LiveActive security incident?Get immediate response
CVE archive

December 2006

Browse CVE records published in December 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 657 matching CVEs · Page 5 of 14.

Unknown · CVSS Not scored

CVE-2006-6572: Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with A...

Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than CVE-2006-4846. NOTE: some of these details are obtained from third party information.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6634: Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier co...

Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php, or (3) the CONFIG_EXT[LIB_DIR] parameter to lib/mail.inc.php.

Published Dec 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6664: Format string vulnerability in Marathon Aleph One before 0.17.1 and 2006-12-17 might allow remote attackers...

Format string vulnerability in Marathon Aleph One before 0.17.1 and 2006-12-17 might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the TopLevelLogger::logMessageV function in Misc/Logging.cpp. NOTE: some details were obtained from third party information.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6652: Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* a...

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6629: lib/WeBWorK/PG/Translator.pm in WeBWorK Program Generation (PG) Language before 2.3.1 uses an insufficientl...

lib/WeBWorK/PG/Translator.pm in WeBWorK Program Generation (PG) Language before 2.3.1 uses an insufficiently restrictive regular expression to determine valid macro filenames, which allows attackers to load arbitrary macro files whose names contain the strings (1) dangerousMacros.pl, (2) PG.pl, or (3) IO.pl.

Published Dec 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6576: Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial...

Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6661: Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overw...

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6667: Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbi...

Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) repass.php or (b) verify.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6565: FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard...

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6614: The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose...

The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.

Published Dec 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6641: Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used i...

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

Published Dec 20, 2006 · Updated Aug 7, 2024