Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-04-07 CVE-2006-1657 HTML Injection vulnerability in Chucky A. Ivey N.T. 1.1.0
Cross-site scripting (XSS) vulnerability in index.php in Chucky A.
network
chucky-a-ivey
4.3
2006-04-06 CVE-2006-1630 Multiple vulnerability in Clam AntiVirus ClamAV
The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access."
network
low complexity
clam-anti-virus
5.0
2006-04-06 CVE-2006-1629 Remote Code Execution vulnerability in Openvpn and Openvpn Access Server
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.
network
low complexity
openvpn
critical
9.0
2006-04-06 CVE-2006-1615 USE of Externally-Controlled Format String vulnerability in Clamav
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code.
network
low complexity
clamav CWE-134
critical
10.0
2006-04-06 CVE-2006-1614 Multiple vulnerability in Clam AntiVirus ClamAV
Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code.
network
high complexity
clam-anti-virus
5.1
2006-04-06 CVE-2006-1656 Unspecified vulnerability in Vserver Util-Vserver 0.30.209
vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root.
local
low complexity
vserver
7.2
2006-04-06 CVE-2006-1655 Unspecified vulnerability in Mpg123 0.59R
Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3.
network
low complexity
mpg123
6.5
2006-04-06 CVE-2006-1654 Directory Traversal vulnerability in HP Color LaserJet 2500/4600 Toolbox
Directory traversal vulnerability in the HP Color LaserJet 2500 Toolbox and Color LaserJet 4600 Toolbox on Microsoft Windows before 20060402 allows remote attackers to read arbitrary files via a ..
network
low complexity
hp
5.0
2006-04-06 CVE-2006-1653 Remote File Include vulnerability in Angelinecms 0.8.1
PHP remote file inclusion vulnerability in loadkernel.php in AngelineCMS 0.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the installPath parameter.
network
low complexity
angelinecms
7.5
2006-04-06 CVE-2006-1652 Buffer Errors vulnerability in Ultravnc Tabbed Viewer and VNC Viewer
Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackers to execute arbitrary code via a malicious server that sends a long string to a client that connects on TCP port 5900, which triggers an overflow in Log::ReallyPrint; and (2) allow remote attackers to cause a denial of service (server crash) via a long HTTP GET request to TCP port 5800, which triggers an overflow in VNCLog::ReallyPrint.
network
low complexity
ultravnc CWE-119
critical
9.0