2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-6984Cross-domain vulnerability in GreenBrowser 3.4.0622 allows remote attackers to access restricted information from other ...
CVE-2006-6983Cross-domain vulnerability in MYweb4net Browser 3.8.8.0 allows remote attackers to access restricted information from ot...
CVE-2006-6986Cross-domain vulnerability in PhaseOut 5.4.4 allows remote attackers to access restricted information from other domains...
CVE-2006-6992Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other do...
CVE-2006-6980The magnatune.com album browser in Amarok allows attackers to cause a denial of service (application crash) via unspecif...
CVE-2006-6979The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably includin...
CVE-2006-69813proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blo...
CVE-2006-69823proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with inco...
CVE-2006-6978Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execut...
CVE-2006-6977Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FreeTextBox allows remote attackers to exec...
CVE-2006-6976PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to...
CVE-2006-2219phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which ...
CVE-2006-2220phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote ...
CVE-2006-6975CRITICAL9.8PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arb...
CVE-2006-6972SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands...
CVE-2006-6973Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administra...
CVE-2006-6974Headstart Solutions DeskPRO stores sensitive information under the web root with insufficient access control, which allo...
CVE-2006-6969Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identif...
CVE-2006-6970Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the en...
CVE-2006-6971Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection me...
CVE-2006-1167SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local ...
CVE-2006-6968Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow...
CVE-2006-6966phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value...
CVE-2006-6967Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configur...
CVE-2006-6535The dev_queue_xmit function in Linux kernel 2.6 can fail before calling the local_bh_disable function, which could lead ...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now