Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-05-18 CVE-2006-2441 Denial-Of-Service vulnerability in Pioneers Meta-Server
Pioneers meta-server before 0.9.55, when the server-console is not installed, allows remote attackers to cause a denial of service (crash) via certain requests from an older gnocatan client to create a new game.
network
low complexity
pioneers
5.0
2006-05-18 CVE-2006-2440 Remote Security vulnerability in Imagemagick 6.0.6.2/6.2.4
Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary code via an image index array that triggers the overflow during filename glob expansion by the ExpandFilenames function.
network
low complexity
imagemagick
7.5
2006-05-17 CVE-2006-2438 Information Disclosure vulnerability in Caucho Technology Resin 3.0.17/3.0.18
Directory traversal vulnerability in the viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to read arbitrary files under other web roots via the contextpath parameter.
network
low complexity
caucho-technology
5.0
2006-05-17 CVE-2006-2437 Information Disclosure vulnerability in Caucho Technology Resin 3.0.17/3.0.18
The viewfile servlet in the documentation package (resin-doc) for Caucho Resin 3.0.17 and 3.0.18 allows remote attackers to obtain the source code for file under the web root via the file parameter.
network
low complexity
caucho-technology
5.0
2006-05-17 CVE-2006-2436 Remote Security vulnerability in IBM Websphere Application Server 5.0.0/5.0.1/5.0.2
WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges.
network
low complexity
ibm
7.5
2006-05-17 CVE-2006-2435 Remote Security vulnerability in Websphere Application Server
Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts."
network
low complexity
ibm
6.4
2006-05-17 CVE-2006-2434 Information Disclosure vulnerability in IBM Websphere Application Server 5.1.1
Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace.
network
low complexity
ibm
5.0
2006-05-17 CVE-2006-2433 Remote Security vulnerability in Websphere Application Server
Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console".
network
low complexity
ibm
critical
10.0
2006-05-17 CVE-2006-2432 Remote Security vulnerability in Websphere Application Server
IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token.
network
low complexity
ibm
7.5
2006-05-17 CVE-2006-2431 Cross-Site Scripting vulnerability in IBM Websphere Application Server
Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a FAULTACTOR element on this page.
network
ibm CWE-79
4.3