2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2006-3381——SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then di...
CVE-2006-3355——Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code vi...
CVE-2006-3356——The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to caus...
CVE-2006-3357——Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote at...
CVE-2006-3358——Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject ar...
CVE-2006-3359——Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web s...
CVE-2006-3360——Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of...
CVE-2006-3361——PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote ...
CVE-2006-3362——Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) G...
CVE-2006-3363——PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to ex...
CVE-2006-3364——SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execut...
CVE-2006-3365——V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2)...
CVE-2006-3366——Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or ...
CVE-2006-3367——Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web document root with insufficient access control, wh...
CVE-2006-3368——Efone 20000723 stores config.inc under the web document root with insufficient access control, which allows remote attac...
CVE-2006-3369——Kamikaze-QSCM 0.1 stores config.inc under the web document root with insufficient access control, which allows remote at...
CVE-2006-3380——Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service...
CVE-2006-3378——passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the re...
CVE-2006-3377——Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlie...
CVE-2006-3379——Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to...
CVE-2006-3376——Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype...
CVE-2006-3375——PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute ...
CVE-2006-3374——PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attacke...
CVE-2006-3373——Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary file...
CVE-2006-3372——Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttribu...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now