LiveActive security incident?Get immediate response
CVE archive

March 2006

Browse CVE records published in March 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 642 matching CVEs · Page 5 of 13.

Unknown · CVSS Not scored

CVE-2006-1402: Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denia...

Buffer overflow in client/server Doom (csDoom) 0.7 and earlier allows remote attackers to (1) cause a denial of service via a long nickname or teamname to the SV_SetupUserInfo function or (2) execute arbitrary code via a long string sent when joining a match or a long chat message to the SV_BroadcastPrintf function.

Published Mar 28, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1397: Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow re...

Multiple cross-site scripting (XSS) vulnerabilities in (a) phpAdsNew and (b) phpPgAds before 2.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) certain parameters to the banner delivery module, which is not properly handled in the administrator interface, or (2) certain parameters to the login form.

Published Mar 28, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1355: avast!

avast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local users to gain privileges or disable protection by modifying those files.

Published Mar 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1365: The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow rem...

The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the target device, by initiating and interrupting an OBEX Push Profile that pretends to send a vCard, aka a "HeloMoto" attack.

Published Mar 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1364: Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when refere...

Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are restricted documents located under the ASP.NET application path.

Published Mar 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1395: SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execut...

SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Published Mar 26, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1401: Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote atta...

Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Published Mar 28, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1367: The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-ba...

The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and view phonebook entries and saved SMS messages by connecting on Bluetooth channel 3 and tricking the user into pressing Grant, aka a "Blueline" attack. NOTE: while user-assisted, the attack is made more feasible because of a GUI misrepresentation issue that allows a default message to be replaced by an attacker-specified one.

Published Mar 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1378: PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand fun...

PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a known plaintext attack.

Published Mar 24, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1368: Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote atta...

Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (kmalloc'd memory corruption) via a remote NDIS response to OID_GEN_SUPPORTED_LIST, which causes memory to be allocated for the reply data but not the reply structure.

Published Mar 23, 2006 · Updated Aug 7, 2024