Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Imanager HIGH 7.8
CVE-2006-4517

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP …

Fix: after 2.5
Fix from $1,950 2006-11-01
Anti Virus MEDIUM 5.0
CVE-2006-5645EPSS 18%

Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of …

Fix: after 6.04
Fix from $1,600 2006-11-01
Ruby MEDIUM 5.0
CVE-2006-5467

The cgi.rb CGI library for Ruby 1.8 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an HTTP request with…

Patch available
Fix from $1,600 2006-10-27
Ftpxq MEDIUM 5.0
CVE-2006-5568

FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command.

No fix yet
Fix from $1,600 2006-10-27
Ichitaro MEDIUM 5.1
CVE-2006-5424

Unspecified vulnerability in Justsystem Ichitaro 2006, 2006 trial version, and Government 2006 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,600 2006-10-20
Openssh HIGH 7.8
CVE-2006-4924EPSS 35%

sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH …

Patch available
Fix from $1,950 2006-09-27
iOS HIGH 7.8
CVE-2006-4774EPSS 5%

The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to cause a denial of service by sending a VTP version 1 summar…

Patch available
Fix from $1,950 2006-09-14
iOS HIGH 7.8
CVE-2006-4775EPSS 5%

The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update…

Patch available
Fix from $1,950 2006-09-14
Wireshark MEDIUM 5.4
CVE-2006-4333

The SSCOP dissector in Wireshark (formerly Ethereal) before 0.99.3 allows remote attackers to cause a denial of service (resource consumption) via ma…

Patch available
Fix from $1,600 2006-08-24
Heartbeat MEDIUM 5.0
CVE-2006-3121EPSS 13%

The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote…

Patch available
Fix from $1,600 2006-08-17
Dhcpd MEDIUM 5.0
CVE-2006-3122

The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) v…

Fix: after 2.0pl5
Fix from $1,600 2006-08-09
Heimdal HIGH 7.2
CVE-2006-3083

The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimd…

Patch available
Fix from $1,950 2006-08-09
Blackice Pc Protection MEDIUM 5.0
CVE-2006-3840

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and…

Mitigation only
Fix from $1,600 2006-07-27
Wireshark MEDIUM 5.0
CVE-2006-3627

Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of serv…

Patch available
Fix from $1,600 2006-07-21
Wireshark MEDIUM 5.0
CVE-2006-3631

Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (inf…

Patch available
Fix from $1,600 2006-07-21
Linux Kernel HIGH 7.8
CVE-2006-2936

The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of …

Mitigation only
Fix from $1,950 2006-07-10
Linux Kernel MEDIUM 5.0
CVE-2006-2934EPSS 5%

SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers t…

Patch available
Fix from $1,600 2006-06-30
Mailenable Enterprise MEDIUM 5.0
CVE-2006-3277EPSS 6%

The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, all…

Fix: after 1.21
Fix from $1,600 2006-06-28
Mac Os X MEDIUM 5.0
CVE-2006-1470EPSS 8%

OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers a…

Patch available
Fix from $1,600 2006-06-27
Java Enterprise System HIGH 7.8
CVE-2006-3127

Memory leak in Network Security Services (NSS) 3.11, as used in Sun Java Enterprise System 2003Q4 through 2005Q1 and Java System Directory Server 5.2…

Mitigation only
Fix from $1,950 2006-06-21
Db2 Universal Database MEDIUM 5.0
CVE-2006-3068

IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect …

Patch available
Fix from $1,600 2006-06-19
Sendmail MEDIUM 5.0
CVE-2006-1173EPSS 5%

Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the sta…

Fix: after 8.13.6
Fix from $1,600 2006-06-07
Powerdns MEDIUM 5.0
CVE-2006-2069EPSS 6%

The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.

Patch available
Fix from $1,600 2006-04-27
Firefox MEDIUM 5.1
CVE-2006-1993EPSS 54%

Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via cer…

Patch available
Fix from $1,600 2006-04-25
Firefox HIGH 10.0
CVE-2006-1790EPSS 5%

A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the In…

Mitigation only
Fix from $1,950 2006-04-14
Firefox HIGH 9.3
CVE-2006-0748EPSS 8%

Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote atta…

Mitigation only
Fix from $1,950 2006-04-14
Firefox HIGH 9.3
CVE-2006-0749EPSS 10%

nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0…

Fix: 1.0 / 1.0.8+
Fix from $1,950 2006-04-14
X Doom MEDIUM 5.0
CVE-2006-1593

The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote…

Fix: after 1.08.01
Fix from $1,600 2006-04-03
Mailenable Enterprise MEDIUM 5.0
CVE-2006-1338

Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU c…

Patch available
Fix from $1,600 2006-03-21
Ggz Gaming Zone MEDIUM 5.0
CVE-2006-1275

GGZ Gaming Zone 0.0.12 allows remote attackers to cause a denial of service (client disconnect) via inputs that produce malformed XML, including (1) …

No fix yet
Fix from $1,600 2006-03-19