LiveActive security incident?Get immediate response
CVE archive

February 2006

Browse CVE records published in February 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 591 matching CVEs · Page 6 of 12.

Unknown · CVSS Not scored

CVE-2006-0848: The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted at...

The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension.

Published Feb 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0796: Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to injec...

Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatemessages.php). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0787: wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to inser...

wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTitle parameters, which can result in providing false information about songs, occupying excessive disk space with very long parameter values, and storing executable code that might be invoked through a different vulnerability. NOTE: since this issue, as described by the original researcher, is entirely dependent on the presence of another vulnerability, it could be argued that Wimpy cannot be responsible for how its data file is processed by applications outside of its control. Since this issue might only be useful as a facilitator manipulation in another vulnerability, perhaps it should not be included in CVE.

Published Feb 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0837: IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf,...

IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 has world-readable permissions for (1) /etc/neusecure.conf, (2) /opt/NeuSecure/etc/cms-3.0.236.buildconf, and (3) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to read sensitive information such as passwords. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues.

Published Feb 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0841: Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to...

Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4) reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8) show_status, (9) show_resolution, (10) show_build, (11) show_profile, (12) show_priority, (13) highlight_changed, (14) relationship_type, and (15) relationship_bug parameters in (a) view_all_set.php; the (16) sort parameter in (b) manage_user_page.php; the (17) view_type parameter in (c) view_filters_page.php; and the (18) title parameter in (d) proj_doc_delete.php. NOTE: item 17 might be subsumed by CVE-2005-4522.

Published Feb 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0830: The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource co...

The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location" variable within the loop.

Published Feb 21, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0844: Leif M.

Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.

Published Feb 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0765: GUI display truncation vulnerability in ICQ Inc.

GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which truncates the malicious extension from the display and could trick a user into executing arbitrary programs.

Published Feb 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0764: The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the sof...

The Authentication, Authorization, and Accounting (AAA) capability in versions 5.0(1) and 5.0(3) of the software used by multiple Cisco Anomaly Detection and Mitigation products, when running with an incomplete TACACS+ configuration without a "tacacs-server host" command, allows remote attackers to bypass authentication and gain privileges, aka Bug ID CSCsd21455.

Published Feb 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0761: Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2...

Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers to execute arbitrary code on the server via a crafted Microsoft Word document that is opened on a wireless device.

Published Feb 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0800: Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripti...

Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklist protection in (1) the pnVarCleanFromInput function in pnAPI.php, (2) the pnSecureInput function in pnAntiCracker.php, and (3) the htmltext parameter in an edituser operation to user.php.

Published Feb 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0785: Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote at...

Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions.

Published Feb 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0833: Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to in...

Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

Published Feb 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0758: Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to i...

Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via a URL encoded expression in the query string in (1) index.php and (2) possibly certain other scripts, which is not properly cleansed when accessed from the $_SERVER['PHP_SELF'] variable.

Published Feb 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0797: Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wi...

Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).

Published Feb 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0782: Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbi...

Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter.

Published Feb 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0799: Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct...

Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate URL. NOTE: this issue is very similar to CVE-2004-1104, although the manipulations are slightly different.

Published Feb 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0766: ICQ Inc.

ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified properties such as company name, icon, and description, which could trick a user into executing arbitrary programs.

Published Feb 18, 2006 · Updated Aug 7, 2024