Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2006-05-22 CVE-2006-1858 Improper Input Validation vulnerability in Linux Kernel
SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with the actual length of provided parameters.
network
low complexity
linux CWE-20
7.8
2006-05-20 CVE-2006-2499 SQL Injection vulnerability in Xfairguy Codeavalanche News 1.2
SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field.
network
low complexity
xfairguy
7.5
2006-05-20 CVE-2006-2495 Cross-Site Request Forgery vulnerability in Serendipity
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
network
low complexity
s9y
7.5
2006-05-20 CVE-2006-2492 Classic Buffer Overflow vulnerability in Microsoft Office and Works Suite
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
network
low complexity
microsoft CWE-120
8.8
2006-05-19 CVE-2006-2489 Remote Content-Length Integer Overflow vulnerability in Nagios
Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x before 2.3.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a content length (Content-Length) HTTP header.
network
low complexity
nagios
7.5
2006-05-19 CVE-2006-2487 Remote File Include vulnerability in ScozNet ScozNews
Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[main_path] parameter in (1) functions.php, (2) template.php, (3) news.php, (4) help.php, (5) mail.php, (6) Admin/admin_cats.php, (8) Admin/admin_edit.php, (9) Admin/admin_import.php, and (10) Admin/admin_templates.php.
network
low complexity
scoznet
7.5
2006-05-19 CVE-2006-2485 Remote File Include vulnerability in Quezza BB 1.1.0
PHP remote file inclusion vulnerability in includes/class_template.php in Quezza 1.0 and earlier, and possibly 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the quezza_root_path parameter.
network
low complexity
quezza
7.5
2006-05-19 CVE-2006-1856 Unspecified vulnerability in Linux Kernel
Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.
network
low complexity
linux
7.5
2006-05-19 CVE-2006-0059 Remote Heap Overflow vulnerability in Livedata Iccp Server 5.00.045
Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets.
network
low complexity
livedata
7.5
2006-05-19 CVE-2006-2475 Directory Traversal vulnerability in Cosmoshop 8.10.78
Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.
network
low complexity
cosmoshop
7.8