Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-12-05 CVE-2006-6297 Resource Management Errors vulnerability in KDE Kdegraphics 3.2/3.4.3
Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, allows remote attackers to cause a denial of service (stack consumption) via a crafted EXIF section in a JPEG file, which results in an infinite recursion.
network
low complexity
kde CWE-399
5.0
2006-12-05 CVE-2006-6296 Resource Management Errors vulnerability in Microsoft Windows 2000 and Windows XP
The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request that specifies a large 'offered' value (output buffer size), a variant of CVE-2005-3644.
low complexity
microsoft CWE-399
6.1
2006-12-05 CVE-2006-6295 Remote File Include vulnerability in Mxbb MX Tinies 1.3.0
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
network
mxbb
6.8
2006-12-05 CVE-2006-6292 Denial Of Service vulnerability in Apple mac OS X 10.4.8
Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-related impact via certain beacon frames.
5.7
2006-12-05 CVE-2006-6291 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mailenable
Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.
network
low complexity
mailenable CWE-119
6.8
2006-12-05 CVE-2006-6290 Buffer Overflow vulnerability in MailEnable IMAP Service
Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.30 and 2.0 through 2.33 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a long argument to the (1) EXAMINE or (2) SELECT command.
network
low complexity
mailenable
6.5
2006-12-05 CVE-2006-6289 SQL-Injection vulnerability in Woltlab Burning Board Lite 1.0.2
Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the wbb_userid parameter to the top-level URI.
network
woltlab
6.8
2006-12-05 CVE-2006-6142 Cross-Site Scripting and Input Validation vulnerability in SquirrelMail
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."
network
squirrelmail
6.8
2006-12-04 CVE-2006-6288 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Niek Albers Coolplayer
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long song names, because of an overflow in the CPL_AddPrefixedFile function in CPI_Playlist.c; (2) a skin file with long button names, because of an overflow in the main_skin_check_ini_value function in skin.c; and (3) a skin file with long bitmap filenames, because of an overflow in the main_skin_open function in skin.c.
local
low complexity
niek-albers CWE-119
4.6
2006-12-04 CVE-2006-6283 Cross-Site Scripting vulnerability in Vikingboard 0.1.2
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the subject field of (1) a private message (PM) or (2) a bulletin board post.
network
vikingboard
4.3