2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-2648Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inj...
CVE-2006-2647Untrusted search path vulnerability in update_flash for IBM AIX 5.1, 5.2 and 5.3 allows local users to execute arbitrary...
CVE-2006-2646Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a lo...
CVE-2006-2645PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote attackers to execu...
CVE-2006-2644AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the confi...
CVE-2006-2643Cross-site scripting (XSS) vulnerability in index.php in Monster Top List (MTL) 1.4 allows remote attackers to inject ar...
CVE-2006-2642** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) ...
CVE-2006-2641** UNVERIFIABLE ** NOTE: this issue does not contain any verifiable or actionable details. Cross-site scripting (XSS) ...
CVE-2006-2640Cross-site scripting (XSS) vulnerability in OmegaMw7a.ASP in OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) allow...
CVE-2006-2639Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote...
CVE-2006-2638SQL injection vulnerability in member.asp in qjForum allows remote attackers to execute arbitrary SQL commands via the u...
CVE-2006-2636newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative acces...
CVE-2006-2637Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1) Morris Guestbook 1, (2) Pretty Guestbook 1, and (3)...
CVE-2006-2632Cross-site scripting (XSS) vulnerability in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to...
CVE-2006-2633Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows ...
CVE-2006-2563The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// requ...
CVE-2006-1174useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to ...
CVE-2006-2453Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of...
CVE-2006-2630Stack-based buffer overflow in Symantec Antivirus 10.1 and Client Security 3.1 allows remote attackers to execute arbitr...
CVE-2006-2631phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the ph...
CVE-2006-2629Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of ...
CVE-2006-1054Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-1861. Reason: This candidate is a reservation ...
CVE-2006-2616SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Dir...
CVE-2006-2618Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1...
CVE-2006-2617(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the in...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now