Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2006-03-30 CVE-2006-1540 Code Injection vulnerability in Microsoft Office
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt.
network
microsoft CWE-94
critical
9.3
2006-03-30 CVE-2006-1539 Local Privilege Escalation vulnerability in Bsd-Games Tetris-Bsd Gold
Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches tetris-bsd.
network
low complexity
bsd-games
7.5
2006-03-30 CVE-2006-1538 Local Security vulnerability in X-Wall Asic
The Enova X-Wall ASIC encrypts with a key obtained via Microwire from a serial EEPROM that stores the key in cleartext, which allows local users with physical access to obtain the key by reading and duplicating an EEPROM that is located on a hardware token, or by sniffing the Microwire bus.
local
low complexity
enova
4.9
2006-03-30 CVE-2006-1537 Information Disclosure vulnerability in Webcalendar 1.1.0
Craig Knudsen WebCalendar 1.1.0-CVS allows remote attackers to obtain sensitive information via a direct request to (1) includes/index.php, (2) tests/add_duration_test.php, (3) tests/all_tests.php, (4) groups.php, (5) nonusers.php, (6) includes/settings.php, (7) includes/init.php, (8) includes/settings.php.orig, (9) includes/js/admin.php, (10) includes/js/edit_entry.php, (11) includes/js/edit_layer.php, (12) includes/js/export_import.php, (13) includes/js/popups.php, (14) includes/js/pref.php, or (15) includes/menu/index.php, which reveal the path in various error messages.
network
low complexity
webcalendar
5.0
2006-03-30 CVE-2006-1536 SQL Injection vulnerability in Phxcontacts 0.93/0.93.1
Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.
network
low complexity
phoetux-net
7.5
2006-03-30 CVE-2006-1535 Cross-Site Scripting vulnerability in Phxcontacts 0.93/0.93.1
Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.
network
phoetux-net
4.3
2006-03-30 CVE-2006-1534 SQL Injection vulnerability in Null News
Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.
network
low complexity
null-news
7.5
2006-03-30 CVE-2006-1533 SQL Injection vulnerability in Sourceworkshop Newsletter 1.0
SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.
network
low complexity
sourceworkshop
7.5
2006-03-30 CVE-2006-1532 Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20
Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.
network
deltascripts
4.3
2006-03-30 CVE-2006-1511 Buffer Overflow vulnerability in Microsoft .NET Framework SDK MSIL Tools
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
network
high complexity
microsoft
5.1