2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-3400Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) ...
CVE-2006-3401Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause...
CVE-2006-3402SQL injection vulnerability in VirtuaStore 2.0 allows remote attackers to execute arbitrary SQL commands via the passwor...
CVE-2006-3404Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attack...
CVE-2006-3373Unspecified vulnerability in the client/bin/logfetch script in Hobbit 4.2-beta allows local users to read arbitrary file...
CVE-2006-3372Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttribu...
CVE-2006-3371Eupla Foros 1.0 stores the inc/config.inc file under the web document root with insufficient access control, which allow...
CVE-2006-3370Blueboy 1.0.3 stores bb_news_config.inc under the web document root with insufficient access control, which allows remot...
CVE-2006-3369Kamikaze-QSCM 0.1 stores config.inc under the web document root with insufficient access control, which allows remote at...
CVE-2006-3368Efone 20000723 stores config.inc under the web document root with insufficient access control, which allows remote attac...
CVE-2006-3367Mp3 JudeBox Server (Mp3NetBox) Beta 1 stores config.inc under the web document root with insufficient access control, wh...
CVE-2006-3366Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or ...
CVE-2006-3365V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2)...
CVE-2006-3364SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execut...
CVE-2006-3363PHP remote file inclusion vulnerability in index.php in the Glossaire module 1.7 for Xoops allows remote attackers to ex...
CVE-2006-3362Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) G...
CVE-2006-3361PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote ...
CVE-2006-3360Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of...
CVE-2006-3359Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web s...
CVE-2006-3358Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject ar...
CVE-2006-3357Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote at...
CVE-2006-3356The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to caus...
CVE-2006-3355Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code vi...
CVE-2006-3376Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype...
CVE-2006-3377Cross-site scripting (XSS) vulnerability in JMB Software AutoRank PHP 3.02 and earlier, and AutoRank Pro 5.01 and earlie...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now