LiveActive security incident?Get immediate response
CVE archive

March 2006

Browse CVE records published in March 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 642 matching CVEs · Page 12 of 13.

Unknown · CVSS Not scored

CVE-2006-0947: Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be...

Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.

Published Mar 1, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1044: Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive...

Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.

Published Mar 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0988: The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Micros...

The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

Published Mar 3, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1014: Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when...

Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

Published Mar 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0977: Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to re...

Craig Morrison Mail Transport System Professional (aka MTS Pro) acts as an open relay when configured to relay all mail through an external SMTP server, which allows remote attackers to relay mail by connecting to the MTS Pro server, then sending a MAIL FROM that specifies a domain that is local to the server.

Published Mar 3, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1019: Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arb...

Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which reference a source URL that appears to be for an unrelated issue.

Published Mar 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0982: The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when ma...

The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allows remote attackers to bypass virus protection, as demonstrated using the EICAR test file.

Published Mar 3, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0987: The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows rec...

The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

Published Mar 3, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0967: NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to...

NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000. NOTE: this issue was reported as a buffer overflow, but that term usually does not apply in flooding attacks.

Published Mar 2, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0905: A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does n...

A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows packets to pass sequence number checks and allows remote attackers to capture IPSec packets and conduct replay attacks.

Published Mar 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0883: OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child proces...

OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of service (client connection refusal) by connecting multiple times to the SSH server, waiting for the password prompt, then disconnecting.

Published Mar 7, 2006 · Updated Aug 7, 2024