CVE-2006-4775
published 2006-09-14CVE-2006-4775: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a…
high7.8CVSS 3.1
AVNACLAuNCNINAC
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a revision value of 0x7FFFFFFF, which is incremented to 0x80000000 and is interpreted as a negative number in a signed context.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-w58x-5ghh-784p: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
ghsa_unreviewed·2022-05-01
CVE-2006-4775 [HIGH] GHSA-w58x-5ghh-784p: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a revision value of 0x7FFFFFFF, which is incremented to 0x80000000 and is interpreted as a negative number in a signed context.
GHSA
GHSA-x2rx-8768-8678: Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2005-4826 [HIGH] GHSA-x2rx-8768-8678: Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12
Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CVE-2006-4774, CVE-2006-4775, and CVE-2006-4776.
Red Hat
phpMyAdmin: XSS issue in pmd_pdf.php via db parameter with register_globals enabled
vendor_redhat·2008-10-27·CVSS 6.8
CVE-2008-4775 [MEDIUM] CWE-79 phpMyAdmin: XSS issue in pmd_pdf.php via db parameter with register_globals enabled
phpMyAdmin: XSS issue in pmd_pdf.php via db parameter with register_globals enabled
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a different vector than CVE-2006-6942 and CVE-2007-5977.
Cisco
Cisco IOS VTP Integer Wrap Denial of Service Vulnerability
vendor_cisco·2006-09-13·CVSS 7.8
CVE-2006-4775 [HIGH] CWE-399 Cisco IOS VTP Integer Wrap Denial of Service Vulnerability
Cisco IOS VTP Integer Wrap Denial of Service Vulnerability
Cisco IOS and Cisco Catalyst OS contain an integer overflow vulnerability that could allow an authenticated, remote attacker to cause affected devices to stop processing configuration changes, possibly resulting in a denial of service (DoS) condition.
This vulnerability exists due to an integer overflow error within the statistics counters. An authenticated, remote attacker could exploit this vulnerability by sending a spoofed VTP summary packet to the affected device, causing the VTP statistics parameter to wrap to a negative number. This condition could prevent the affected device from processing further configuration changes. Under some circumstances, this could prevent the device from responding to further requests, resulting
No detection rules found.
http://secunia.com/advisories/21896http://secunia.com/advisories/21902http://securitytracker.com/id?1016843http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtmlhttp://www.kb.cert.org/vuls/id/175148http://www.osvdb.org/28776http://www.phenoelit.de/stuff/CiscoVTP.txthttp://www.securityfocus.com/archive/1/445896/100/0/threadedhttp://www.securityfocus.com/archive/1/445938/100/0/threadedhttp://www.securityfocus.com/bid/19998http://www.vupen.com/english/advisories/2006/3600https://exchange.xforce.ibmcloud.com/vulnerabilities/28925http://secunia.com/advisories/21896http://secunia.com/advisories/21902http://securitytracker.com/id?1016843http://www.cisco.com/warp/public/707/cisco-sr-20060913-vtp.shtmlhttp://www.kb.cert.org/vuls/id/175148http://www.osvdb.org/28776http://www.phenoelit.de/stuff/CiscoVTP.txthttp://www.securityfocus.com/archive/1/445896/100/0/threadedhttp://www.securityfocus.com/archive/1/445938/100/0/threadedhttp://www.securityfocus.com/bid/19998http://www.vupen.com/english/advisories/2006/3600https://exchange.xforce.ibmcloud.com/vulnerabilities/28925
2006-09-14
Published