Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-12-13 CVE-2006-6496 Unspecified vulnerability in Broadcom Etrust Antivirus and Internet Security Suite
The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs.
local
broadcom
6.6
2006-12-13 CVE-2006-6495 Local vulnerability in Sun Solaris LD.SO
Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function.
local
sun
6.6
2006-12-13 CVE-2006-6494 Local vulnerability in Sun Solaris LD.SO
Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a ..
local
sun
6.6
2006-12-13 CVE-2006-4702 Remote ASF File Buffer Overflow vulnerability in Microsoft products
Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.
network
microsoft
6.8
2006-12-13 CVE-2006-2386 Remote Code Execution vulnerability in Microsoft Outlook Express Windows Address Book Contact Record
Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file.
network
microsoft
6.8
2006-12-13 CVE-2006-6493 Remote Security vulnerability in OpenLDAP
Buffer overflow in the krbv4_ldap_auth function in servers/slapd/kerberos.c in OpenLDAP 2.4.3 and earlier, when OpenLDAP is compiled with the --enable-kbind (Kerberos KBIND) option, allows remote attackers to execute arbitrary code via an LDAP bind request using the LDAP_AUTH_KRBV41 authentication method and long credential data.
network
high complexity
openldap
5.1
2006-12-12 CVE-2006-6485 Cross-Site Scripting vulnerability in Shopsite 8.1
Multiple cross-site scripting (XSS) vulnerabilities in ShopSite 8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the prevlocation parameter in shopper/sc/registration.cgi and other unspecified vectors.
network
shopsite
6.8
2006-12-12 CVE-2006-6484 Remote Denial of Service vulnerability in MailEnable IMAP Service
The IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.34, Professional Edition 1.6 through 1.83, and Enterprise Edition 1.1 through 1.40 allows remote attackers to cause a denial of service (crash) via unspecified vectors that trigger a null pointer dereference, as addressed by the ME-10023 hotfix, and a different issue than CVE-2006-6423.
network
low complexity
mailenable
5.0
2006-12-12 CVE-2006-6482 Input Validation vulnerability in Adobe Coldfusion 7.0
Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's internal IP address in an HREF tag.
network
low complexity
adobe
5.0
2006-12-12 CVE-2006-5577 Information Disclosure vulnerability in Microsoft Internet Explorer Object Tag TIF Folder
Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5578.
network
microsoft
4.3