2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-6990——Cross-domain vulnerability in Enigma Browser 3.8.8 allows remote attackers to access restricted information from other d...
CVE-2006-6991——Cross-domain vulnerability in Fast Browser Pro 8.1 allows remote attackers to access restricted information from other d...
CVE-2006-6986——Cross-domain vulnerability in PhaseOut 5.4.4 allows remote attackers to access restricted information from other domains...
CVE-2006-6992——Cross-domain vulnerability in GoSuRF Browser 2.62 allows remote attackers to access restricted information from other do...
CVE-2006-6979——The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably includin...
CVE-2006-6980——The magnatune.com album browser in Amarok allows attackers to cause a denial of service (application crash) via unspecif...
CVE-2006-6982——3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with inco...
CVE-2006-6981——3proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blo...
CVE-2006-6978——Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execut...
CVE-2006-6977——Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FreeTextBox allows remote attackers to exec...
CVE-2006-6976——PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to...
CVE-2006-2219——phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which ...
CVE-2006-2220——phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote ...
CVE-2006-6975CRITICAL9.8PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arb...
CVE-2006-6972——SQL injection in torrents.php in BtitTracker 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands...
CVE-2006-6974——Headstart Solutions DeskPRO stores sensitive information under the web root with insufficient access control, which allo...
CVE-2006-6973——Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administra...
CVE-2006-6969——Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identif...
CVE-2006-6971——Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection me...
CVE-2006-6970——Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the en...
CVE-2006-1167——SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local ...
CVE-2006-6968——Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow...
CVE-2006-6966——phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value...
CVE-2006-6967——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configur...
CVE-2006-5753——Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local user...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now