Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-01-21 CVE-2006-0345 Input Validation vulnerability in Saral Kaushik Saralblog 1.0
Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php.
network
low complexity
saral-kaushik
7.5
2006-01-21 CVE-2006-0344 Directory Traversal vulnerability in Intervations Filecopa 1.01
Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a ..
network
low complexity
intervations
6.4
2006-01-21 CVE-2006-0343 Denial of Service vulnerability in Hitachi products
Unspecified vulnerability in the Port Discovery Standard and Advanced features in Hitachi JP1/NetInsight II allows attackers to stop the Port Discovery service via unknown vectors involving "invalid format data".
network
low complexity
hitachi
5.0
2006-01-21 CVE-2006-0342 Resource Management Errors vulnerability in Rockliffe Mailsite 7.0.3.1
RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string containing special characters such as "|".
network
low complexity
rockliffe CWE-399
7.8
2006-01-21 CVE-2006-0340 Improper Input Validation vulnerability in Cisco IOS
Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.
network
cisco CWE-20
7.1
2006-01-21 CVE-2006-0339 Remote Buffer Overflow vulnerability in Bitcomet 0.60
Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.
network
low complexity
bitcomet
7.5
2006-01-21 CVE-2006-0338 Archive Handling vulnerability in F-Secure
Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP archives, which are not properly scanned.
network
low complexity
f-secure
5.0
2006-01-21 CVE-2006-0337 Archive Handling vulnerability in F-Secure
Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives.
network
low complexity
f-secure
7.5
2006-01-21 CVE-2006-0336 Denial of Service vulnerability in Kerio WinRoute Firewall Web Browsing
Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".
network
low complexity
kerio
5.0
2006-01-21 CVE-2006-0335 Denial of Service vulnerability in Kerio WinRoute Firewall
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.
network
low complexity
kerio
5.0