LiveActive security incident?Get immediate response
CVE archive

February 2006

Browse CVE records published in February 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 591 matching CVEs · Page 9 of 12.

Unknown · CVSS Not scored

CVE-2006-0671: Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause...

Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0625: Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to rea...

Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3.

Published Feb 9, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0665: Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has...

Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impact and attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. An original vendor bug report is referenced, but not accessible to the general public.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0631: CRLF injection vulnerability in mailback.pl in Erik C.

CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "spam proxy" by modifying mail headers, including recipient e-mail addresses, via newline characters in the Subject field.

Published Feb 10, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0642: Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security...

Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass anti-virus checks by sending compressed archives containing many small files. NOTE: since this is related to a configuration setting that has an operational impact that might vary depending on the environment, and the product is claimed to report a message when the compressed file exceeds specified limits, perhaps this should not be included in CVE.

Published Feb 10, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0645: Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3...

Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite.

Published Feb 10, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0632: The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create...

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

Published Feb 10, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0648: Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to...

Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbitrary files via the (1) getdate and possibly other parameters used in the replace_files function in search.php and (2) $file variable as used in the parse function in functions/template.php.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0641: Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is...

Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of sensitive information to an unintended remote destination.

Published Feb 10, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0669: Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute...

Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database. SecurityTracker's research indicates that the original problem could be due to a vbscript parsing error based on invalid arguments

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0550: Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary c...

Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DBC02 from the January 2006 CPU, in which case this would be a duplicate of CVE-2006-0283. However, there are enough inconsistencies that the mapping can not be made authoritatively.

Published Feb 4, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0652: WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote au...

WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated users to perform privileged actions or obtain sensitive information. NOTE: this report is based on a vendor bug report that identified "incorrect permissions." However, the vendor did not label it a security issue, and there was no statement regarding whether or not the permissions were actually more permissive than intended. If in fact the permissions were more restrictive than intended, then this would be a functional problem but not a vulnerability.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0646: ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an...

ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH or RUNPATH, which allows local attackers to execute arbitrary code as other users via by running an ld-linked application from the current directory, which could contain an attacker-controlled library file.

Published Feb 11, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0630: RITLabs The Bat!

RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messages, instead of the real headers, which is in violation of RFC2046 header merging rules and allows remote attackers to spoof the origin of e-mail by sending a fragmented message, as demonstrated using spoofed Received: and Message-ID: headers.

Published Feb 10, 2006 · Updated Aug 7, 2024