Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-02-15 CVE-2006-0718 Denial of Service vulnerability in Avaya VSU/CSU Products ISAKMP IKE Traffic
The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
avaya
5.0
2006-02-15 CVE-2006-0717 LDAP Memory Corruption vulnerability in IBM Tivoli Directory Server 6.0
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
network
low complexity
ibm
5.0
2006-02-15 CVE-2006-0716 Input Validation vulnerability in Solucija Snews 1.3
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
network
low complexity
solucija
7.5
2006-02-15 CVE-2006-0715 Input Validation vulnerability in Solucija Snews 1.3
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
network
solucija
4.3
2006-02-15 CVE-2006-0714 Remote File Include vulnerability in Flyspray 0.9.7
Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a ..
network
low complexity
flyspray
5.0
2006-02-15 CVE-2006-0713 Local File Inclusion and PHP Code Injection vulnerability in LinPHA
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via ..
network
low complexity
linpha
5.0
2006-02-15 CVE-2006-0712 Unspecified vulnerability in Squishdot
mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability.
network
low complexity
squishdot
5.0
2006-02-15 CVE-2006-0711 Unspecified vulnerability in Neomail
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.
network
low complexity
neomail
5.0
2006-02-15 CVE-2006-0710 Buffer Errors vulnerability in Isode M-Vault Server 11.3
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sample LDAP.
network
low complexity
isode CWE-119
7.5
2006-02-15 CVE-2006-0709 Remote Buffer Overflow vulnerability in Metamail Corporation Metamail 2.7.50
Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.
network
low complexity
metamail-corporation
7.5