)
3873 NOT-FOR-US: OSADS
3874 CVE-2006-2873 (Cross-site scripting (XSS) vulnerability in hava.asp in Enigma Haber ...)
3875 NOT-FOR-US: Enigma Haber
3876 CVE-2006-2872 (PHP remote file inclusion vulnerability in config.php in Rumble 1.02 ...)
3877 NOT-FOR-US: Rumble
3878 CVE-2006-2871 (PHP remote file inclusion vulnerability in include/common.php in ...)
3879 NOT-FOR-US: CyBoards
3880 CVE-2006-2870 (Cross-site scripting (XSS) vulnerability in forum_search.asp in ...)
3881 NOT-FOR-US: Intelligent Solutions Inc.
3882 CVE-2006-2869 (Unspecified vulnerability in the CHM unpacker in avast! before 4.7.844 ...)
3883 NOT-FOR-US: Avast
3884 CVE-2006-2868 (Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 ...)
3885 NOT-FOR-US: Claroline
3886 CVE-2006-2867 (SQL injection vulnerability in editpost.php in CoolForum 0.8.3 beta ...)
3887 NOT-FOR-US: CoolForum
3888 CVE-2006-2866 (PHP remote file inclusion vulnerability in layout/prepend.php in ...)
3889 NOT-FOR-US: DotClear
3890 CVE-2006-2865 (** DISPUTED ** ...)
3891 NOTE: phpbb2, but invalid
3892 CVE-2006-2864 (Multiple PHP remote file inclusion vulnerabilities in BlueShoes ...)
3893 NOT-FOR-US: BlueShoes
3894 CVE-2006-2863 (PHP remote file inclusion vulnerability in class.cs_phpmailer.php in ...)
3895 NOT-FOR-US: CS-Cart
3896 CVE-2006-2862 (SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 ...)
3897 NOT-FOR-US: Particle Gallery
3898 CVE-2006-2861 (SQL injection vulnerability in index.php in Particle Wiki 1.0.2 and ...)
3899 NOT-FOR-US: Particle Wiki
3900 CVE-2006-2860 (PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 ...)
3901 NOT-FOR-US: Webspotblogging
3902 CVE-2006-2859 (** DISPUTED ** ...)
3903 NOT-FOR-US: MyBloggie
3904 CVE-2006-2858 (SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds ...)
3905 NOT-FOR-US: LocazoList
3906 CVE-2006-2857 (SQL injection vulnerability in index.php in LifeType 1.0.4 allows ...)
3907 NOT-FOR-US: LifeType
3908 CVE-2006-2856 (ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib ...)
3909 NOT-FOR-US: ActiveState
3910 CVE-2006-2855 (SQL injection vulnerability in index.php in xueBook 1.0 allows remote ...)
3911 NOT-FOR-US: xueBook
3912 CVE-2006-2854 (SQL injection vulnerability in index.php in iBWd Guestbook 1.0 allows ...)
3913 NOT-FOR-US: iBWd
3914 CVE-2006-2853 (SQL injection vulnerability in content.php in abarcar Realty Portal ...)
3915 NOT-FOR-US: abarcar
3916 CVE-2006-2852 (PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and ...)
3917 NOT-FOR-US: dotWidget
3918 CVE-2006-2851 (Cross-site scripting (XSS) vulnerability in index.php in dotProject ...)
3919 NOT-FOR-US: dotProject
3920 CVE-2006-2850 (Cross-site scripting (XSS) vulnerability in recentchanges.php in PHP ...)
3921 NOT-FOR-US: LabWiki
3922 CVE-2006-2849 (PHP remote file inclusion vulnerability in includes/webdav/server.php ...)
3923 NOT-FOR-US: Bytehoard
3924 CVE-2006-2848 (links.asp in aspWebLinks 2.0 allows remote attackers to change the ...)
3925 NOT-FOR-US: aspWebLinks
3926 CVE-2006-2847 (SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows ...)
3927 NOT-FOR-US: aspWebLinks
3928 CVE-2006-2846 (Cross-site scripting (XSS) vulnerability in Print.PHP in VisionGate ...)
3929 NOT-FOR-US: VisionGate
3930 CVE-2006-2845 (PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows ...)
3931 NOT-FOR-US: Redaxo
3932 CVE-2006-2844 (Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow ...)
3933 NOT-FOR-US: Redaxo
3934 CVE-2006-2843 (PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote ...)
3935 NOT-FOR-US: Redaxo
3936 CVE-2006-2841 (Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ...)
3937 NOT-FOR-US: AssoCIateD
3938 CVE-2006-2840 (Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) ...)
3939 NOT-FOR-US: PmWiki
3940 CVE-2006-2839 (Directory traversal vulnerability in PG Problem Editor module ...)
3941 NOT-FOR-US: WeBWorK
3942 CVE-2006-2838 (Buffer overflow in the web console in F-Secure Anti-Virus for ...)
3943 NOT-FOR-US: F-Secure
3944 CVE-2006-2837 (Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book ...)
3945 NOT-FOR-US: Techno Dreams
3946 CVE-2006-2836 (SQL injection vulnerability in comment.php in Pineapple Technologies ...)
3947 NOT-FOR-US: Pineapple Technologies Lore
3948 CVE-2006-2835 (SQL injection vulnerability in saphplesson 2.0 allows remote attackers ...)
3949 NOT-FOR-US: saphplesson
3950 CVE-2006-2834 (PHP remote file inclusion vulnerability in includes/common.php in ...)
3951 NOT-FOR-US: gnopaste
3952 CVE-2006-2833 (Cross-site scripting (XSS) vulnerability in the taxonomy module in ...)
3953 {DSA-1125}
3954 - drupal 4.5.8-1.1 (medium)
3955 CVE-2006-2832 (Cross-site scripting (XSS) vulnerability in the upload module ...)
3956 {DSA-1125}
3957 - drupal 4.5.8-1.1 (medium)
3958 CVE-2006-2831 (Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under ...)
3959 {DSA-1125}
3960 NOTE: Although not in the changelog, sesse@ (responsible for 4.5.8-1.1)
3961 NOTE: says he pulled in the entire patch for DRUPAL-SA-2006-007, which
3962 NOTE: fixes CVE-2006-2831.
3963 - drupal 4.5.8-1.1 (medium)
3964 CVE-2006-2830 (Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent ...)
3965 NOT-FOR-US: TIBCO
3966 CVE-2006-2829 (Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before ...)
3967 NOT-FOR-US: TIBCO
3968 CVE-2006-2828 (Global variable overwrite vulnerability in PHP-Nuke allows remote ...)
3969 NOT-FOR-US: PHP-Nuke
3970 CVE-2006-2827 (** DISPUTED ** ...)
3971 NOT-FOR-US: X-Cart
3972 CVE-2006-2826 (SQL injection vulnerability in sessions.inc in PHP Base Library ...)
3973 NOT-FOR-US: PHPLIB
3974 CVE-2006-2825 (cPanel does not automatically synchronize the PHP open_basedir ...)
3975 NOT-FOR-US: cPanel the vhost manager, not cpanel the Chinese desktop configuration tool
3976 CVE-2006-2824 (Logicalware MailManager before 2.0.10 does not remove 0xc8 0x27 (0xc8 ...)
3977 NOT-FOR-US: Logicalware
3978 CVE-2006-2823 (Katrien De Graeve a.shopKart 2.0 (aka ashopKart20) stores sensitive ...)
3979 NOT-FOR-US: ashopKart
3980 CVE-2006-2822 (SQL injection vulnerability in admin/default.asp in Dusan Drobac ...)
3981 NOT-FOR-US: cforum
3982 CVE-2006-2821 (Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts ...)
3983 NOT-FOR-US: DeltaScripts
3984 CVE-2006-2820 (Cross-site scripting (XSS) vulnerability in HotWebScripts.com Weblog ...)
3985 NOT-FOR-US: HotWebScripts
3986 CVE-2006-2819 (PHP remote file inclusion vulnerability in Wiki.php in Barnraiser ...)
3987 NOT-FOR-US: Barnraiser Igloo
3988 CVE-2006-2818 (PHP remote file inclusion vulnerability in common-menu.php in Cameron ...)
3989 NOT-FOR-US: Cameron McKay Informium
3990 CVE-2006-2817 (SQL injection vulnerability in bolum.php in tekno.Portal allows remote ...)
3991 NOT-FOR-US: tekno.Portal
3992 CVE-2006-2816 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
3993 NOT-FOR-US: CoolPHP
3994 CVE-2006-2815 (Multiple cross-site scripting (XSS) vulnerabilities in Two Shoes ...)
3995 NOT-FOR-US: SimpleBoard
3996 CVE-2006-2814 (Multiple buffer overflows in the (1) vGetPost and (2) main functions ...)
3997 NOT-FOR-US: iShopCart
3998 CVE-2006-2813 (Directory traversal vulnerability in easy-scart.cgi in iShopCart ...)
3999 NOT-FOR-US: iShopCart
4000 CVE-2006-2812 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
4001 NOT-FOR-US: PICRATE
4002 CVE-2006-2811 (Multiple PHP remote file inclusion vulnerabilities in Cantico ...)
4003 NOT-FOR-US: Ovidentia
4004 CVE-2006-2810 (Multiple cross-site scripting (XSS) vulnerabilities in Belchior ...)
4005 NOT-FOR-US: Belchior vCard
4006 CVE-2006-2809 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
4007 NOT-FOR-US: ar-blog
4008 CVE-2006-2808 (Cross-site scripting (XSS) vulnerability in Lycos Tripod htmlGEAR ...)
4009 NOT-FOR-US: Lycos
4010 CVE-2006-2807 (ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to ...)
4011 NOT-FOR-US: ASPwebSoft
4012 CVE-2006-2806 (The SMTP server in Apache Java Mail Enterprise Server (aka Apache ...)
4013 NOT-FOR-US: Apache James
4014 CVE-2005-2468 (Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and ...)
4015 NOT-FOR-US: MySQL Eventum
4016 CVE-2005-2467 (Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum ...)
4017 NOT-FOR-US: MySQL Eventum
4018 CVE-2005-2466 (Multiple SQL injection vulnerabilities in the auth_user function in ...)
4019 NOT-FOR-US: OpenBook
4020 CVE-2005-2465 (Cross-site scripting (XSS) vulnerability in pm.php in PCXP/TOPPE CMS ...)
4021 NOT-FOR-US: PC-EXPERIENCE/TOPPE CMS
4022 CVE-2005-2464 (login.php in PCXP/TOPPE CMS allows remote attackers to bypass ...)
4023 NOT-FOR-US: PC-EXPERIENCE/TOPPE CMS
4024 CVE-2005-2463 (Kayako liveResponse 2.x allows remote attackers to obtain sensitive ...)
4025 NOT-FOR-US: Kayako liveResponse
4026 CVE-2005-2462 (Kayako liveResponse 2.x, when logging in a user, records the password ...)
4027 NOT-FOR-US: Kayako liveResponse
4028 CVE-2005-2461 (Multiple SQL injection vulnerabilities in the calendar feature in ...)
4029 NOT-FOR-US: Kayako liveResponse
4030 CVE-2005-2460 (Multiple cross-site scripting (XSS) vulnerabilities in Kayako ...)
4031 NOT-FOR-US: Kayako liveResponse
4032 CVE-2006-2842 (** DISPUTED ** ...)
4033 - squirrelmail 2:1.4.7-1 (unimportant)
4034 NOTE: Only exploitable with register_globals enabled
4035 CVE-2006-XXXX [XSS vulnerability in dokuwikis's "Fullname" and "E-Mail" fields]
4036 - dokuwiki <unfixed> (medium)
4037 CVE-2006-XXXX [PHP injection vulnerability in dokuwiki via curly braces]
4038 - dokuwiki <unfixed> (medium)
4039 CVE-2006-XXXX [webalizer: symlink vulnerability]
4040 - webalizer 2.01.10-29
4041 CVE-2006-2805 (SQL injection vulnerability in VBulletin 3.0.10 allows remote ...)
4042 NOT-FOR-US: vBulletin
4043 CVE-2006-2804 (Cross-site scripting (XSS) vulnerability in index.cfm in Goss ...)
4044 NOT-FOR-US: Goss iCM
4045 CVE-2006-2803 (Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker ...)
4046 NOT-FOR-US: PHP ManualMaker
4047 CVE-2006-2802 (Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib ...)
4048 {DSA-1105}
4049 - xine-lib 1.1.1-2 (bug #369876; medium)
4050 CVE-2006-2801 (Multiple SQL injection vulnerabilities in Unak CMS 1.5 RC2 and earlier ...)
4051 NOT-FOR-US: Unak CMS
4052 CVE-2006-2800 (Multiple cross-site scripting (XSS) vulnerabilities in Unak CMS 1.5 ...)
4053 NOT-FOR-US: Unak CMS
4054 CVE-2006-2799 (Cross-site scripting (XSS) vulnerability in content_footer.php in ...)
4055 NOT-FOR-US: toendaCMS
4056 CVE-2006-2798 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
4057 NOT-FOR-US: phpCommunityCalendar
4058 CVE-2006-2797 (Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 ...)
4059 NOT-FOR-US: phpCommunityCalendar
4060 CVE-2006-2796 (Cross-site scripting (XSS) vulnerability in gallery.php in Captivate ...)
4061 NOT-FOR-US: Captivate gallery.php
4062 CVE-2006-2795 (Multiple cross-site scripting (XSS) vulnerabilities in XiTi Tracking ...)
4063 NOT-FOR-US: XiTi Tracking Script
4064 CVE-2006-2794 (Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to ...)
4065 NOT-FOR-US: ASPSitem
4066 CVE-2006-2793 (SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier ...)
4067 NOT-FOR-US: ASPSitem
4068 CVE-2006-2792 (SQL injection vulnerability in misc.php in Woltlab Burning Board (WBB) ...)
4069 NOT-FOR-US: wbboard
4070 CVE-2006-2791 (Directory traversal vulnerability in index.php in iBoutique.MALL and ...)
4071 NOT-FOR-US: iBoutique.MALL
4072 CVE-2006-2790 (A package component in Sun Storage Automated Diagnostic Environment ...)
4073 NOT-FOR-US: Sun StorADE
4074 CVE-2006-2789 (Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when &quot;load images if ...)
4075 - evolution 2.4.0-1 (low)
4076 [sarge] - evolution <not-affected> (Not reproducible on Sarge's evolution)
4077 NOTE: Verified that the patch has been applied in 2.4.0-1,
4078 NOTE: may have been fixed earlier.
4079 CVE-2006-2788 (Double-free vulnerability in the getRawDER function for nsIX509Cert in ...)
4080 - mozilla <unfixed> (high)
4081 - mozilla-firefox <unfixed> (high)
4082 - firefox 1.5.dfsg+1.5.0.4 (high)
4083 - xulrunner 1.8.0.4-1 (high)
4084 CVE-2006-2787 (EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows ...)
4085 {DSA-1134-1 DSA-1120 DSA-1118}
4086 NOTE: MFSA-2006-31
4087 - firefox 1.5.dfsg+1.5.0.4-1 (medium)
4088 - thunderbird 1.5.0.4-1 (medium)
4089 [sarge] - mozilla-thunderbird <unfixed> (medium)
4090 - mozilla 2:1.7.13-0.3 (medium)
4091 - xulrunner 1.8.0.4-1 (medium)
4092 CVE-2006-2786 (HTTP response smuggling vulnerability in Mozilla Firefox and ...)
4093 {DSA-1134-1 DSA-1120 DSA-1118}
4094 NOTE: MFSA-2006-33
4095 - firefox 1.5.dfsg+1.5.0.4-1 (medium)
4096 - thunderbird 1.5.0.4-1 (medium)
4097 [sarge] - mozilla-thunderbird <unfixed> (medium)
4098 - mozilla 2:1.7.13-0.3 (medium)
4099 - xulrunner 1.8.0.4-1 (medium)
4100 CVE-2006-2785 (Cross-site scripting (XSS) vulnerability in Mozilla Firefox before ...)
4101 {DSA-1134-1 DSA-1120 DSA-1118}
4102 NOTE: MFSA-2006-34
4103 - firefox 1.5.dfsg+1.5.0.4-1 (medium)
4104 - mozilla 2:1.7.13-0.3 (medium)
4105 - xulrunner 1.8.0.4-1 (medium)
4106 CVE-2006-2784 (The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ...)
4107 {DSA-1134-1 DSA-1120 DSA-1118}
4108 NOTE: MFSA-2006-36
4109 - firefox 1.5.dfsg+1.5.0.4-1 (medium)
4110 - mozilla <unfixed> (medium)
4111 - xulrunner 1.8.0.4-1 (medium)
4112 CVE-2006-2783 (Mozilla Firefox and Thunderbird before 1.5.0.4 strips the Unicode ...)
4113 {DSA-1134-1 DSA-1120 DSA-1118}
4114 NOTE: MFSA-2006-42
4115 - firefox 1.5.dfsg+1.5.0.4-1 (medium)
4116 - thunderbird 1.5.0.4-1 (medium)
4117 - mozilla 2:1.7.13-0.3 (medium)
4118 - xulrunner 1.8.0.4-1 (medium)
4119 CVE-2006-2782 (Firefox 1.5.0.2 does not fix all test cases associated with ...)
4120 {DSA-1134-1 DSA-1120 DSA-1118}
4121 NOTE: MFSA-2006-41
4122 - firefox 1.5.dfsg+1.5.0.4-1 (medium)
4123 - mozilla 2:1.7.13-0.3 (medium)
4124 - xulrunner 1.8.0.4-1 (medium)
4125 CVE-2006-2781 (Double-free vulnerability in Mozilla Thunderbird before 1.5.0.4 and ...)
4126 {DSA-1134-1 DSA-1118}
4127 NOTE: MFSA-2006-40
4128 - thunderbird 1.5.0.4-1 (high)
4129 - mozilla 2:1.7.13-0.3 (high)
4130 - xulrunner <unfixed> (high)
4131 CVE-2006-2780 (Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 ...)
4132 {DSA-1134-1 DSA-1120 DSA-1118}
4133 NOTE: MFSA-2006-32
4134 - firefox 1.5.dfsg+1.5.0.4-1 (high)
4135 - thunderbird 1.5.0.4-1 (high)
4136 - mozilla 2:1.7.13-0.3 (high)
4137 - xulrunner 1.8.0.4-1 (high)
4138 CVE-2006-2779 (Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ...)
4139 {DSA-1160 DSA-1159 DSA-1134-1 DSA-1120 DSA-1118}
4140 NOTE: MFSA-2006-32
4141 - firefox 1.5.dfsg+1.5.0.4-1 (high)
4142 - thunderbird 1.5.0.4-1 (high)
4143 - mozilla 2:1.7.13-0.3 (high)
4144 - xulrunner <unfixed> (high)
4145 CVE-2006-2778 (The crypto.signText function in Mozilla Firefox and Thunderbird before ...)
4146 {DSA-1134-1 DSA-1120 DSA-1118}
4147 NOTE: MFSA-2006-38
4148 - firefox 1.5.dfsg+1.5.0.4-1 (high)
4149 - thunderbird 1.5.0.4-1 (high)
4150 - mozilla 2:1.7.13-0.3 (high)
4151 - xulrunner 1.8.0.4-1 (high)
4152 CVE-2006-2777 (Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and ...)
4153 {DSA-1134-1 DSA-1120 DSA-1118}
4154 NOTE: MFSA-2006-43
4155 - firefox 1.5.dfsg+1.5.0.4-1 (high)
4156 - mozilla 2:1.7.13-0.3 (high)
4157 - xulrunner <unfixed> (high)
4158 CVE-2006-2776 (Certain privileged UI code in Mozilla Firefox and Thunderbird before ...)
4159 {DSA-1134-1 DSA-1120 DSA-1118}
4160 NOTE: MFSA-2006-37
4161 - firefox 1.5.dfsg+1.5.0.4-1 (high)
4162 - thunderbird 1.5.0.4-1 (high)
4163 - mozilla 2:1.7.13-0.3 (high)
4164 - xulrunner 1.8.0.4-1 (high)
4165 CVE-2006-2775 (Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL ...)
4166 {DSA-1134-1 DSA-1120 DSA-1118}
4167 NOTE: MFSA-2006-35
4168 - firefox 1.5.dfsg+1.5.0.4-1 (high)
4169 - thunderbird 1.5.0.4-1 (high)
4170 - mozilla 2:1.7.13-0.3 (high)
4171 - xulrunner 1.8.0.4-1 (high)
4172 CVE-2006-2774 (Cross-site scripting (XSS) vulnerability in search.php in QontentOne ...)
4173 NOT-FOR-US: QontentOne
4174 CVE-2006-2773 (admin/redigera/redigera2.asp in Hogstorps hogstorp Guestbook 2.0 does ...)
4175 NOT-FOR-US: Hogstorps
4176 CVE-2006-2772 (Cross-site scripting (XSS) vulnerability in add.asp in Hogstorps ...)
4177 NOT-FOR-US: Hogstorps
4178 CVE-2006-2771 (admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not ...)
4179 NOT-FOR-US: Hogstorps
4180 CVE-2006-2770 (Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 ...)
4181 NOT-FOR-US: pppBLOG
4182 CVE-2006-2769 (The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through ...)
4183 - snort 2.3.3-8 (low; bug #381726)
4184 [sarge] - snort <no-dsa> (Minor impact)
4185 CVE-2006-2768 (PHP remote file inclusion vulnerability in METAjour 2.1, when ...)
4186 NOT-FOR-US: METAjour
4187 CVE-2006-2767 (PHP remote file inclusion vulnerability in Ottoman 1.1.2, when ...)
4188 NOT-FOR-US: Ottoman
4189 CVE-2006-2766 (Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet ...)
4190 NOT-FOR-US: Microsoft
4191 CVE-2006-2765 (Cross-site scripting (XSS) vulnerability in news_information.php in ...)
4192 NOT-FOR-US: Interlink
4193 CVE-2006-2764 (Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows ...)
4194 NOT-FOR-US: GuestbookXL
4195 CVE-2006-2763 (SQL injection vulnerability in Pre News Manager 1.0 allows remote ...)
4196 NOT-FOR-US: Pre News Manager
4197 CVE-2006-2762 (PHP remote file inclusion vulnerability in includes/config.php in ...)
4198 {DSA-1096-1}
4199 - webcalendar 1.0.4-1 (medium)
4200 CVE-2006-2761 (SQL injection vulnerability in Hitachi HITSENSER3 HITSENSER3/PRP, ...)
4201 NOT-FOR-US: Hitachi
4202 CVE-2006-2760 (SQL injection vulnerability in modules.php in 4nNukeWare 4nForum 0.91 ...)
4203 NOT-FOR-US: 4nForum
4204 CVE-2006-2759 (jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary ...)
4205 TODO: check
4206 NOTE: sf: pinged maintainers about jetty 5
4207 CVE-2006-2758 (Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 ...)
4208 TODO: check
4209 NOTE: sf: pinged maintainers about jetty 5
4210 CVE-2006-2757 (Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows ...)
4211 NOT-FOR-US: Chipmunk guestbook
4212 CVE-2006-2756 (Eitsop My Web Server 1.0 allows remote attackers to cause a denial of ...)
4213 NOT-FOR-US: Eitsop
4214 CVE-2006-2755 (Cross-site scripting (XSS) vulnerability in index.php in UBBThreads ...)
4215 NOT-FOR-US: UBBThreads
4216 CVE-2006-2754 (Stack-based buffer overflow in st.c in slurpd for OpenLDAP before ...)
4217 - openldap2.3 <unfixed> (bug #375494; bug #377047; unimportant)
4218 NOTE: File is only written and read by slurpd, only editable by root
4219 CVE-2006-2752 (The RedCarpet /etc/ximian/rcd.conf configuration file in Novell Linux ...)
4220 NOT-FOR-US: RedCarpet
4221 CVE-2006-2751 (Cross-site scripting (XSS) vulnerability in Open Searchable Image ...)
4222 NOT-FOR-US: OSIC
4223 CVE-2006-2750 (Cross-site scripting (XSS) vulnerability in the do_mysql_query ...)
4224 NOT-FOR-US: OSIC
4225 CVE-2006-2749 (SQL injection vulnerability in search.php in Open Searchable Image ...)
4226 NOT-FOR-US: OSIC
4227 CVE-2006-2748 (SQL injection vulnerability in the do_mysql_query function in core.php ...)
4228 NOT-FOR-US: OSIC
4229 CVE-2006-2747 (Directory traversal vulnerability in index.php in PhpMyDesktop|arcade ...)
4230 NOT-FOR-US: PhpMyDesktop
4231 CVE-2006-2746 (Multiple cross-site scripting (XSS) vulnerabilities in F@cile ...)
4232 NOT-FOR-US: F@cile
4233 CVE-2006-2745 (Multiple PHP remote file inclusion vulnerabilities in F@cile ...)
4234 NOT-FOR-US: F@cile
4235 CVE-2006-2744 (PHP remote file inclusion vulnerability in p-popupgallery.php in ...)
4236 NOT-FOR-US: F@cile
4237 CVE-2006-2743 (Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with ...)
4238 {DSA-1125}
4239 - drupal 4.5.8-1.1 (bug #368835; medium)
4240 CVE-2006-2742 (SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 ...)
4241 {DSA-1125}
4242 - drupal 4.5.8-1.1 (medium)
4243 CVE-2006-2741 (Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 ...)
4244 NOT-FOR-US: tinyBB
4245 CVE-2006-2740 (Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow ...)
4246 NOT-FOR-US: tinyBB
4247 CVE-2006-2739 (PHP remote file inclusion vulnerability in footers.php in Epicdesigns ...)
4248 NOT-FOR-US: tinyBB
4249 CVE-2006-2738 (The open source version of Open-Xchange 0.8.2 and earlier uses a ...)
4250 NOT-FOR-US: Open-Xchange
4251 CVE-2006-2737 (utilities/register.asp in Nukedit 4.9.6 and earlier allows remote ...)
4252 NOT-FOR-US: Nukedit
4253 CVE-2006-2736 (PHP remote file inclusion vulnerability in blend_data/blend_common.php ...)
4254 NOT-FOR-US: Blend Portal
4255 CVE-2006-2735 (PHP remote file inclusion vulnerability in ...)
4256 NOT-FOR-US: Amod
4257 CVE-2006-2734 (enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote ...)
4258 NOT-FOR-US: Mini-Nuke
4259 CVE-2006-2733 (membership.asp in Mini-Nuke 2.3 and earlier uses plaintext security ...)
4260 NOT-FOR-US: Mini-Nuke
4261 CVE-2006-2732 (SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and ...)
4262 NOT-FOR-US: Mini-Nuke
4263 CVE-2006-2731 (Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier ...)
4264 NOT-FOR-US: Enigma Haber
4265 CVE-2006-2730 (PHP remote file inclusion vulnerability in admin/lib_action_step.php ...)
4266 NOT-FOR-US: Hot Open Tickets
4267 CVE-2006-2729 (Cross-site scripting (XSS) vulnerability in superalbum/index.php in ...)
4268 NOT-FOR-US: Photoalbum
4269 CVE-2006-2728 (Cross-site scripting (XSS) vulnerability in superalbum/index.php in ...)
4270 NOT-FOR-US: Photoalbum
4271 CVE-2006-2727 (home/register.php in Eggblog before 3.0 allows remote attackers to ...)
4272 NOT-FOR-US: Eggblog
4273 CVE-2006-2726 (PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d ...)
4274 NOT-FOR-US: Fastpublish
4275 CVE-2006-2725 (SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 ...)
4276 NOT-FOR-US: Eggblog
4277 CVE-2006-2724 (Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote ...)
4278 NOT-FOR-US: PunBB
4279 CVE-2006-2723 (Unspecified versions of Mozilla Firefox allow remote attackers to ...)
4280 - firefox <unfixed> (unimportant)
4281 - mozilla <unfixed> (unimportant)
4282 - mozilla-firefox <unfixed> (unimportant)
4283 - xulrunner <unfixed> (unimportant)
4284 NOTE: Non-issue
4285 CVE-2006-2722 (SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows ...)
4286 NOT-FOR-US: SelectaPix
4287 CVE-2006-2721 (Cross-site scripting (XSS) vulnerability in news.php in VARIOMAT ...)
4288 NOT-FOR-US: VARIOMAT
4289 CVE-2006-2720 (SQL injection vulnerability in news.php in VARIOMAT allows remote ...)
4290 NOT-FOR-US: VARIOMAT
4291 CVE-2006-2719 (JIWA Financials 6.4.14 stores usernames and passwords for all accounts ...)
4292 NOT-FOR-US: JIWA
4293 CVE-2006-2718 (JIWA Financials 6.4.14 passes a Microsoft SQL Server account's ...)
4294 NOT-FOR-US: JIWA
4295 CVE-2006-2717 (Unspecified vulnerability in Secure Elements Class 5 AVR client and ...)
4296 NOT-FOR-US: C5 EVM
4297 CVE-2006-2716 (Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 uses a ...)
4298 NOT-FOR-US: C5 EVM
4299 CVE-2006-2715 (The Administration Console in Secure Elements Class 5 AVR (aka C5 EVM) ...)
4300 NOT-FOR-US: C5 EVM
4301 CVE-2006-2714 (Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 does not ...)
4302 NOT-FOR-US: C5 EVM
4303 CVE-2006-2713 (Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 generates ...)
4304 NOT-FOR-US: C5 EVM
4305 CVE-2006-2712 (Secure Elements Class 5 AVR (aka C5 EVM) client and server before ...)
4306 NOT-FOR-US: C5 EVM
4307 CVE-2006-2711 (Secure Elements Class 5 AVR (aka C5 EVM) 2.8.1 and earlier, and ...)
4308 NOT-FOR-US: C5 EVM
4309 CVE-2006-2710 (Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 uses the same ...)
4310 NOT-FOR-US: C5 EVM
4311 CVE-2006-2709 (Secure Elements Class 5 AVR (aka C5 EVM) before 2.8.1 do not validate ...)
4312 NOT-FOR-US: C5 EVM
4313 CVE-2006-2708 (Secure Elements Class 5 AVR client (aka C5 EVM) before 2.8.1 allows ...)
4314 NOT-FOR-US: C5 EVM
4315 CVE-2006-2707 (Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 does not ...)
4316 NOT-FOR-US: C5 EVM
4317 CVE-2006-2706 (Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows ...)
4318 NOT-FOR-US: C5 EVM
4319 CVE-2006-2705 (Secure Elements Class 5 AVR server (aka C5 EVM) before 2.8.1 allows ...)
4320 NOT-FOR-US: C5 EVM
4321 CVE-2006-2704 (Secure Elements Class 5 AVR server and client (aka C5 EVM) before ...)
4322 NOT-FOR-US: C5 EVM
4323 CVE-2006-2703 (The RedCarpet command-line client (rug) does not verify SSL ...)
4324 NOT-FOR-US: RedCarpet
4325 CVE-2006-2702 (vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows ...)
4326 - wordpress 2.0.3-1 (bug #369014; medium)
4327 CVE-2006-2701 (SQL injection vulnerability in Geeklog 1.4.0sr2 and earlier allows ...)
4328 NOT-FOR-US: Geeklog
4329 CVE-2006-2700 (SQL injection vulnerability in admin/auth.inc.php in Geeklog 1.4.0sr2 ...)
4330 NOT-FOR-US: Geeklog
4331 CVE-2006-2699 (Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog ...)
4332 NOT-FOR-US: Geeklog
4333 CVE-2006-2698 (Geeklog 1.4.0sr2 and earlier allows remote attackers to obtain the ...)
4334 NOT-FOR-US: Geeklog
4335 CVE-2006-2697 (Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 ...)
4336 NOT-FOR-US: Easy-Content
4337 CVE-2006-2696 (Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 ...)
4338 NOT-FOR-US: Easy-Content
4339 CVE-2006-2695 (admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers ...)
4340 NOT-FOR-US: DGNews
4341 CVE-2006-2694 (Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro ...)
4342 NOT-FOR-US: EzUpload
4343 CVE-2006-2693 (Directory traversal vulnerability in admin_hacks_list.php in Nivisec ...)
4344 NOT-FOR-US: Nivisec
4345 CVE-2006-2692 (Multiple unspecified vulnerabilities in aMuleWeb for AMule before ...)
4346 - amule 2.1.2-1 (medium)
4347 CVE-2006-2691 (Unspecified &quot;information leakage&quot; vulnerabilities in aMuleWeb for ...)
4348 - amule 2.1.2-1 (medium)
4349 CVE-2006-2690 (An unspecified script in EVA-Web 2.1.2 and earlier, probably ...)
4350 NOT-FOR-US: EVA-Web
4351 CVE-2006-2689 (Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 ...)
4352 NOT-FOR-US: EVA-Web
4353 CVE-2006-2688 (SQL injection vulnerability in the employees node (class.employee.inc) ...)
4354 NOT-FOR-US: Achievo
4355 CVE-2006-2687 (Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC ...)
4356 NOT-FOR-US: AGTC
4357 CVE-2006-2686 (PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow ...)
4358 NOT-FOR-US: ActionApps
4359 CVE-2006-2685 (PHP remote file inclusion vulnerability in Basic Analysis and Security ...)
4360 - acidbase 1.2.5-1 (bug #370576; low)
4361 CVE-2006-2684 (Cross-site scripting (XSS) vulnerability in the search module in CMS ...)
4362 NOT-FOR-US: Mundo
4363 CVE-2006-2683 (PHP remote file inclusion vulnerability in 404.php in open-medium.CMS ...)
4364 NOT-FOR-US: open-medium
4365 CVE-2006-2682 (PHP remote file inclusion vulnerability in BE_config.php in Back-End ...)
4366 NOT-FOR-US: Back-End
4367 CVE-2006-2681 (PHP remote file inclusion vulnerability in SocketMail Lite and Pro ...)
4368 NOT-FOR-US: SocketMail
4369 CVE-2006-2680 (Cross-site scripting (XSS) vulnerability in index.php in AZ Photo ...)
4370 NOT-FOR-US: AZ Photo Album
4371 CVE-2006-2679 (Unspecified vulnerability in the VPN Client for Windows Graphical User ...)
4372 NOT-FOR-US: Cisco VPN Client
4373 CVE-2006-2678 (Multiple cross-site scripting (XSS) vulnerabilities in Pre News ...)
4374 NOT-FOR-US: Pre News Manager
4375 CVE-2006-2677 (SiteScape Forum 7.2 and possibly earlier stores the avf.rc ...)
4376 NOT-FOR-US: SiteScape Forum
4377 CVE-2006-2676 (Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly ...)
4378 NOT-FOR-US: SiteScape Forum
4379 CVE-2006-2675 (PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads ...)
4380 NOT-FOR-US: UBBThreads
4381 CVE-2006-2674 (Multiple SQL injection vulnerabilities in Tamber Forum 1.9.13 and ...)
4382 NOT-FOR-US: Tamber Forum
4383 CVE-2006-2673 (Cross-site scripting (XSS) vulnerability in search.html in Bulletin ...)
4384 NOT-FOR-US: Elite-Board
4385 CVE-2006-2672 (Multiple cross-site scripting (XSS) vulnerabilities in Realty Pro One ...)
4386 NOT-FOR-US: Realty Pro One
4387 CVE-2006-2671 (SQL injection vulnerability in ChatPat 1.0 allows remote attackers to ...)
4388 NOT-FOR-US: ChatPat
4389 CVE-2006-2670 (Multiple cross-site scripting (XSS) vulnerabilities in ChatPat 1.0 ...)
4390 NOT-FOR-US: ChatPat
4391 CVE-2006-2669 (Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping ...)
4392 NOT-FOR-US: Pre Shopping Mall
4393 CVE-2006-2668 (Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 ...)
4394 NOT-FOR-US: Docebo LMS
4395 CVE-2006-2667 (Direct static code injection vulnerability in WordPress 2.0.2 and ...)
4396 - wordpress 2.0.3-1 (bug #369014; medium)
4397 CVE-2006-2666 (PHP remote file inclusion vulnerability in ...)
4398 NOT-FOR-US: V-Webmail
4399 CVE-2006-2665 (PHP remote file inclusion vulnerability in ...)
4400 NOT-FOR-US: V-Webmail
4401 CVE-2006-2664 (Cross-site scripting (XSS) vulnerability in iFdate 1.2 allows remote ...)
4402 NOT-FOR-US: iFdate
4403 CVE-2006-2663 (Multiple cross-site scripting (XSS) vulnerabilities in iFlance 1.1 ...)
4404 NOT-FOR-US: iFlance
4405 CVE-2006-2662 (VMware Server before RC1 does not clear user credentials from memory ...)
4406 NOT-FOR-US: VMware Server
4407 CVE-2006-2661 (ftutil.c in Freetype before 2.2 allows remote attackers to cause a ...)
4408 {DSA-1095-1}
4409 - freetype 2.2.1-1 (medium)
4410 CVE-2006-2660 (Buffer consumption vulnerability in the tempnam function in PHP 5.1.4 ...)
4411 - php4 4:4.4.4-1 (low)
4412 [sarge] - php4 <no-dsa> (not worth an update, see NOTE by Sean)
4413 NOTE: using a long enough path (>MAXPATHLEN) allows you to have
4414 NOTE: tempnam create a file without the temp extension. sounds like
4415 NOTE: another shoot yourself in the foot issue, since the local user
4416 NOTE: could just as easily create the file manually, and if the
4417 NOTE: tempnam function is taking unsanitized input, it's an
4418 NOTE: application error
4419 - php5 5.1.6-1 (low)
4420 CVE-2006-2658
4421 RESERVED
4422 CVE-2006-2657
4423 REJECTED
4424 CVE-2006-2655 (The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally ...)
4425 NOT-FOR-US: FreeBSD
4426 CVE-2006-2654 (Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to ...)
4427 NOT-FOR-US: FreeBSD-specific (see CVE-2006-1864 for Linux-specific CVE)
4428 CVE-2006-2653 (Cross-site scripting (XSS) vulnerability in login_error.shtml for ...)
4429 NOT-FOR-US: D-Link
4430 CVE-2006-2652 (Cross-site scripting (XSS) vulnerability in WikiNi 0.4.2 and earlier ...)
4431 NOT-FOR-US: WikiNi
4432 CVE-2006-2651 (Cross-site scripting (XSS) vulnerability in index.php in Vacation ...)
4433 NOT-FOR-US: Vacation Rental Script
4434 CVE-2006-2650 (SQL injection vulnerability in cosmicshop/search.php in ...)
4435 NOT-FOR-US: CosmicShoppingCart
4436 CVE-2006-2649 (Multiple cross-site scripting (XSS) vulnerabilities in (a) search.php, ...)
4437 NOT-FOR-US: CosmicShoppingCart
4438 CVE-2006-2648 (Cross-site scripting (XSS) vulnerability in perform_search.asp for ...)
4439 NOT-FOR-US: ASPBB
4440 CVE-2006-2647 (Untrusted search path vulnerability in update_flash for IBM AIX 5.1, ...)
4441 NOT-FOR-US: IBM AIX
4442 CVE-2006-2646 (Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows ...)
4443 NOT-FOR-US: Alt-N MDaemon
4444 CVE-2006-2645 (PHP remote file inclusion vulnerability in ...)
4445 NOT-FOR-US: Plume
4446 CVE-2006-2644 (AWStats 6.5, and possibly other versions, allows remote authenticated ...)
4447 {DSA-1075-1}
4448 - awstats 6.5-2 (bug #365910)
4449 CVE-2006-XXXX [libxine1 overflow via a specially-crafted AVI file]
4450 - xine-lib 1.1.1-2 (bug #369876; medium)
4451 CVE-2006-XXXX [specialy crafted WAV turns mkvmerge into a malloc bomb]
4452 - mkvtoolnix 1.7.0-2 (bug #370144; low)
4453 CVE-2006-XXXX ['Cache' shell injection vulnerability]
4454 - wordpress 2.0.3-1 (high; bug #369014)
4455 CVE-2006-2753 (SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x ...)
4456 {DSA-1092-1}
4457 - mysql-dfsg <not-affected> (Vulnerable code was introduced in 4.1)
4458 - mysql <not-affected> (Vulnerable code was introduced in 4.1)
4459 - mysql-dfsg-5.0 5.0.22-1 (bug #369735; medium)
4460 - mysql-dfsg-4.1 <unfixed> (medium)
4461 CVE-2006-2659 (libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause ...)
4462 {DSA-1101}
4463 - courier 0.53.2-1 (bug #368834)
4464 CVE-2006-2656 (Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 ...)
4465 {DSA-1091-1}
4466 - tiff 3.8.2-3 (bug #369819; low)
4467 CVE-2006-2643 (Cross-site scripting (XSS) vulnerability in index.php in Monster Top ...)
4468 NOT-FOR-US: Monster Top List
4469 CVE-2006-2642 (** UNVERIFIABLE ** ...)
4470 NOT-FOR-US: Php-residence
4471 CVE-2006-2641 (** UNVERIFIABLE ** ...)
4472 NOT-FOR-US: John Frank Asset Manager
4473 CVE-2006-2640 (Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA ...)
4474 NOT-FOR-US: OMEGA INterneSErvicesLosungen (INSEL)
4475 CVE-2006-2639 (Cross-site scripting (XSS) vulnerability in the input forms in ...)
4476 NOT-FOR-US: PHPSimpleChoose
4477 CVE-2006-2638 (SQL injection vulnerability in member.asp in qjForum allows remote ...)
4478 NOT-FOR-US: qjForum
4479 CVE-2006-2637 (Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1) ...)
4480 NOT-FOR-US: TuttoPhp
4481 CVE-2006-2636 (newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to ...)
4482 NOT-FOR-US: Katy Whitton NewsCMSLite
4483 CVE-2006-2635 (Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka ...)
4484 - tikiwiki 1.9.4-1 (medium)
4485 CVE-2006-2634 (Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under ...)
4486 NOT-FOR-US: Neocrome Seditio
4487 CVE-2006-2633 (Absolute path traversal vulnerability in the copy action in index.php ...)
4488 NOT-FOR-US: Andrew Godwin ByteHoard
4489 CVE-2006-2632 (Cross-site scripting (XSS) vulnerability in Andrew Godwin ByteHoard ...)
4490 NOT-FOR-US: Andrew Godwin ByteHoard
4491 CVE-2006-2631 (phpFoX allows remote authenticated users to modify arbitrary accounts ...)
4492 NOT-FOR-US: phpFoX
4493 CVE-2006-2630 (Stack-based buffer overflow in Symantec Antivirus 10.1 and Client ...)
4494 NOT-FOR-US: Symantec
4495 CVE-2006-2629 (Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP ...)
4496 - linux-2.6 <unfixed> (low)
4497 - linux-2.6.16 <unfixed> (low)
4498 CVE-2006-2628
4499 RESERVED
4500 CVE-2006-2627
4501 RESERVED
4502 CVE-2006-2626
4503 RESERVED
4504 CVE-2006-2625
4505 RESERVED
4506 CVE-2006-2624
4507 RESERVED
4508 CVE-2006-2623
4509 RESERVED
4510 CVE-2006-2622
4511 RESERVED
4512 CVE-2006-2621
4513 RESERVED
4514 CVE-2006-2620
4515 RESERVED
4516 CVE-2006-2619
4517 RESERVED
4518 CVE-2006-2618 (Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host ...)
4519 NOT-FOR-US: AlstraSoft Web Host Directory
4520 CVE-2006-2617 ((1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost ...)
4521 NOT-FOR-US: AlstraSoft Web Host Directory
4522 CVE-2006-2616 (SQL injection vulnerability in the search script in (1) AlstraSoft Web ...)
4523 NOT-FOR-US: AlstraSoft Web Host Directory
4524 CVE-2006-2615 (ping.php in Russcom.Ping allows remote attackers to execute arbitrary ...)
4525 NOT-FOR-US: Russcom.Ping
4526 CVE-2006-2614 (Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 ...)
4527 NOT-FOR-US: Sun Solaris
4528 CVE-2006-2613 (Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other ...)
4529 NOTE: Installation path disclosure is uninteresting on Debian systems.
4530 NOTE: The profile path might be more sensitive, but exploit that
4531 NOTE: requires another, real security bug.
4532 CVE-2006-2612 (Novell Client for Windows 4.8 and 4.9 does not restrict access to the ...)
4533 NOT-FOR-US: Novell Client for Windows
4534 NOTE: The Windows clipboard is a public resource anyway.
4535 CVE-2006-2611 (Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in ...)
4536 - mediawiki <unfixed> (medium)
4537 CVE-2006-2610 (Cross-site scripting (XSS) vulnerability in view.php in phpRaid 2.9.5 ...)
4538 NOT-FOR-US: phpRaid
4539 CVE-2006-2609 (artmedic newsletter 4.1.2 and possibly other versions, when ...)
4540 NOT-FOR-US: artmedic newsletter
4541 CVE-2006-2608 (artmedic newsletter 4.1 and possibly other versions, when ...)
4542 NOT-FOR-US: artmedic newsletter
4543 CVE-2004-2660 (Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.10 allows ...)
4544 - linux-2.6 <not-affected> (fixed before the first upload)
4545 CVE-2003-1301 (Sun Java Runtime Environment (JRE) 1.x before 1.4.2_11 and 1.5.x ...)
4546 - sun-java5 1.5.0-06-1 (low; bug #384734)
4547 CVE-2006-XXXX [mono xsp file disclosure]
4548 - xsp 1.1.15-1 (medium)
4549 CVE-2006-2607 (do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return ...)
4550 - cron 3.0pl1-64 (bug #85609; bug #86775; medium)
4551 CVE-2006-2606 (Cross-site scripting (XSS) vulnerability in Chatty, possibly 1.0.2 and ...)
4552 NOT-FOR-US: Chatty
4553 CVE-2006-2605 (Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier ...)
4554 NOT-FOR-US: DSChat
4555 CVE-2006-2604
4556 REJECTED
4557 CVE-2006-2603
4558 REJECTED
4559 CVE-2006-2602
4560 REJECTED
4561 CVE-2006-2601
4562 REJECTED
4563 CVE-2006-2600
4564 REJECTED
4565 CVE-2006-2599
4566 REJECTED
4567 CVE-2006-2598
4568 REJECTED
4569 CVE-2006-2597
4570 REJECTED
4571 CVE-2006-2596
4572 REJECTED
4573 CVE-2006-2595
4574 REJECTED
4575 CVE-2006-2594
4576 REJECTED
4577 CVE-2006-2593
4578 REJECTED
4579 CVE-2006-2592 (Unspecified vulnerability in DSChat 1.0 allows remote attackers to ...)
4580 NOT-FOR-US: DSChat
4581 CVE-2006-2591 (Unspecified vulnerability in e107 before 0.7.5 has unknown impact and ...)
4582 NOT-FOR-US: e107
4583 CVE-2006-2590 (SQL injection vulnerability in e107 before 0.7.5 allows remote ...)
4584 NOT-FOR-US: e107
4585 CVE-2006-2589 (SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) ...)
4586 NOT-FOR-US: MyBB
4587 CVE-2006-2588 (Russcom PHPImages allows remote attackers to upload files of arbitrary ...)
4588 NOT-FOR-US: Russcom PHPImages
4589 CVE-2006-2587 (Buffer overflow in the WebTool HTTP server component in (1) PunkBuster ...)
4590 NOT-FOR-US: WebTool HTTP server
4591 CVE-2006-2586 (Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier ...)
4592 NOT-FOR-US: IpLogger
4593 CVE-2006-2585 (SQL injection vulnerability in Destiney Links Script 2.1.2 allows ...)
4594 NOT-FOR-US: Destiney Links Script
4595 CVE-2006-2584 (Multiple cross-site scripting (XSS) vulnerabilities in post.php in ...)
4596 NOT-FOR-US: SkyeBox
4597 CVE-2006-2583 (PHP remote file inclusion vulnerability in ...)
4598 NOT-FOR-US: Nucleus
4599 CVE-2006-2582 (The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote ...)
4600 NOT-FOR-US: RWiki
4601 CVE-2006-2581 (Cross-site scripting (XSS) vulnerability in Wiki content in RWiki ...)
4602 NOT-FOR-US: RWiki
4603 CVE-2005-4806 (Multiple unspecified vulnerabilities in Sun Java System Web Proxy ...)
4604 NOT-FOR-US: Sun Java System Web Proxy Server
4605 CVE-2005-4805 (Unspecified vulnerability in Sun Java System Application Server 7 ...)
4606 NOT-FOR-US: Sun Java System Application Server
4607 CVE-2005-4804 (Unspecified vulnerability in Sun Java System Application Server ...)
4608 NOT-FOR-US: Sun Java System Application Server
4609 CVE-2006-2580 (Multiple unspecified vulnerabilities in HP OpenView Network Node ...)
4610 NOT-FOR-US: HP OpenView Network Node Manager
4611 CVE-2006-2579 (Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 ...)
4612 NOT-FOR-US: HP OpenView Storage Data Protector
4613 CVE-2006-2578 (admin/cron.php in eSyndicat Directory 1.2, when register_globals is ...)
4614 NOT-FOR-US: eSyndicat Directory
4615 CVE-2006-2577 (Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and ...)
4616 NOT-FOR-US: Docebo
4617 CVE-2006-2576 (Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and ...)
4618 NOT-FOR-US: Docebo
4619 CVE-2006-2575 (The setFrame function in Lib/2D/Surface.hpp for NetPanzer 0.8 and ...)
4620 - netpanzer 0.8+svn20060319-2 (bug #370146; low)
4621 CVE-2006-2574 (Multiple unspecified vulnerabilities in Software Distributor in HP-UX ...)
4622 NOT-FOR-US: Software Distributor in HP-UX
4623 CVE-2006-2573 (SQL injection vulnerability in index.php in DGBook 1.0, with ...)
4624 NOT-FOR-US: DGBook
4625 CVE-2006-2572 (Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 ...)
4626 NOT-FOR-US: DGBook
4627 CVE-2006-2571 (Cross-site scripting (XSS) vulnerability in search.html in Alkacon ...)
4628 NOT-FOR-US: Alkacon OpenCms
4629 CVE-2006-2570 (PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 ...)
4630 NOT-FOR-US: CaLogic Calendars
4631 CVE-2006-2569 (SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and ...)
4632 NOT-FOR-US: Linklist
4633 CVE-2006-2568 (PHP remote file inclusion vulnerability in addpost_newpoll.php in ...)
4634 NOT-FOR-US: UBB.threads
4635 CVE-2006-2567 (Cross-site scripting (XSS) vulnerability in submit_article.php in ...)
4636 NOT-FOR-US: Alstrasoft Article Manager Pro
4637 CVE-2006-2566 (Alstrasoft Article Manager Pro 1.6 allows remote attackers to obtain ...)
4638 NOT-FOR-US: Alstrasoft Article Manager Pro
4639 CVE-2006-2565 (SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 ...)
4640 NOT-FOR-US: Alstrasoft Article Manager Pro
4641 CVE-2006-2564 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
4642 NOT-FOR-US: Alstrasoft Article Manager Pro
4643 CVE-2006-2563 (The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to ...)
4644 - php4 4:4.4.4-1 (bug #370166; low)
4645 [sarge] - php4 <no-dsa> (Safe mode violations not supported)
4646 - php5 5.1.6-1 (bug #370165; low)
4647 CVE-2006-2562 (ZyXEL P-335WT router allows remote attackers to bypass access ...)
4648 NOT-FOR-US: ZyXEL P-335WT router
4649 CVE-2006-2561 (Edimax BR-6104K router allows remote attackers to bypass access ...)
4650 NOT-FOR-US: Edimax BR-6104K router
4651 CVE-2006-2560 (Sitecom WL-153 router firmware before 1.38 allows remote attackers to ...)
4652 NOT-FOR-US: Sitecom WL-153 router
4653 CVE-2006-2559 (Linksys WRT54G Wireless-G Broadband Router allows remote attackers to ...)
4654 NOT-FOR-US: Linksys WRT54G router
4655 CVE-2006-2558 (Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier ...)
4656 NOT-FOR-US: IpLogger
4657 CVE-2006-2557 (PHP remote file inclusion vulnerability in extras/poll/poll.php in ...)
4658 NOT-FOR-US: newsportal
4659 NOTE: RFP #149069 closed after no activity since too long time
4660 CVE-2006-2556 (Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal ...)
4661 NOT-FOR-US: newsportal
4662 NOTE: RFP #149069 closed after no activity since too long time
4663 CVE-2006-2555 (The parse_command function in Genecys 0.2 and earlier allows remote ...)
4664 NOT-FOR-US: Genecys
4665 CVE-2006-2554 (Buffer overflow in the tell_player_surr_changes function in Genecys ...)
4666 NOT-FOR-US: Genecys
4667 CVE-2006-2553 (Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl ...)
4668 NOT-FOR-US: DownloadControl
4669 CVE-2006-2552 (Jemscripts DownloadControl 1.0 allows remote attackers to obtain ...)
4670 NOT-FOR-US: DownloadControl
4671 CVE-2006-2551 (Unspecified vulnerability in the kernel in HP-UX B.11.00 allows local ...)
4672 NOT-FOR-US: HP-UX
4673 CVE-2002-2213 (The DNS resolver in unspecified versions of Infoblox DNS One, when ...)
4674 NOT-FOR-US: Infoblox DNS One
4675 CVE-2002-2212 (The DNS resolver in unspecified versions of Fujitsu UXP/V, when ...)
4676 NOT-FOR-US: Fujitsu UXP/V
4677 CVE-2002-2211 (BIND 4 and BIND 8, when resolving recursive DNS queries for arbitrary ...)
4678 - bind <unfixed> (medium)
4679 [sarge] - bind <no-dsa> (Upgrade to BIND 9 as a fix)
4680 - bind9 <not-affected> (does not send parallel queries)
4681 NOTE: Disabling recursion does not close all attack vectors.
4682 NOTE: Browser reflection attacks will still work.
4683 CVE-2006-2550 (perlpodder before 0.5 allows remote attackers to execute arbitrary ...)
4684 NOT-FOR-US: perlpodder
4685 CVE-2006-2549 (Stack-based buffer overflow in PDF Form Filling and Flattening Tool ...)
4686 NOT-FOR-US: PDF Form Filling and Flattening Tool
4687 CVE-2006-2548 (Prodder before 0.5, and perlpodder before 0.5, allows remote attackers ...)
4688 NOT-FOR-US: prodder/perlpodder
4689 CVE-2006-2547 (Unspecified vulnerability in the sapdba command in SAP with Informix ...)
4690 NOT-FOR-US: Sap
4691 CVE-2006-2546 (A recommended admin password reset mechanism for BEA WebLogic Server ...)
4692 NOT-FOR-US: BEA
4693 CVE-2006-2545 (Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites ...)
4694 NOT-FOR-US: Xtreme Topsites
4695 CVE-2006-2544 (Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with ...)
4696 NOT-FOR-US: Xtreme Topsites
4697 CVE-2006-2543 (Xtreme Topsites 1.1 allows remote attackers to trigger MySQL errors ...)
4698 NOT-FOR-US: Xtreme Topsites
4699 CVE-2006-2542 (xmcdconfig in xmcd for Debian GNU/Linux 2.6-17.1 creates /var/lib/cddb ...)
4700 {DSA-1086-1}
4701 - xmcd 2.6-17.2 (bug #366816; medium)
4702 CVE-2006-2541 (SQL injection vulnerability in settings.asp in Zixforum 1.12 allows ...)
4703 NOT-FOR-US: Zixforum
4704 CVE-2006-2540 (Privacy leak in install.php for Diesel PHP Job Site sends sensitive ...)
4705 NOT-FOR-US: Diesel
4706 CVE-2006-2539 (Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, ...)
4707 NOT-FOR-US: Sybase
4708 CVE-2006-2538 (IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote ...)
4709 NOT-FOR-US: Windows-only Firefox plugin
4710 CVE-2006-2537 (Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and ...)
4711 NOT-FOR-US: *BOR
4712 CVE-2006-2536 (Cross-site scripting (XSS) vulnerability in Destiney Links Script ...)
4713 NOT-FOR-US: Destiney
4714 CVE-2006-2535 (index.php in Destiney Links Script 2.1.2 allows remote attackers to ...)
4715 NOT-FOR-US: Destiney
4716 CVE-2006-2534 (Destiney Links Script 2.1.2 does not protect library and other support ...)
4717 NOT-FOR-US: Destiney
4718 CVE-2006-2533 (Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2) ...)
4719 NOT-FOR-US: Destiney
4720 CVE-2006-2532 (stats.php in Destiney Rated Images Script 0.5.0 allows remote ...)
4721 NOT-FOR-US: Destiney
4722 CVE-2006-2531 (Ipswitch WhatsUp Professional 2006 only verifies the users identity ...)
4723 NOT-FOR-US: Ipswitch
4724 CVE-2006-2530 (avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly ...)
4725 NOT-FOR-US: Snitz mod
4726 CVE-2006-2529 (editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, ...)
4727 - knowledgeroot <not-affected> (fixed before first upload; see bug #381912)
4728 CVE-2006-2528 (PHP remote file inclusion vulnerability in classified_right.php in ...)
4729 NOT-FOR-US: phpBazar
4730 CVE-2006-2527 (Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers ...)
4731 NOT-FOR-US: phpBazar
4732 CVE-2006-2526 (PHP remote file inclusion vulnerability in index.php in PHP Easy ...)
4733 NOT-FOR-US: PHP Easy Galerie
4734 CVE-2006-2525 (SQL injection vulnerability in UseBB 1.0 RC1 and earlier allows remote ...)
4735 NOT-FOR-US: UseBB
4736 CVE-2006-2524 (Cross-site scripting (XSS) vulnerability in UseBB 1.0 RC1 and earlier ...)
4737 NOT-FOR-US: UseBB
4738 CVE-2006-2523 (PHP remote file inclusion vulnerability in config.php in phpListPro ...)
4739 NOT-FOR-US: phpListPro
4740 CVE-2006-2522 (Dayfox Blog 2.0 and earlier stores user credentials in ...)
4741 NOT-FOR-US: Dayfox
4742 CVE-2006-2521 (PHP remote file inclusion vulnerability in cron.php in phpMyDirectory ...)
4743 NOT-FOR-US: phpMyDirectory
4744 CVE-2006-2520 (Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier ...)
4745 NOT-FOR-US: BitZipper
4746 CVE-2006-2519 (Directory traversal vulnerability in ...)
4747 NOT-FOR-US: phpwcms
4748 CVE-2006-2518 (Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows ...)
4749 NOT-FOR-US: phpwcms
4750 CVE-2006-2517 (SQL injection vulnerability in MyWeb Portal Office, Standard Edition, ...)
4751 NOT-FOR-US: MyWeb
4752 CVE-2006-2516 (mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is ...)
4753 NOT-FOR-US: XOOPS
4754 CVE-2006-2515 (Cross-site scripting (XSS) vulnerability in index.php in Hiox ...)
4755 NOT-FOR-US: Hiox
4756 CVE-2006-2514 (Coppermine galleries before 1.4.6, when running on Apache with ...)
4757 NOT-FOR-US: Coppermine
4758 CVE-2006-2513 (Unspecified vulnerability in the installation process in Sun Java ...)
4759 NOT-FOR-US: Sun
4760 CVE-2006-2512 (SQL injection vulnerability in Hitachi EUR Professional Edition, EUR ...)
4761 NOT-FOR-US: Hitachi
4762 CVE-2006-2511 (The ActiveX version of FrontRange iHEAT allows remote authenticated ...)
4763 NOT-FOR-US: FrontRange
4764 CVE-2006-2510 (Cross-site scripting (XSS) vulnerability in the URL submission form in ...)
4765 NOT-FOR-US: YourFreeWorld.com
4766 CVE-2006-2509 (SQL injection vulnerability in login.php in YourFreeWorld.com Short ...)
4767 NOT-FOR-US: YourFreeWorld.com
4768 CVE-2006-2508 (SQL injection vulnerability in tr1.php in YourFreeWorld.com Stylish ...)
4769 NOT-FOR-US: YourFreeWorld.com
4770 CVE-2006-2507 (Multiple PHP remote file inclusion vulnerabilities in Teake Nutma ...)
4771 NOT-FOR-US: phpbb2 mod
4772 CVE-2006-2506 (Multiple cross-site scripting (XSS) vulnerabilities in search.php in ...)
4773 NOT-FOR-US: Sphider
4774 CVE-2006-2505 (Oracle Database Server 10g Release 2 allows local users to execute ...)
4775 NOT-FOR-US: Oracle
4776 CVE-2006-2504 (Multiple SQL injection vulnerabilities in mono AZBOARD 1.0 and earlier ...)
4777 NOT-FOR-US: AZBOARD
4778 CVE-2006-2503 (SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote ...)
4779 NOT-FOR-US: DeluxeBB
4780 CVE-2006-2502 (Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) ...)
4781 - cyrus-imapd-2.2 <not-affected> (Vulnerable code not present)
4782 CVE-2006-2501 (Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 ...)
4783 NOT-FOR-US: Sun
4784 CVE-2006-2500 (Cross-site scripting (XSS) vulnerability in add_news.asp in ...)
4785 NOT-FOR-US: CodeAvalanche News
4786 CVE-2006-2499 (SQL injection vulnerability in default.asp in CodeAvalanche News ...)
4787 NOT-FOR-US: CodeAvalanche News
4788 CVE-2006-2498 (Invision Power Board (IPB) before 2.1.6 allows remote attackers to ...)
4789 NOT-FOR-US: Invision
4790 CVE-2006-2497 (Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 ...)
4791 NOT-FOR-US: AspBB
4792 CVE-2006-2496 (Buffer overflow in iMonitor 2.4 in Novell eDirectory 8.8 allows remote ...)
4793 NOT-FOR-US: Novell
4794 CVE-2006-2495 (Cross-site request forgery (CSRF) vulnerability in the Entry Manager ...)
4795 - serendipity 1.0-1
4796 CVE-2006-2494 (Stack-based buffer overflow in IntelliTamper 2.07 allows remote ...)
4797 NOT-FOR-US: IntelliTampe
4798 CVE-2006-2493
4799 REJECTED
4800 CVE-2005-1755 (PHP remote code injection vulnerability in poll_vote.php in PHP Poll ...)
4801 NOT-FOR-US: PHP Poll Creator
4802 CVE-2005-1754 (JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, ...)
4803 NOT-FOR-US: JavaMail API
4804 NOTE: vulnerable file not in Debian
4805 CVE-2005-1753 (ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache ...)
4806 NOT-FOR-US: JavaMail API
4807 NOTE: vulnerable file not in Debian
4808 CVE-2005-1752 (viewFile.php in the scm component of Gforge before 4.0 allows remote ...)
4809 - gforge 3.1-30
4810 NOTE: viewFile.php disabled in 3.1-30
4811 CVE-2006-2492 (Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, ...)
4812 NOT-FOR-US: Microsoft
4813 CVE-2006-2491 (Cross-site scripting (XSS) vulnerability in (1) index.php and (2) ...)
4814 NOT-FOR-US: BoastMachine
4815 CVE-2006-2490 (Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP ...)
4816 NOT-FOR-US: Mobotix
4817 CVE-2006-2489 (Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x ...)
4818 {DSA-1072-1}
4819 - nagios 2:1.4-1 (bug #366682; bug #366803; high)
4820 - nagios2 2.3-1 (bug #366683; high)
4821 CVE-2006-2488 (Multiple cross-site scripting (XSS) vulnerabilities in Spymac WebOS ...)
4822 NOT-FOR-US: Spymac
4823 CVE-2006-2487 (Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 ...)
4824 NOT-FOR-US: ScozNews
4825 CVE-2006-2486 (SQL injection vulnerability in find.php in YapBB 1.2 Beta2 and earlier ...)
4826 NOT-FOR-US: YapBB
4827 CVE-2006-2485 (PHP remote file inclusion vulnerability in includes/class_template.php ...)
4828 NOT-FOR-US: Quezza
4829 CVE-2006-2484 (Cross-site scripting (XSS) vulnerability in index.html in IceWarp ...)
4830 NOT-FOR-US: IceWarp
4831 CVE-2006-2483 (PHP remote file inclusion vulnerability in cart_content.php in ...)
4832 NOT-FOR-US: Squirrelcart
4833 CVE-2006-2482
4834 RESERVED
4835 CVE-2006-2481 (VMware ESX Server 2.0.x before 2.0.2 and 2.x before 2.5.2 patch 4 ...)
4836 NOT-FOR-US: VMware ESX
4837 CVE-2006-2480 (Format string vulnerability in Dia 0.94 allows user-assisted ...)
4838 - dia 0.95.0-4 (bug #368202; low)
4839 [sarge] - dia <no-dsa> (Hardly exploitable, would require obviously malformed file names)
4840 CVE-2006-2479 (The Update functionality in Bitrix Site Manager 4.1.x does not verify ...)
4841 NOT-FOR-US: Bitrix
4842 CVE-2006-2478 (Bitrix Site Manager 4.1.x allows remote attackers to redirect users to ...)
4843 NOT-FOR-US: Bitrix
4844 CVE-2006-2477 (Cross-site scripting (XSS) vulnerability in the administrative ...)
4845 NOT-FOR-US: Bitrix
4846 CVE-2006-2476 (Bitrix Site Manager 4.1.x stores updater.log under the web document ...)
4847 NOT-FOR-US: Bitrix
4848 CVE-2006-2475 (Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) ...)
4849 NOT-FOR-US: Cosmoshop
4850 CVE-2006-2474 (SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and ...)
4851 NOT-FOR-US: Cosmoshop
4852 CVE-2006-2473 (Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 ...)
4853 NOT-FOR-US: OpenWiki
4854 CVE-2006-2472 (Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 ...)
4855 NOT-FOR-US: BEA
4856 CVE-2006-2471 (Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 ...)
4857 NOT-FOR-US: BEA
4858 CVE-2006-2470 (Unspecified vulnerability in the WebLogic Server Administration ...)
4859 NOT-FOR-US: BEA
4860 CVE-2006-2469 (The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to ...)
4861 NOT-FOR-US: BEA
4862 CVE-2006-2468 (The WebLogic Server Administration Console in BEA WebLogic Server 8.1 ...)
4863 NOT-FOR-US: BEA
4864 CVE-2006-2467 (BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 ...)
4865 NOT-FOR-US: BEA
4866 CVE-2006-2466 (BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote ...)
4867 NOT-FOR-US: BEA
4868 CVE-2006-2465 (Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary ...)
4869 - mp3info 0.8.4-9.1 (bug #368207; low)
4870 [sarge] - mp3info <no-dsa> (Hardly exploitable)
4871 CVE-2006-2464 (stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and ...)
4872 NOT-FOR-US: BEA
4873 CVE-2006-2463 (view_album.php in SelectaPix 1.31 and earlier allows remote attackers ...)
4874 NOT-FOR-US: SelectaPix
4875 CVE-2006-2462 (BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service ...)
4876 NOT-FOR-US: BEA
4877 CVE-2006-2461 (BEA WebLogic Server before 8.1 Service Pack 4 does not properly set ...)
4878 NOT-FOR-US: BEA
4879 CVE-2006-2460 (Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when ...)
4880 NOT-FOR-US: SugarCRM
4881 CVE-2006-2459 (SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and ...)
4882 NOT-FOR-US: PHP-Fusion
4883 CVE-2006-2458 (Multiple heap-based buffer overflows in Libextractor 0.5.13 and ...)
4884 {DSA-1081-1}
4885 - libextractor 0.5.14-1
4886 CVE-2006-2457
4887 RESERVED
4888 CVE-2006-2456
4889 RESERVED
4890 CVE-2006-2455
4891 RESERVED
4892 CVE-2006-2454
4893 RESERVED
4894 CVE-2006-2453 (Multiple unspecified format string vulnerabilities in Dia have ...)
4895 - dia 0.95.0-4 (bug #368202; medium)
4896 [sarge] - dia <no-dsa> (Hardly exploitable, would require obviously malformed file names)
4897 CVE-2006-2452 (GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the &quot;face browser&quot; feature ...)
4898 - gdm <unfixed> (bug #375281; medium)
4899 [sarge] - gdm <not-affected> (Vulnerable code has only been introduced with 2.8)
4900 CVE-2006-2451 (The suid_dumpable support in Linux kernel 2.6.13 up to versions before ...)
4901 - linux-2.6 2.6.17-3 (high)
4902 - linux-2.6.16 2.6.16-17 (high)
4903 CVE-2006-2450 (auth.c in LibVNCServer 0.7.1 allows remote attackers to bypass ...)
4904 - libvncserver 0.8.2-1 (high; bug #376824)
4905 CVE-2006-2449 (KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users ...)
4906 {DSA-1156}
4907 - kdebase 4:3.5.2-2 (bug #374002; medium)
4908 CVE-2006-2448 (Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, ...)
4909 - linux-2.6 2.6.16-15
4910 CVE-2006-2447 (SpamAssassin before 3.1.3, when running with vpopmail and the paranoid ...)
4911 {DSA-1090-1}
4912 - spamassassin 3.1.3-1 (medium)
4913 CVE-2006-2446 (Race condition between the kfree_skb and __skb_unlink functions in the ...)
4914 TODO: check
4915 CVE-2006-2445 (Race condition in run_posix_cpu_timers in Linux kernel before ...)
4916 - linux-2.6 2.6.16-15
4917 CVE-2006-2444 (The snmp_trap_decode function in the SNMP NAT helper for Linux kernel ...)
4918 - linux-2.6 2.6.16-15
4919 CVE-2006-2442 (kphone 4.2 creates .qt/kphonerc with world-readable permissions, which ...)
4920 {DSA-1062-1}
4921 - kphone 1:4.2-3 (bug #337830; medium)
4922 CVE-2006-2439 (Stack-based buffer overflow in ZipCentral 4.01 allows remote ...)
4923 NOT-FOR-US: ZipCentral
4924 CVE-2006-2438 (Directory traversal vulnerability in the viewfile servlet in the ...)
4925 NOT-FOR-US: Caucho
4926 CVE-2006-2437 (The viewfile servlet in the documentation package (resin-doc) for ...)
4927 NOT-FOR-US: Caucho
4928 CVE-2006-2436 (WebSphere Application Server 5.0.2 (or any earlier cumulative fix) ...)
4929 NOT-FOR-US: IBM
4930 CVE-2006-2435 (Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 ...)
4931 NOT-FOR-US: IBM
4932 CVE-2006-2434 (Unspecified vulnerability in WebSphere 5.1.1 (or any earlier ...)
4933 NOT-FOR-US: IBM
4934 CVE-2006-2433 (Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, ...)
4935 NOT-FOR-US: IBM
4936 CVE-2006-2432 (IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) ...)
4937 NOT-FOR-US: IBM
4938 CVE-2006-2431 (Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 ...)
4939 NOT-FOR-US: IBM
4940 CVE-2006-2430 (IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, ...)
4941 NOT-FOR-US: IBM
4942 CVE-2006-2429 (Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, ...)
4943 NOT-FOR-US: IBM
4944 CVE-2006-2428 (add.asp in DUware DUbanner 3.1 allows remote attackers to execute ...)
4945 NOT-FOR-US: Duware
4946 CVE-2006-2427 (freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h ...)
4947 - clamav <not-affected> (clamav-freshclam doesn't ship freshclam setuid or setgid)
4948 CVE-2006-2426 (Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 ...)
4949 - sun-java5 <unfixed>
4950 CVE-2006-2425 (Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in ...)
4951 NOT-FOR-US: phpRemoteView
4952 CVE-2006-2424 (PHP remote file inclusion vulnerability in ezUserManager 1.6 and ...)
4953 NOT-FOR-US: ezUserManager
4954 CVE-2006-2423 (Cross-site scripting (XSS) vulnerability in ftplogin/index.php in ...)
4955 NOT-FOR-US: Confixx
4956 CVE-2006-2422 (phpCOIN 1.2.3 and earlier stores messages based upon e-mail addresses, ...)
4957 NOT-FOR-US: phpCOIN
4958 CVE-2006-2421 (Stack-based buffer overflow in Pragma FortressSSH 4.0.7.20 allows ...)
4959 NOT-FOR-US: Pragma
4960 CVE-2006-2420 (Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows ...)
4961 NOTE: "this issue normally would not be included in CVE, it is being identified since the Bugzilla developers have addressed it."
4962 - bugzilla <unfixed> (unimportant)
4963 CVE-2006-2419 (Cross-site scripting (XSS) vulnerability in index.php in Directory ...)
4964 NOT-FOR-US: Directory Listing Script
4965 CVE-2006-2418 (Cross-site scripting (XSS) vulnerabilities in certain versions of ...)
4966 - phpmyadmin 4:2.8.1-1 (bug #368082; medium)
4967 CVE-2006-2417 (Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.x before ...)
4968 - phpmyadmin 4:2.8.1-1 (bug #368082; medium)
4969 [sarge] - phpmyadmin <not-affected> (Vulnerable code not present)
4970 CVE-2006-2416 (SQL injection vulnerability in class2.php in e107 0.7.2 and earlier ...)
4971 NOT-FOR-US: e107
4972 CVE-2006-2415 (Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0 ...)
4973 NOT-FOR-US: FlexChat
4974 CVE-2006-2414 (Directory traversal vulnerability in Dovecot 1.0 beta and 1.0 allows ...)
4975 {DSA-1080-1}
4976 - dovecot 1.0.beta8-1 (low)
4977 [sarge] - dovecot <not-affected> (vulnerability introduced in 1.0)
4978 CVE-2006-2413 (GNUnet before SVN revision 2781 allows remote attackers to cause a ...)
4979 - gnunet 0.7.0e-1 (bug #368159; medium)
4980 [sarge] - gnunet <not-affected> (according to maintainer)
4981 CVE-2006-2412 (The raydium_network_read function in network.c in Raydium SVN revision ...)
4982 NOT-FOR-US: Raydium
4983 CVE-2006-2411 (Buffer overflow in raydium_network_read function in network.c in ...)
4984 NOT-FOR-US: Raydium
4985 CVE-2006-2410 (raydium_network_netcall_exec function in network.c in Raydium SVN ...)
4986 NOT-FOR-US: Raydium
4987 CVE-2006-2409 (Format string vulnerability in the raydium_log function in console.c ...)
4988 NOT-FOR-US: Raydium
4989 CVE-2006-2408 (Multiple buffer overflows in Raydium before SVN revision 310 allow ...)
4990 NOT-FOR-US: Raydium
4991 CVE-2006-2407 (Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX ...)
4992 NOT-FOR-US: ActiveX component
4993 CVE-2006-2406 (Directory traversal vulnerability in bb_lib/abbc.css.php in ...)
4994 NOT-FOR-US: Unclassified NewsBoard
4995 CVE-2006-2405 (Directory traversal vulnerability in unb_lib/abbc.conf.php in ...)
4996 NOT-FOR-US: Unclassified NewsBoard
4997 CVE-2006-2404 (Directory traversal vulnerability in popup.php in RadScripts RadLance ...)
4998 NOT-FOR-US: RadScripts
4999 CVE-2006-2403 (Buffer overflow in FileZilla before 2.2.23 allows remote attackers to ...)
5000 NOT-FOR-US: FileZilla
5001 CVE-2006-2402 (Buffer overflow in the changeRegistration function in servernet.cpp ...)
5002 NOT-FOR-US: Outgun
5003 CVE-2006-2401 (The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and ...)
5004 NOT-FOR-US: Outgun
5005 CVE-2006-2400 (The leetnet functions (leetnet/rudp.cpp) in Outgun 1.0.3 bot 2 and ...)
5006 NOT-FOR-US: Outgun
5007 CVE-2006-2399 (Stack-based buffer overflow in the ...)
5008 NOT-FOR-US: Outgun
5009 CVE-2006-2398 (Directory traversal vulnerability in index.php in GPhotos 1.5 and ...)
5010 NOT-FOR-US: GPhotos web gallery
5011 CVE-2006-2397 (Multiple cross-site scripting (XSS) vulnerabilities in GPhotos 1.5 and ...)
5012 NOT-FOR-US: GPhotos web gallery
5013 CVE-2006-2396 (Cross-site scripting (XSS) vulnerability in phpODP 1.5h allows remote ...)
5014 NOT-FOR-US: phpODP
5015 CVE-2006-2395 (PHP remote file inclusion vulnerability in ...)
5016 NOT-FOR-US: PopPhoto
5017 CVE-2006-2394 (Cross-site scripting (XSS) vulnerability in chat.php in PHP Live ...)
5018 NOT-FOR-US: PHP Live Support
5019 CVE-2006-2393 (The client_cmd function in Empire 4.3.2 and earlier allows remote ...)
5020 NOT-FOR-US: Debian's 'empire' is a different game
5021 CVE-2006-2392 (PHP remote file inclusion vulnerability in ...)
5022 NOT-FOR-US: PHP Blue Dragon Platinum
5023 CVE-2006-2391 (Buffer overflow in EMC Retrospect Client 5.1 through 7.5 allows remote ...)
5024 NOT-FOR-US: EMC Retrospect
5025 CVE-2006-2390 (Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows ...)
5026 NOT-FOR-US: OZJournals
5027 CVE-2006-2389 (Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office ...)
5028 NOT-FOR-US: Microsoft
5029 CVE-2006-2388 (Microsoft Office Excel 2000 through 2004 allows user-assisted ...)
5030 NOT-FOR-US: Microsoft
5031 CVE-2006-2387
5032 RESERVED
5033 CVE-2006-2386
5034 RESERVED
5035 CVE-2006-2385 (Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and ...)
5036 NOT-FOR-US: Microsoft
5037 CVE-2006-2384 (Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows ...)
5038 NOT-FOR-US: Microsoft
5039 CVE-2006-2383 (Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and ...)
5040 NOT-FOR-US: Microsoft
5041 CVE-2006-2382 (Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and ...)
5042 NOT-FOR-US: Microsoft
5043 CVE-2006-2381
5044 RESERVED
5045 CVE-2006-2380 (Microsoft Windows 2000 SP4 does not properly validate an RPC server ...)
5046 NOT-FOR-US: Microsoft
5047 CVE-2006-2379 (Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows ...)
5048 NOT-FOR-US: Microsoft
5049 CVE-2006-2378 (Buffer overflow in the ART Image Rendering component (jgdw400.dll) in ...)
5050 NOT-FOR-US: Microsoft
5051 CVE-2006-2377
5052 RESERVED
5053 CVE-2006-2376 (Heap-based buffer overflow in the PolyPolygon function in Graphics ...)
5054 NOT-FOR-US: Microsoft
5055 CVE-2006-2375
5056 RESERVED
5057 CVE-2006-2374 (The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft ...)
5058 NOT-FOR-US: Microsoft
5059 CVE-2006-2373 (The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft ...)
5060 NOT-FOR-US: Microsoft
5061 CVE-2006-2372 (Buffer overflow in the DHCP Client service for Microsoft Windows 2000 ...)
5062 NOT-FOR-US: Microsoft
5063 CVE-2006-2371 (Buffer overflow in the Remote Access Connection Manager service ...)
5064 NOT-FOR-US: Microsoft
5065 CVE-2006-2370 (Buffer overflow in the Routing and Remote Access service (RRAS) in ...)
5066 NOT-FOR-US: Microsoft
5067 CVE-2006-2369 (RealVNC 4.1.1, and other products that use RealVNC such as AdderLink ...)
5068 - vnc4 4.1.1+X4.3.0-10 (high)
5069 [sarge] - vnc4 <not-affected> (vuln not in 4.0)
5070 CVE-2006-2368 (Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka ...)
5071 NOT-FOR-US: Clansys
5072 CVE-2006-2367 (Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka ...)
5073 NOT-FOR-US: Clansys
5074 CVE-2006-2366 (ircp_io.c in libopenobex for ircp 1.2, when ircp is run with the -r ...)
5075 - libopenobex 1.2-3 (bug #366484)
5076 CVE-2006-2365 (Cross-site scripting (XSS) vulnerability in a_login.php in Vizra ...)
5077 NOT-FOR-US: Vizra
5078 CVE-2006-2364 (Cross-site scripting (XSS) vulnerability in the validation feature in ...)
5079 NOT-FOR-US: Macromedia
5080 CVE-2006-2363 (SQL injection vulnerability in the weblinks option (weblinks.html.php) ...)
5081 NOT-FOR-US: Limbo
5082 CVE-2006-2362 (Buffer overflow in getsym in tekhex.c in libbfd in Free Software ...)
5083 - binutils 2.17-1 (bug #368237)
5084 CVE-2006-2361 (PHP remote file inclusion vulnerability in pafiledb_constants.php in ...)
5085 NOT-FOR-US: phpbb mod
5086 CVE-2006-2360 (SQL injection vulnerability in charts.php in the Chart mod for phpBB ...)
5087 NOT-FOR-US: phpbb mod
5088 CVE-2006-2359 (Cross-site scripting (XSS) vulnerability in charts.php in the Chart ...)
5089 NOT-FOR-US: phpbb mod
5090 CVE-2006-2192
5091 RESERVED
5092 CVE-2005-4803 (graphviz before 2.2.1 allows local users to overwrite arbitrary files ...)
5093 {DSA-857-1}
5094 - graphviz 2.2.1-1sarge1 (bug #336985; low)
5095 CVE-2005-4802 (Flexbackup 1.2.1 and earlier allows local users to overwrite files and ...)
5096 - flexbackup <unfixed> (bug #334350; low)
5097 CVE-2005-4801 (Multiple cross-site request forgery (CSRF) vulnerabilities in Yet ...)
5098 NOT-FOR-US: YaPIG
5099 CVE-2005-4800 (Direct static code injection vulnerability in Yet Another PHP Image ...)
5100 NOT-FOR-US: YaPIG
5101 CVE-2005-4799 (Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP ...)
5102 NOT-FOR-US: YaPIG
5103 CVE-2006-2358 (Multiple cross-site scripting (XSS) vulnerabilities in various scripts ...)
5104 NOT-FOR-US: Web Labs CMS
5105 CVE-2006-2357 (Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 ...)
5106 NOT-FOR-US: Ipswitch WhatsUp
5107 CVE-2006-2356 (NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 ...)
5108 NOT-FOR-US: Ipswitch WhatsUp
5109 CVE-2006-2355 (Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional ...)
5110 NOT-FOR-US: Ipswitch WhatsUp
5111 CVE-2006-2354 (NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch ...)
5112 NOT-FOR-US: Ipswitch WhatsUp
5113 CVE-2006-2353 (NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 ...)
5114 NOT-FOR-US: Ipswitch WhatsUp
5115 CVE-2006-2352 (Multiple cross-site scripting (XSS) vulnerabilities in IPswitch ...)
5116 NOT-FOR-US: Ipswitch WhatsUp
5117 CVE-2006-2351 (Multiple cross-site scripting (XSS) vulnerabilities in IPswitch ...)
5118 NOT-FOR-US: Ipswitch WhatsUp
5119 CVE-2006-2350 (SQL injection vulnerability in the inc/elementz.php script in AliPAGER ...)
5120 NOT-FOR-US: AliPAGER
5121 CVE-2006-2349 (E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to ...)
5122 NOT-FOR-US: E-Business Designer
5123 CVE-2006-2348 (Cross-site scripting (XSS) vulnerability in form_grupo.html in ...)
5124 NOT-FOR-US: E-Business Designer
5125 CVE-2006-2347 (E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to ...)
5126 NOT-FOR-US: E-Business Designer
5127 CVE-2006-2346 (vpopmail 5.4.14 and 5.4.15, with cleartext passwords enabled, allows ...)
5128 - vpopmail <not-affected> (vulnerability introduced in 5.4.14)
5129 NOTE: Unable to reach CVS to determine if prior versions are affected
5130 NOTE: Micah will return to this one
5131 CVE-2006-2345 (Cross-site scripting (XSS) vulnerability in inc/elementz.php in ...)
5132 NOT-FOR-US: AliPAGER
5133 CVE-2006-2344 (SQL injection vulnerability in inc/elementz.php in AliPAGER 1.5, with ...)
5134 NOT-FOR-US: AliPAGER
5135 CVE-2006-2343 (Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine ...)
5136 NOT-FOR-US: ManageEngine OpManager
5137 CVE-2006-2342 (IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote ...)
5138 NOT-FOR-US: IBM WebSphere Application Server
5139 CVE-2006-2341 (The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, ...)
5140 NOT-FOR-US: Symantec Gateway Security
5141 CVE-2006-2340 (Cross-site scripting (XSS) vulnerability in PassMasterFlex and ...)
5142 NOT-FOR-US: PassMasterFlex
5143 CVE-2006-2339 (SQL injection vulnerability in index.php in evoTopsites 2.x and ...)
5144 NOT-FOR-US: evoTopsites
5145 CVE-2006-2338 (PlaNet Concept plaNetStat 20050127 allows remote attackers to gain ...)
5146 NOT-FOR-US: PlaNet
5147 CVE-2006-2337 (Directory traversal vulnerability in webcm in the D-Link DSL-G604T ...)
5148 NOT-FOR-US: D-Link
5149 CVE-2006-2336 (SQL injection vulnerability in showthread.php in MyBB (aka ...)
5150 NOT-FOR-US: MyBB
5151 CVE-2006-2335 (Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and ...)
5152 NOT-FOR-US: vBulletin
5153 CVE-2006-2334 (The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in ...)
5154 NOT-FOR-US: Windows
5155 CVE-2006-2333 (Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) ...)
5156 NOT-FOR-US: MyBB
5157 CVE-2006-2332 (Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of ...)
5158 NOTE: 1.5.dfsg+1.5.0.3-2 didn't crash or do anything but stutter on the sample pages, marking it fixed in there
5159 - firefox 1.5.dfsg+1.5.0.3-2
5160 CVE-2006-2331 (Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 ...)
5161 NOT-FOR-US: PHP-Fusion
5162 CVE-2006-2330 (PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server ...)
5163 NOT-FOR-US: PHP-Fusion
5164 CVE-2006-2329 (AngelineCMS 0.6.5 and earlier allow remote attackers to obtain ...)
5165 NOT-FOR-US: AngelineCMS
5166 CVE-2006-2328 (SQL injection vulnerability in lib/adodb/server.php in AngelineCMS ...)
5167 NOT-FOR-US: AngelineCMS
5168 CVE-2006-2327 (Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) ...)
5169 NOT-FOR-US: Novell
5170 CVE-2006-2326 (Directory traversal vulnerability in index.php in OnlyScript.info ...)
5171 NOT-FOR-US: OnlyScript.info
5172 CVE-2006-2325 (Cross-site scripting (XSS) vulnerability in index.php in ...)
5173 NOT-FOR-US: OnlyScript.info
5174 CVE-2006-2324 (180solutions Zango downloads &quot;required Adware components&quot; without ...)
5175 NOT-FOR-US: 180solutions
5176 CVE-2006-2323 (Multiple PHP remote file inclusion vulnerabilities in SmartISoft ...)
5177 NOT-FOR-US: SmartISoft
5178 CVE-2006-2322 (The transparent proxy feature of the Cisco Application Velocity System ...)
5179 NOT-FOR-US: Cisco
5180 CVE-2006-2321 (Multiple cross-site scripting (XSS) vulnerabilities in Ideal Science ...)
5181 NOT-FOR-US: Ideal Science
5182 CVE-2006-2320 (Multiple SQL injection vulnerabilities in Ideal Science Ideal BB ...)
5183 NOT-FOR-US: Ideal Science
5184 CVE-2006-2319 (Ideal Science Ideal BB 1.5.4a and earlier does not properly check file ...)
5185 NOT-FOR-US: Ideal Science
5186 CVE-2006-2318 (Incomplete blacklist vulnerability in Ideal Science Ideal BB 1.5.4a ...)
5187 NOT-FOR-US: Ideal Science
5188 CVE-2006-2317 (Unspecified vulnerability in Ideal Science Ideal BB 1.5.4a and earlier ...)
5189 NOT-FOR-US: Ideal Science
5190 CVE-2006-2316 (S24EvMon.exe in the Intel PROset/Wireless software, possibly ...)
5191 NOT-FOR-US: Intel Windows software
5192 CVE-2006-2315 (PHP remote file inclusion vulnerability in session.inc.php in ...)
5193 NOT-FOR-US: ISPConfig
5194 CVE-2006-2314 (PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before ...)
5195 {DSA-1087-1}
5196 - postgresql 7.5.4 (medium; bug #368645)
5197 - postgresql-7.4 1:7.4.13-1 (medium)
5198 - postgresql-8.1 8.1.4-1 (medium)
5199 [sarge] - pygresql <not-affected> (Already includes proper quoting)
5200 NOTE: Beginning with version 7.5.4, postgresql is a transition
5201 NOTE: package which does not contain actual code. That's why
5202 NOTE: it's marked as fixed here. (Previous versions are vulnerable.)
5203 NOTE: The following packages needed to adapted to cope with the new system:
5204 NOTE: psycopg 1.1.21-5 (bug #369230)
5205 NOTE: python-pgsql 2.4.0-8 (bug #369250)
5206 NOTE: pygresql 1:3.8-1.1 (bug #369239)
5207 NOTE: dovecot 1.0.beta8-3 (bug #369359)
5208 NOTE: postfix 2.2.10-2 (bug #369349)
5209 CVE-2006-2313 (PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before ...)
5210 {DSA-1087-1}
5211 - postgresql 7.5.4 (high; bug #368645)
5212 - postgresql-7.4 1:7.4.13-1 (high)
5213 - postgresql-8.1 8.1.4-1 (high)
5214 NOTE: Beginning with version 7.5.4, postgresql is a transition
5215 NOTE: package which does not contain actual code. That's why
5216 NOTE: it's marked as fixed here. (Previous versions are vulnerable.)
5217 CVE-2006-2312 (Unspecified vulnerability in the URI handler in Skype 2.0.*.104 and ...)
5218 NOT-FOR-US: Skype
5219 CVE-2006-2311 (Cross-site scripting (XSS) vulnerability in BlueDragon Server and ...)
5220 NOT-FOR-US: BlueDragon Server and Server JX
5221 CVE-2006-2310 (BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote ...)
5222 NOT-FOR-US: BlueDragon Server and Server JX
5223 CVE-2006-2309 (The HTTP service in EServ/3 3.25 allows remote attackers to obtain ...)
5224 NOT-FOR-US: EServ
5225 CVE-2006-2308 (Directory traversal vulnerability in the IMAP service in EServ/3 3.25 ...)
5226 NOT-FOR-US: EServ
5227 CVE-2006-2307 (Cross-site scripting (XSS) vulnerability in Website Baker CMS before ...)
5228 NOT-FOR-US: Webiste Banker
5229 CVE-2006-2306 (Cross-site scripting (XSS) vulnerability in moreinfo.asp in ...)
5230 NOT-FOR-US: EPublisherPro
5231 CVE-2006-2305 (Multiple cross-site scripting (XSS) vulnerabilities in Jadu CMS allow ...)
5232 NOT-FOR-US: Jadu
5233 CVE-2006-2304 (Multiple integer overflows in the DPRPC library (DPRPCW32.DLL) in ...)
5234 NOT-FOR-US: Novell software for Windows
5235 CVE-2006-2303 (Cross-Application Scripting (XAS) vulnerability in ICQ Client 5.04 ...)
5236 NOT-FOR-US: Windows ICQ client
5237 CVE-2006-2302 (SQL injection vulnerability in admin_default.asp in DUGallery 2.x ...)
5238 NOT-FOR-US: DUGallery
5239 CVE-2006-2301 (SQL injection vulnerability in admin_default.asp in OzzyWork Galeri ...)
5240 NOT-FOR-US: OzzyWork
5241 CVE-2006-2300 (Multiple SQL injection vulnerabilities in EImagePro allow remote ...)
5242 NOT-FOR-US: EImagePro
5243 CVE-2006-2299
5244 RESERVED
5245 CVE-2006-2298 (The Internet Key Exchange version 1 (IKEv1) implementation in the ...)
5246 NOT-FOR-US: Solaris
5247 CVE-2006-2297 (Heap-based buffer overflow in Microsoft Infotech Storage System ...)
5248 NOT-FOR-US: Microsoft Infotech Storage System
5249 CVE-2006-2296 (SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 ...)
5250 NOT-FOR-US: EDirectoryPro
5251 CVE-2006-2295 (Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote ...)
5252 NOT-FOR-US: Dynamic Galerie
5253 CVE-2006-2294 (Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows ...)
5254 NOT-FOR-US: Dynamic Galerie
5255 CVE-2006-2293 (SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 ...)
5256 NOT-FOR-US: MultiCalendars
5257 CVE-2006-2292 (Multiple SQL injection vulnerabilities in IA-Calendar allow remote ...)
5258 NOT-FOR-US: IA-Calendar
5259 CVE-2006-2291 (Cross-site scripting (XSS) vulnerability in calendar_new.asp in ...)
5260 NOT-FOR-US: IA-Calendar
5261 CVE-2006-2290 (Multiple cross-site scripting (XSS) vulnerabilities in kommentar.php ...)
5262 NOT-FOR-US: 2005-Comments-Script
5263 CVE-2006-2289 (Buffer overflow in avahi-core in Avahi before 0.6.10 allows local ...)
5264 - avahi 0.6.10-1 (medium)
5265 CVE-2006-2288 (Avahi before 0.6.10 allows local users to cause a denial of service ...)
5266 - avahi 0.6.10-1 (low)
5267 CVE-2006-2287 (Multiple cross-site scripting (XSS) vulnerabilities in Vision Source ...)
5268 NOT-FOR-US: Vision Source
5269 CVE-2006-2286 (Multiple PHP remote file inclusion vulnerabilities in ...)
5270 NOT-FOR-US: Dokeos
5271 CVE-2006-2285 (PHP remote file inclusion vulnerability in authldap.php in Dokeos ...)
5272 NOT-FOR-US: Dokeos
5273 CVE-2006-2284 (Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 ...)
5274 NOT-FOR-US: Claroline
5275 CVE-2006-2283 (Multiple PHP remote file inclusion vulnerabilities in SpiffyJr phpRaid ...)
5276 NOT-FOR-US: phpRaid
5277 CVE-2006-2282 (Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier ...)
5278 NOT-FOR-US: X7 Chat
5279 CVE-2006-2281 (X-Scripts X-Poll (xpoll) 2.30 allows remote attackers to execute ...)
5280 NOT-FOR-US: X-Scripts X-Poll
5281 CVE-2006-2280 (Directory traversal vulnerability in website.php in openEngine 1.8 ...)
5282 NOT-FOR-US: openEngine
5283 CVE-2006-2279 (Multiple SQL injection vulnerabilities in SaphpLesson 3.0 allow remote ...)
5284 NOT-FOR-US: SaphpLesson
5285 CVE-2006-2278 (SaphpLesson 3.0 does not initialize array variables, which allows ...)
5286 NOT-FOR-US: SaphpLesson
5287 CVE-2006-2277 (Multiple Apple Mac OS X 10.4 applications might allow ...)
5288 NOT-FOR-US: Apple Mac OS X
5289 CVE-2006-2276 (bgpd in Quagga 0.98 and 0.99 before 20060504 allows local users to ...)
5290 {DSA-1059-1}
5291 - quagga 0.99.4-1 (bug #366980; low)
5292 CVE-2006-2275 (Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a ...)
5293 - linux-2.6 2.6.16-13
5294 CVE-2006-2274 (Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a ...)
5295 {DSA-1103 DSA-1097-1}
5296 - linux-2.6 2.6.16-13
5297 CVE-2006-2273 (The InstallProduct routine in the Verisign VUpdater.Install (aka ...)
5298 NOT-FOR-US: Verisign
5299 CVE-2006-2272 (Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a ...)
5300 {DSA-1103 DSA-1097-1}
5301 - linux-2.6 2.6.16-13
5302 CVE-2006-2271 (The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows ...)
5303 {DSA-1103 DSA-1097-1}
5304 - linux-2.6 2.6.16-13
5305 CVE-2005-4798 (Buffer overflow in NFS readlink handling in the Linux Kernel 2.4 up to ...)
5306 - linux-2.6 <not-affected>
5307 CVE-2006-2270 (PHP remote file inclusion vulnerability in includes/config.php in ...)
5308 NOT-FOR-US: Jetbox CMS
5309 CVE-2006-2269 (Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 ...)
5310 NOT-FOR-US: myWebland MyBloggie
5311 CVE-2006-2268 (SQL injection vulnerability in FlexCustomer 0.0.4 and earlier allows ...)
5312 NOT-FOR-US: FlexCustomer
5313 CVE-2006-2267 (Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause ...)
5314 NOT-FOR-US: Kerio WinRoute Firewall
5315 CVE-2006-2266 (SQL injection vulnerability in Chirpy! 0.1 allows remote attackers to ...)
5316 NOT-FOR-US: Chirpy!
5317 CVE-2006-2265 (Cross-site scripting vulnerability in admin/main.asp in Ocean12 ...)
5318 NOT-FOR-US: Ocean12 Calendar Manager Pro
5319 CVE-2006-2264 (Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro ...)
5320 NOT-FOR-US: Ocean12 Calendar Manager Pro
5321 CVE-2006-2263 (SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows ...)
5322 NOT-FOR-US: VP-ASP
5323 CVE-2006-2262 (Cross-site scripting (XSS) vulnerability in index.php in singapore ...)
5324 NOT-FOR-US: singapore
5325 CVE-2006-2261 (PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 ...)
5326 NOT-FOR-US: ACal
5327 CVE-2006-2260 (Cross-site scripting (XSS) vulnerability in the project module ...)
5328 - drupal <not-affected> (bug #366947)
5329 CVE-2006-2259 (SQL injection vulnerability in Logon.asp in MaxxSchedule 1.0 allows ...)
5330 NOT-FOR-US: MaxxSchedule
5331 CVE-2006-2258 (Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule ...)
5332 NOT-FOR-US: MaxxSchedule
5333 CVE-2006-2257 (Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 ...)
5334 NOT-FOR-US: easyEvent
5335 CVE-2006-2256 (PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp ...)
5336 NOT-FOR-US: EQdkp
5337 CVE-2006-2255 (Multiple SQL injection vulnerabilities in Creative Community Portal ...)
5338 NOT-FOR-US: Creative Community Portal
5339 CVE-2006-2254 (Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote ...)
5340 NOT-FOR-US: FileCOPA
5341 CVE-2006-2253 (PHP remote file inclusion vulnerability in visible_count_inc.php in ...)
5342 NOT-FOR-US: Statit
5343 CVE-2006-2252 (Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 ...)
5344 NOT-FOR-US: OpenFAQ
5345 CVE-2006-2251 (SQL injection vulnerability in the do_mmod function in mod.php in ...)
5346 NOT-FOR-US: Invision Community Blog
5347 CVE-2006-2250 (CuteNews 1.4.1 allows remote attackers to obtain sensitive information ...)
5348 NOT-FOR-US: CuteNews
5349 CVE-2006-2249 (Multiple cross-site scripting (XSS) vulnerabilities in search.php in ...)
5350 NOT-FOR-US: CuteNews
5351 CVE-2006-2248 (Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source ...)
5352 NOT-FOR-US: Xeneo Web Server
5353 CVE-2006-2247 (WebCalendar 1.0.1 to 1.0.3 generates different error messages ...)
5354 {DSA-1056-1}
5355 - webcalendar 1.0.2-2.2 (medium; bug #366927)
5356 CVE-2006-2246 (Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition ...)
5357 NOT-FOR-US: UBlog
5358 CVE-2006-2245 (PHP remote file inclusion vulnerability in auction\auction_common.php ...)
5359 NOT-FOR-US: Auction mod 1.3m for phpBB
5360 CVE-2006-2244 (Multiple SQL injection vulnerabilities in Web4Future News Portal allow ...)
5361 NOT-FOR-US: Web4Future News Portal
5362 CVE-2006-2243 (Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News ...)
5363 NOT-FOR-US: Web4Future News Portal
5364 CVE-2006-2242 (acFTP 1.4 allows remote attackers to cause a denial of service ...)
5365 NOT-FOR-US: acFTP
5366 CVE-2006-2241 (PHP remote file inclusion vulnerability in show.php in Fast Click SQL ...)
5367 NOT-FOR-US: Fast Click SQL Lite
5368 CVE-2006-2240 (Unspecified vulnerability in the (1) web cache or (2) web proxy in ...)
5369 NOT-FOR-US: Fujitsu NetShelter/FW
5370 CVE-2006-2239 (SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows ...)
5371 NOT-FOR-US: Newsadmin
5372 CVE-2006-2238 (Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote ...)
5373 NOT-FOR-US: Apple
5374 CVE-2006-2237 (The web interface for AWStats 6.4 and 6.5, when statistics updates are ...)
5375 {DSA-1058-1}
5376 - awstats 6.5-2 (bug #365909; bug #365910; medium)
5377 CVE-2006-2236 (Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) ...)
5378 - quake3 <itp> (bug #337937)
5379 CVE-2006-2235 (CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is ...)
5380 NOT-FOR-US: Simple Poll
5381 CVE-2006-2234 (Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta ...)
5382 NOT-FOR-US: TyroCMS
5383 CVE-2006-2233 (Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) ...)
5384 NOT-FOR-US: BankTown Client Control
5385 CVE-2006-2232 (Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook ...)
5386 NOT-FOR-US: Scriptsez Cute Guestbook
5387 CVE-2006-2231 (Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in ...)
5388 NOT-FOR-US: Big Webmaster Guestbook Script
5389 CVE-2006-2230 (Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine ...)
5390 {DSA-1093-1}
5391 - xine-ui 0.99.4-2 (medium; bug #363370)
5392 CVE-2006-2229 (OpenVPN 2.0.7 and earlier, when configured to use the --management ...)
5393 - openvpn <unfixed> (unimportant)
5394 NOTE: One needs to explicitly set the IP to something else than 127.0.0.1
5395 NOTE: in order to be vulnerable. The man page recommends not to do it.
5396 CVE-2006-2228 (Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) ...)
5397 NOT-FOR-US: Web-Agora
5398 CVE-2006-2227 (Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 ...)
5399 NOT-FOR-US: PunBB
5400 CVE-2006-2226 (Buffer overflow in XM Easy Personal FTP Server 4.2 allows remote ...)
5401 NOT-FOR-US: Easy Personal FTP Server
5402 CVE-2006-2225 (Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows ...)
5403 NOT-FOR-US: Easy Personal FTP Server
5404 CVE-2006-2224 (RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce ...)
5405 {DSA-1059-1}
5406 - quagga 0.99.3-2 (bug #365940; medium)
5407 CVE-2006-2223 (RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly ...)
5408 {DSA-1059-1}
5409 - quagga 0.99.3-2 (bug #365940; medium)
5410 CVE-2006-2222 (Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, ...)
5411 NOT-FOR-US: zawhttpd
5412 CVE-2006-2221 (A third-party installer generation tool, possibly BitRock ...)
5413 - ejabberd <not-affected> (only binary distribution is affected)
5414 CVE-2006-2220
5415 RESERVED
5416 CVE-2006-2219
5417 RESERVED
5418 CVE-2006-2218 (Unspecified vulnerability in Internet Explorer 6.0 on Microsoft ...)
5419 NOT-FOR-US: MS IE
5420 CVE-2006-2217 (SQL injection vulnerability in index.php in Invision Power Board ...)
5421 NOT-FOR-US: Invision Power Board
5422 CVE-2006-2216 (Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain ...)
5423 NOT-FOR-US: OpenBB
5424 CVE-2006-2215 (Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.x ...)
5425 NOT-FOR-US: Albinator
5426 CVE-2005-4797 (Directory traversal vulnerability in printd line printer daemon (lpd) ...)
5427 NOT-FOR-US: Solaris
5428 CVE-2005-4796 (Unspecified vulnerability in the XView library (libxview.so) in ...)
5429 - xview <unfixed> (unimportant)
5430 NOTE: Is only relevant for suid binaries, but xview is not really suitable for
5431 NOTE: those anyway. Exact information is not available, but a similar problem
5432 NOTE: is already fixed in the Debian package.
5433 CVE-2005-4795 (Unspecified vulnerability in the multi-language environment library ...)
5434 NOT-FOR-US: Solaris
5435 CVE-2006-XXXX [pstotext insufficient filename sanitizing]
5436 - pstotext 1.9-3 (bug #356988; medium)
5437 CVE-2006-XXXX [cyrus-imapd allows user probes]
5438 - cyrus-imapd-2.2 2.2.13-3
5439 CVE-2006-2214 (Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier ...)
5440 NOT-FOR-US: 4images
5441 CVE-2006-2213 (Hostapd 0.3.7-2 allows remote attackers to cause a denial of service ...)
5442 {DSA-1065-1}
5443 - hostapd 1:0.5.0-1 (bug #365897; high)
5444 CVE-2006-2212 (Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows ...)
5445 NOT-FOR-US: KarjaSoft Sami FTP Server
5446 CVE-2006-2211 (Absolute path traversal vulnerability in index.php in 321soft ...)
5447 NOT-FOR-US: 321soft PhP-Gallery
5448 CVE-2006-2210 (Cross-site scripting (XSS) vulnerability in index.php in 321soft ...)
5449 NOT-FOR-US: 321soft PhP-Gallery
5450 CVE-2006-2209 (Multiple SQL injection vulnerabilities in index.php in PHP Arena ...)
5451 NOT-FOR-US: paCheckBook
5452 CVE-2006-2208 (Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php ...)
5453 NOT-FOR-US: paCheckBook
5454 CVE-2006-2207
5455 RESERVED
5456 CVE-2006-2206 (The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 ...)
5457 NOT-FOR-US: UltraVNC
5458 CVE-2006-2205 (The audio_write function in NetBSD 3.0 allows local users to cause a ...)
5459 NOT-FOR-US: NetBSD kernel
5460 CVE-2006-2204 (SQL injection vulnerability in the topic deletion functionality ...)
5461 NOT-FOR-US: Invision Power Board
5462 CVE-2006-2203 (Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown ...)
5463 NOT-FOR-US: Kerio MailServer
5464 CVE-2006-2202 (SQL injection vulnerability in post.php in Invision Gallery 2.0.6 ...)
5465 NOT-FOR-US: Invision Gallery
5466 CVE-2006-2201 (Unspecified vulnerability in CA Resource Initialization Manager ...)
5467 NOT-FOR-US: CA Resource Initialization Manager
5468 CVE-2006-2200 (Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and ...)
5469 - libmms 0.2-7 (bug #374577; medium)
5470 - mimms 2.0.0-1 (bug #374577; medium)
5471 - xine-lib 1.1.2-2 (bug #374577; medium)
5472 CVE-2006-2199 (Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka ...)
5473 {DSA-1104}
5474 - openoffice.org 2.0.3-1
5475 CVE-2006-2198 (OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before ...)
5476 {DSA-1104}
5477 - openoffice.org 2.0.3-1
5478 CVE-2006-2197 (Integer overflow in wv2 before 0.2.3 might allow context-dependent ...)
5479 {DSA-1100}
5480 - wv2 0.2.2-6 (medium)
5481 CVE-2006-2196 (Unspecified vulnerability in pinball 0.3.1 allows local users to gain ...)
5482 {DSA-1102}
5483 - pinball 0.3.1-6
5484 CVE-2006-2195 (Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before ...)
5485 {DSA-1099-1 DSA-1098-1}
5486 - horde3 3.1.1-3
5487 CVE-2006-2194 (The winbind plugin in pppd for ppp 2.4.4 and earlier does not check ...)
5488 {DSA-1106}
5489 - ppp 2.4.4rel-1 (medium)
5490 CVE-2006-2193 (Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff ...)
5491 {DSA-1091-1}
5492 - tiff 3.8.2-4 (bug #371064; medium)
5493 CVE-2006-2191
5494 RESERVED
5495 CVE-2006-2190 (Cross-site scripting (XSS) vulnerability in ow-shared.pl in ...)
5496 NOT-FOR-US: OpenWebMail
5497 CVE-2006-2189 (SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 ...)
5498 NOT-FOR-US: Servous sBLOG
5499 CVE-2006-2188 (Multiple cross-site scripting (XSS) vulnerabilities in CMScout 1.10 ...)
5500 NOT-FOR-US: CMScout
5501 CVE-2006-2187 (Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 ...)
5502 NOT-FOR-US: zenphoto
5503 CVE-2006-2186 (zenphoto 1.0.1 beta and earlier allow remote attackers to obtain ...)
5504 NOT-FOR-US: zenphoto
5505 CVE-2006-2185 (PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password ...)
5506 NOT-FOR-US: Novell
5507 CVE-2006-2184 (Cross-site scripting (XSS) vulnerability in search.php in PHPKB ...)
5508 NOT-FOR-US: PHPKB Knowledge Base
5509 CVE-2006-2183 (Untrusted search path vulnerability in Truecrypt 4.1, when running ...)
5510 NOT-FOR-US: Truecrypt
5511 CVE-2006-2182 (Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, ...)
5512 NOT-FOR-US: albinator
5513 CVE-2006-2181 (Multiple cross-site scripting (XSS) vulnerabilities in albinator 2.0.8 ...)
5514 NOT-FOR-US: albinator
5515 CVE-2006-2180 (Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers ...)
5516 NOT-FOR-US: Golden FTP Server Pro
5517 CVE-2006-2179 (Multiple SQL injection vulnerabilities in CyberBuild allow remote ...)
5518 NOT-FOR-US: CyberBuild
5519 CVE-2006-2178 (Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild ...)
5520 NOT-FOR-US: CyberBuild
5521 CVE-2006-2177 (Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 ...)
5522 NOT-FOR-US: geoBlog
5523 CVE-2006-2176 (Multiple cross-site scripting (XSS) vulnerabilities in links.php in ...)
5524 NOT-FOR-US: PHP Linkliste
5525 CVE-2006-2175 (PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 ...)
5526 NOT-FOR-US: Fast Click
5527 CVE-2006-2174 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
5528 NOT-FOR-US: Virtual Hosting Control System (VHCS)
5529 CVE-2006-2173 (Buffer overflow in FileZilla FTP Server allows remote authenticated ...)
5530 NOT-FOR-US: FileZilla FTP Server
5531 CVE-2006-2172 (Buffer overflow in Gene6 FTP Server 3.1.0 allows remote authenticated ...)
5532 NOT-FOR-US: Gene6 FTP Server
5533 CVE-2006-2171 (Buffer overflow in WDM.exe in WarFTPD allows remote attackers to ...)
5534 NOT-FOR-US: WarFTPD
5535 CVE-2006-2170 (Buffer overflow in ArgoSoft FTP Server allows remote attackers to ...)
5536 NOT-FOR-US: ArgoSoft FTP Server
5537 CVE-2006-2169 (RT: Request Tracker 3.5.HEAD allows remote attackers to obtain ...)
5538 - request-tracker3.4 <not-affected> (file not included in 3.4)
5539 CVE-2006-2168 (FileProtection Express 1.0.1 and earlier allows remote attackers to ...)
5540 NOT-FOR-US: FileProtection Express
5541 CVE-2006-2167 (Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, ...)
5542 NOT-FOR-US: SloughFlash
5543 CVE-2006-2166 (Unspecified vulnerability in the HTTP management interface in Cisco ...)
5544 NOT-FOR-US: Cisco
5545 CVE-2006-2165 (Multiple cross-site scripting (XSS) vulnerabilities in Avactis ...)
5546 NOT-FOR-US: Avactis
5547 CVE-2006-2164 (Multiple SQL injection vulnerabilities in Avactis Shopping Cart 0.1.2 ...)
5548 NOT-FOR-US: Avactis
5549 CVE-2006-2163 (Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart ...)
5550 NOT-FOR-US: Pinnacle
5551 CVE-2006-2162 (Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before ...)
5552 {DSA-1072-1}
5553 - nagios 2:1.4-1 (bug #366682; bug #366803; medium)
5554 - nagios2 2.3-1 (bug #366683; medium)
5555 CVE-2006-2161 (Buffer overflow in (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 and ...)
5556 NOT-FOR-US: TZipBuilder/Abakt
5557 CVE-2006-2160 (Cross-site scripting (XSS) vulnerability in Russcom Network Loginphp ...)
5558 NOT-FOR-US: Russcom
5559 CVE-2006-2159 (CRLF injection vulnerability in help.php in Russcom Network Loginphp ...)
5560 NOT-FOR-US: Russcom
5561 CVE-2006-2158 (Dynamic variable evaluation vulnerability in index.php in Stadtaus ...)
5562 NOT-FOR-US: Stadtaus
5563 CVE-2006-2157 (SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and ...)
5564 NOT-FOR-US: Plogger
5565 CVE-2006-2156 (Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and ...)
5566 NOT-FOR-US: X7 Chat
5567 CVE-2006-2155 (EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and ...)
5568 NOT-FOR-US: EMC Retrospect
5569 CVE-2006-2154 (EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and ...)
5570 NOT-FOR-US: EMC Retrospect
5571 CVE-2006-2153 (Cross-site scripting (XSS) vulnerability in HTM_PASSWD in DirectAdmin ...)
5572 NOT-FOR-US: DirectAdmin
5573 CVE-2006-2152 (PHP remote file inclusion vulnerability in admin/addentry.php in phpBB ...)
5574 NOT-FOR-US: phpBB Advanced Guestbook
5575 CVE-2006-2151 (PHP remote file inclusion vulnerability in toplist.php in phpBB ...)
5576 NOT-FOR-US: phpBB TopList
5577 CVE-2006-2150 (PHP remote file inclusion vulnerability in top/list.php in phpBB ...)
5578 NOT-FOR-US: phpBB TopList
5579 CVE-2006-2149 (PHP remote file inclusion vulnerability in sources/lostpw.php in ...)
5580 NOT-FOR-US: Aardvark Topsites
5581 CVE-2006-2147 (resmgrd in resmgr for SUSE Linux and other distributions does not ...)
5582 {DSA-1047-1}
5583 - resmgr 1.0-4 (low)
5584 CVE-2006-2146 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
5585 NOT-FOR-US: HB-NS
5586 CVE-2006-2145 (Multiple SQL injection vulnerabilities in index.php in HB-NS 1.1.6 ...)
5587 NOT-FOR-US: HB-NS
5588 CVE-2006-2144 (PHP remote file inclusion vulnerability in kopf.php in DMCounter ...)
5589 NOT-FOR-US: DMCounter
5590 CVE-2006-2143 (Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB ...)
5591 NOT-FOR-US: TextFileBB
5592 CVE-2006-2142 (PHP remote file inclusion vulnerability in classes/adodbt/sql.php in ...)
5593 NOT-FOR-US: Limbo
5594 CVE-2006-2141 (Cross-site scripting (XSS) vulnerability in popup_image in ...)
5595 NOT-FOR-US: Collaborative Portal Server
5596 CVE-2006-2140 (Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 ...)
5597 NOT-FOR-US: OrbitHYIP
5598 CVE-2006-2139 (Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow ...)
5599 NOT-FOR-US: PHP Newsfeed
5600 CVE-2006-2138 (Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 ...)
5601 NOT-FOR-US: NeoMail
5602 CVE-2006-2137 (PHP remote file inclusion vulnerability in master.php in OpenPHPNuke ...)
5603 NOT-FOR-US: OpenPHPNuke
5604 CVE-2006-2136 (SQL injection vulnerability in news.php in AZNEWS allows remote ...)
5605 NOT-FOR-US: AZNEWS
5606 CVE-2006-2135 (SQL injection vulnerability in login.php in Ruperts News allows remote ...)
5607 NOT-FOR-US: Ruperts News
5608 CVE-2006-2134 (PHP remote file inclusion vulnerability in /includes/kb_constants.php ...)
5609 NOT-FOR-US: phpbb2 mod
5610 CVE-2005-4794 (Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and ...)
5611 NOT-FOR-US: Cisco
5612 CVE-2006-2148 (Multiple buffer overflows in client.c in CGI:IRC (CGIIRC) before 0.5.8 ...)
5613 {DSA-1052-1}
5614 - cgiirc 0.5.9-1 (bug #365680; medium)
5615 [sarge] - cgiirc 0.5.4-6sarge1 (bug #365680; medium)
5616 CVE-2006-2133 (SQL injection vulnerability in index.php in BoonEx Barracuda 1.1 and ...)
5617 NOT-FOR-US: BoonEx Barracuda
5618 CVE-2006-2132 (SQL injection vulnerability in detail.asp in DUclassified allows ...)
5619 NOT-FOR-US: DUclassified
5620 CVE-2006-2131 (include/class_poll.php in Advanced Poll 2.0.4 uses the ...)
5621 NOT-FOR-US: Advanced Poll
5622 CVE-2006-2130 (SQL injection vulnerability in include/class_poll.php in Advanced Poll ...)
5623 NOT-FOR-US: Advanced Poll
5624 CVE-2006-2129 (Direct static code injection vulnerability in Pro Publish 2.0 allows ...)
5625 NOT-FOR-US: Pro Publish
5626 CVE-2006-2128 (Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote ...)
5627 NOT-FOR-US: Pro Publish
5628 CVE-2006-2127 (SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x ...)
5629 NOT-FOR-US: Blog Mod
5630 CVE-2006-2126 (SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and ...)
5631 NOT-FOR-US: MaxTrade
5632 CVE-2006-2125
5633 REJECTED
5634 CVE-2006-2124 (Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and ...)
5635 NOT-FOR-US: SunShop
5636 CVE-2006-2123 (Multiple SQL injection vulnerabilities in the report interface in ...)
5637 NOT-FOR-US: Network Administration Visualiazed
5638 CVE-2006-2122 (PHP remote file inclusion vulnerability in index.php in CoolMenus allows ...)
5639 NOT-FOR-US: CoolMenus
5640 CVE-2006-2121 (PHP remote file include vulnerability in admin/config_settings.tpl.php ...)
5641 NOT-FOR-US: I-RATER Platinum
5642 CVE-2006-2120 (The TIFFToRGB function in libtiff before 3.8.1 allows remote attackers ...)
5643 {DSA-1078-1}
5644 - tiff 3.8.1 (bug #366588; medium)
5645 CVE-2006-2119 (PHP remote file inclusion vulnerability in event/index.php in Artmedic ...)
5646 NOT-FOR-US: Artmedic
5647 CVE-2006-2118 (JMK's Picture Gallery allows remote attackers to bypass authentication ...)
5648 NOT-FOR-US: JMK
5649 CVE-2006-2117 (Cross-site scripting (XSS) vulnerability in Thyme 1.3 allows remote ...)
5650 NOT-FOR-US: Thyme
5651 CVE-2006-2116 (planetGallery allows remote attackers to gain administrator privileges ...)
5652 NOT-FOR-US: planetGallery
5653 CVE-2006-2115 (Format string vulnerability in SWS web Server 0.1.7 allows remote ...)
5654 NOT-FOR-US: SWS
5655 CVE-2006-2114 (Buffer overflow in SWS web Server 0.1.7 allows remote attackers to ...)
5656 NOT-FOR-US: SWS
5657 CVE-2006-2113 (The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print ...)
5658 NOT-FOR-US: Fuji Xerox Printing Systems
5659 CVE-2006-2112 (Fuji Xerox Printing Systems (FXPS) print engine, as used in products ...)
5660 NOT-FOR-US: Fuji Xerox Printing Systems
5661 CVE-2006-2111 (Microsoft Internet Explorer 6.0 on Windows XP SP2, and possibly other ...)
5662 NOT-FOR-US: Microsoft Internet Explorer
5663 CVE-2006-2110 (Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x ...)
5664 {DSA-1060-1}
5665 - kernel-patch-vserver 2:2.0.1-4 (low)
5666 - linux-2.6 2.6.16-11 (low)
5667 CVE-2006-2109 (Cross-site scripting (XSS) vulnerability in the parse_query_str ...)
5668 NOTE: #357204: request for removal
5669 - jsboard 2.0.10-2 (bug #368305; low)
5670 CVE-2006-2108 (parser.exe in Oc&#233; (OCE) 3121/3122 Printer allows remote attackers to ...)
5671 NOT-FOR-US: OCE
5672 CVE-2006-2107 (Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote ...)
5673 NOT-FOR-US: BL4
5674 CVE-2006-2106 (Cross-site scripting (XSS) vulnerability in Edgewall Software Trac ...)
5675 - trac 0.9.5-1 (medium)
5676 [sarge] - trac <unfixed> (medium)
5677 NOTE: http://trac.edgewall.org/changeset/3201
5678 NOTE: http://trac.edgewall.org/changeset/3287
5679 NOTE: the second reference fixes a regression in the first. i *believe*
5680 NOTE: that these correctly solve the problem, though we really ought
5681 NOTE: to run this by upstream or the reporter.
5682 CVE-2006-2105 (Directory traversal vulnerability in index.php in Jupiter CMS 1.1.4 ...)
5683 NOT-FOR-US: Jupiter
5684 CVE-2006-2104 (Multiple cross-site scripting (XSS) vulnerabilities in Kamgaing Email ...)
5685 NOT-FOR-US: Kamgaing
5686 CVE-2006-2103 (SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows ...)
5687 NOT-FOR-US: MyBB
5688 CVE-2006-2102 (Directory traversal vulnerability in PowerISO 2.9 allows remote ...)
5689 NOT-FOR-US: PowerISO
5690 CVE-2006-2101 (Directory traversal vulnerability in WinISO 5.3 allows remote ...)
5691 NOT-FOR-US: WinISO
5692 CVE-2006-2100 (Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows ...)
5693 NOT-FOR-US: Magic ISO
5694 CVE-2006-2099 (Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote ...)
5695 NOT-FOR-US: UltraISO
5696 CVE-2006-2098 (PHP remote file inclusion vulnerability in Thumbnail AutoIndex before ...)
5697 NOT-FOR-US: Thumbnail AutoIndex
5698 CVE-2006-2097 (SQL injection vulnerability in func_msg.php in Invision Power Board ...)
5699 NOT-FOR-US: Invision
5700 CVE-2006-2096 (plug.php in Land Down Under (LDU) 802 and earlier allows remote ...)
5701 NOT-FOR-US: LDU
5702 CVE-2006-2095 (Phex before 2.8.6 allows remote attackers to cause a denial of service ...)
5703 NOT-FOR-US: Phex
5704 CVE-2006-2094 (Microsoft Internet Explorer before Windows XP Service Pack 2 and ...)
5705 NOT-FOR-US: Microsoft Internet Explorer
5706 CVE-2006-2093 (Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted ...)
5707 - libnasl 2.2.8-1 (bug #365898; low)
5708 [sarge] - libnasl <no-dsa> (Hardly exploitable, see #365898)
5709 CVE-2006-2092 (Unspecified vulnerability in HP StorageWorks Secure Path for Windows ...)
5710 NOT-FOR-US: HP
5711 CVE-2006-2091 (admin.php in Virtual War (VWar) 1.5 and versions before 1.2 allows ...)
5712 NOT-FOR-US: Virtual War
5713 CVE-2006-2090 (Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x ...)
5714 NOT-FOR-US: MySmartBB
5715 CVE-2006-2089 (Multiple cross-site scripting (XSS) vulnerabilities in misc.php in ...)
5716 NOT-FOR-US: OpenBB
5717 CVE-2006-2088 (Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open ...)
5718 NOT-FOR-US: OpenBB
5719 CVE-2006-2087 (The Gmax Mail client in Hitachi Groupmax before 20060426 allows remote ...)
5720 NOT-FOR-US: Hitachi Groupmax
5721 CVE-2006-2086 (Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx ...)
5722 NOT-FOR-US: juniper SSL-VPN
5723 CVE-2006-2085 (Multiple buffer overflows in (1) CxAce60.dll and (2) CxAce60u.dll in ...)
5724 NOT-FOR-US: SpeedProject Squeez
5725 CVE-2006-2084 (Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 ...)
5726 NOT-FOR-US: FarsiNews
5727 CVE-2006-2083 (Integer overflow in the receive_xattr function in the extended ...)
5728 - rsync 2.6.8-1 (bug #365614; high)
5729 [sarge] - rsync <not-affected> (xattr patch appeared in 2.6.7)
5730 [woody] - rsync <not-affected> (xattr patch appeared in 2.6.7)
5731 CVE-2006-2082 (Directory traversal vulnerability in Quake 3 engine, as used in ...)
5732 - quake3 <itp> (bug #337937)
5733 CVE-2006-2081 (Oracle Database Server 10g Release 2 allows local users to execute ...)
5734 NOT-FOR-US: Oracle
5735 CVE-2006-2080 (SQL injection vulnerability in portfolio_photo_popup.php in Verosky ...)
5736 NOT-FOR-US: Verosky
5737 CVE-2006-2079 (Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky ...)
5738 NOT-FOR-US: Verosky
5739 CVE-2006-2078 (Multiple unspecified vulnerabilities in multiple FITELnet products, ...)
5740 NOT-FOR-US: FITELnet
5741 CVE-2006-2077 (Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has unknown impact ...)
5742 - pdnsd 1.2.4par-0.1 (bug #368268; high)
5743 CVE-2006-2076 (Memory leak in Paul Rombouts pdnsd before 1.2.4 allows remote ...)
5744 - pdnsd 1.2.4par-0.1 (bug #368268; high)
5745 CVE-2006-2075 (Unspecified vulnerability in MyDNS 1.1.0 allows remote attackers to ...)
5746 [sarge] - mydns 1.0.0-4sarge1
5747 - mydns 1.1.0+pre-3 (medium; bug #348826)
5748 CVE-2006-2074 (Unspecified vulnerability in Juniper Networks JUNOSe E-series routers ...)
5749 NOT-FOR-US: Juniper Networks JUNOSe
5750 CVE-2006-2073 (Unspecified vulnerability in ISC BIND allows remote attackers to cause ...)
5751 - bind9 <unfixed> (low)
5752 [sarge] - bind9 <no-dsa> (Only exploitable by trusted users after TSIG transaction)
5753 CVE-2006-2072 (Multiple unspecified vulnerabilities in DeleGate 9.x before 9.0.6 and ...)
5754 NOT-FOR-US: DeleGate
5755 CVE-2005-4793 (Multiple unspecified vulnerabilities in the web utility function in ...)
5756 NOT-FOR-US: Hitachi
5757 CVE-2005-4792 (SQL injection vulnerability in index.php in Appalachian State ...)
5758 NOT-FOR-US: phpWebSite
5759 CVE-2004-2659 (Opera offers an Open button to verify that a user wishes to execute a ...)
5760 NOT-FOR-US: Opera
5761 CVE-2006-2071 (Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass ...)
5762 - linux-2.6 2.6.16-8
5763 CVE-2006-2070 (Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 ...)
5764 NOT-FOR-US: DevBB
5765 CVE-2006-2069 (The recursor in PowerDNS before 3.0.1 allows remote attackers to cause ...)
5766 - pdns-recursor 3.0.1-1 (medium)
5767 CVE-2006-2068 (Unspecified vulnerability in Hitachi JP1 products allow remote ...)
5768 NOT-FOR-US: Hitachi JP1
5769 CVE-2006-2067 (SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, ...)
5770 NOT-FOR-US: MKPortal
5771 CVE-2006-2066 (Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in ...)
5772 NOT-FOR-US: MKPortal
5773 CVE-2006-2065 (SQL injection vulnerability in save.php in PHPSurveyor 0.995 and ...)
5774 NOT-FOR-US: PHPSurveyor
5775 CVE-2006-2064 (Unspecified vulnerability in the libpkcs11 library in Sun Solaris 10 ...)
5776 NOT-FOR-US: Sun
5777 CVE-2006-2063 (Multiple cross-site scripting (XSS) vulnerabilities in Leadhound Full ...)
5778 NOT-FOR-US: Leadhound
5779 CVE-2006-2062 (Multiple SQL injection vulnerabilities in Leadhound Full and LITE 2.1, ...)
5780 NOT-FOR-US: Leadhound
5781 CVE-2006-2061 (SQL injection vulnerability in lib/func_taskmanager.php in Invision ...)
5782 NOT-FOR-US: Invision
5783 CVE-2006-2060 (Directory traversal vulnerability in action_admin/paysubscriptions.php ...)
5784 NOT-FOR-US: Invision
5785 CVE-2006-2059 (action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x ...)
5786 NOT-FOR-US: Invision
5787 CVE-2006-2058 (Argument injection vulnerability in Avant Browser 10.1 Build 17 allows ...)
5788 NOT-FOR-US: Avant
5789 CVE-2006-2057 (Argument injection vulnerability in Mozilla Firefox 1.0.6 allows ...)
5790 NOT-FOR-US: Only on Windows
5791 CVE-2006-2056 (Argument injection vulnerability in Internet Explorer 6 for Windows XP ...)
5792 NOT-FOR-US: Microsoft
5793 CVE-2006-2055 (Argument injection vulnerability in Micrsoft Outlook 2003 SP1 allows ...)
5794 NOT-FOR-US: Micrsoft Outlook
5795 CVE-2006-2054 (3Com Baseline Switch 2848-SFP Plus Model #3C16486 with firmware before ...)
5796 NOT-FOR-US: 3Com
5797 CVE-2006-2053 (Multiple SQL injection vulnerabilities in QuickEStore 7.9 and earlier ...)
5798 NOT-FOR-US: QuickEStore
5799 CVE-2006-2052 (Cross-site scripting (XSS) vulnerability in Verosky Media Instant ...)
5800 NOT-FOR-US: Verosky
5801 CVE-2006-2051 (Multiple cross-site scripting (XSS) vulnerabilities in ...)
5802 NOT-FOR-US: NextAge
5803 CVE-2006-2050 (SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite ...)
5804 NOT-FOR-US: DCScripts
5805 CVE-2006-2049 (Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts ...)
5806 NOT-FOR-US: DCScripts
5807 CVE-2006-2048 (Multiple cross-site scripting (XSS) vulnerabilities in index.php in ...)
5808 NOT-FOR-US: phpWebFTP
5809 CVE-2006-2047 (Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows ...)
5810 NOT-FOR-US: ColdFusion
5811 CVE-2006-2046 (Multiple SQL injection vulnerabilities in Application Dynamics ...)
5812 NOT-FOR-US: ColdFusion
5813 CVE-2006-2045 (The (1) shadow password file in na-img-4.0.34.bin for the IP3 Networks ...)
5814 NOT-FOR-US: IP3
5815 CVE-2006-2044 (na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has a default ...)
5816 NOT-FOR-US: IP3
5817 CVE-2006-2043 (na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local ...)
5818 NOT-FOR-US: IP3
5819 CVE-2006-2042 (Adobe Dreamweaver 8 before 8.0.2 and MX 2004 can generate code that ...)