2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-3378passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the re...
CVE-2006-3379Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to...
CVE-2006-3381SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then di...
CVE-2006-3374PHP remote file inclusion vulnerability in index.php in Randshop 1.2 and earlier, including 0.9.3, allows remote attacke...
CVE-2006-3375PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote attackers to execute ...
CVE-2006-3351Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a deni...
CVE-2006-3352Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domain...
CVE-2006-3353Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun...
CVE-2006-3354Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter propert...
CVE-2006-3336TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenam...
CVE-2006-2910Buffer overflow in jetAudio 6.2.6.8330 (Basic), and possibly other versions, allows user-assisted attackers to execute a...
CVE-2006-2935The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, ...
CVE-2006-2194The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which...
CVE-2006-3349Multiple SQL injection vulnerabilities in SmS Script allow remote attackers to execute arbitrary SQL commands via the Ca...
CVE-2006-3348Multiple SQL injection vulnerabilities in HSPcomplete 3.2.2 and 3.3 Beta and earlier allow remote attackers to execute a...
CVE-2006-3347SQL injection vulnerability in index.php in deV!Lz Clanportal DZCP 1.3.4 allows remote attackers to execute arbitrary SQ...
CVE-2006-3346SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2006-3345Cross-site scripting (XSS) vulnerability in AliPAGER, possibly 1.5 and earlier, allows remote attackers to inject arbitr...
CVE-2006-3344Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using...
CVE-2006-3338Cross-site scripting (XSS) vulnerability in Atlassian JIRA 3.6.2-#156 allows remote attackers to inject arbitrary web sc...
CVE-2006-3337Cross-site scripting (XSS) vulnerability in frontend/x/files/select.html in cPanel 10.8.2-CURRENT 118 and earlier allows...
CVE-2006-3343PHP remote file inclusion vulnerability in recipe/cookbook.php in CrisoftRicette 1.0pre15b allows remote attackers to ex...
CVE-2006-3342Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 and earlier allows remote attackers to inject arbi...
CVE-2006-3341SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp for Xoops allows remote attackers to execute arbi...
CVE-2006-3340Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is ena...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now