LiveActive security incident?Get immediate response
CVE archive

October 2006

Browse CVE records published in October 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 549 matching CVEs · Page 7 of 11.

Unknown · CVSS Not scored

CVE-2006-5303: Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password,...

Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signers.cfg. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Published Oct 17, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5313: Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands...

Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary SMTP commands by placing them after a CRLF.CRLF sequence in the smtp_message parameter. NOTE: this crosses privilege boundaries if the SMTP server configuration prevents a user from establishing a direct SMTP session. NOTE: this is a different type of issue than CVE-2006-5262.

Published Oct 17, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5325: Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Suite IP Logger in dwingmods f...

Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Suite IP Logger in dwingmods for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) mkb.php, (2) iplogger.php, (3) admin_board2.php, or (4) admin_logger.php in includes/, different vectors than CVE-2006-5224.

Published Oct 17, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5331: The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19...

The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19 on 64-bit systems mishandles the case where CONFIG_ALTIVEC is defined and the CPU actually supports Altivec, but the Altivec support was not detected by the kernel, which allows local users to cause a denial of service (panic) by triggering execution of an Altivec instruction.

Published Oct 29, 2017 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5327: Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and ea...

Untrusted search path vulnerability in OpenBase SQL 10.0 and earlier, as used in Apple Xcode 2.2 2.2 and earlier and possibly other products, allows local users to execute arbitrary code via a modified PATH that references a malicious gzip program, which is executed by gnutar with certain TAR_OPTIONS environment variable settings, when gnutar is invoked by OpenBase.

Published Oct 17, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5306: Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier fo...

Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php.

Published Oct 17, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5367: Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.7 up to 11.5.10CU2 have unknown impact...

Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.7 up to 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS03 in Oracle Applications Framework, (2) APPS04 in Oracle Applications Technology Stack, and (3) APPS05 in Oracle Balanced Scorecard, (4) APPS09 in Oracle Scripting, and (5) APPS10 in Oracle Trading Community.

Published Oct 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5342: Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.3 has...

Unspecified vulnerability in Oracle Spatial component in Oracle Database 9.0.1.5, 9.2.0.6, and 10.1.0.3 has unknown impact and remote authenticated attack vectors related to mdsys.sdo_tune, aka Vuln# DB18. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB18 might be related to SQL injection in the EXTENT_OF function.

Published Oct 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5291: PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1....

PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition, so this issue is probably a duplicate of CVE-2006-4656.

Published Oct 16, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5296: PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceed...

PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.

Published Oct 16, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5255: PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attack...

PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attackers to execute arbitrary PHP code via a URL in the languagefile parameter. NOTE: another researcher has observed that languageFile is defined before use. CVE analysis as of 20061012 concurs with the dispute

Published Oct 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5243: Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_glob...

Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_file.php, and (5) lib_form_file.php in sw/lib_up_file/; (6) find_comment.php, (7) comment.php, and (8) lib_comment.php in sw/lib_comment/; (9) sw/lib_find/find.php; and other unspecified PHP scripts.

Published Oct 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-5263: Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote att...

Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.

Published Oct 12, 2006 · Updated Aug 7, 2024