2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-6944phpMyAdmin before 2.9.1.1 allows remote attackers to bypass Allow/Deny access rules that use IP addresses via false head...
CVE-2006-5963Directory traversal vulnerability in PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221 allows user-assisted remote attacke...
CVE-2006-5964choShilA.bpl in PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221 allows local users, and user-assisted remote attackers t...
CVE-2006-6941index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action...
CVE-2006-6489The SISCO OSI stack, as used in SISCO MMS-EASE, ICCP Toolkit for MMS-EASE, AX-S4 MMS and AX-S4 ICCP, and possibly other ...
CVE-2006-6491Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2006-6492Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2006-6940Buffer overflow in the ParseHeader function in clsOWA.cls in POP3/SMTP to OWA (pop2owa) 1.1.3 allows remote attackers to...
CVE-2006-6937SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQ...
CVE-2006-6938Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote ...
CVE-2006-6936Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or...
CVE-2006-6939GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files, possibly in t...
CVE-2006-6935SQL injection vulnerability in the login component in Portix-PHP 0.4.2 allows remote attackers to execute arbitrary SQL ...
CVE-2006-6934Multiple cross-site scripting (XSS) vulnerabilities in Portix-PHP 0.4.2 allow remote attackers to inject arbitrary web s...
CVE-2006-6933Easy Chat Server 2.1 stores sensitive information under the web root with insufficient access control, which allows remo...
CVE-2006-6932Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary...
CVE-2006-6931Algorithmic complexity vulnerability in Snort before 2.6.1, during predicate evaluation in rule matching for certain rul...
CVE-2006-5171Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup ...
CVE-2006-5172Stack-based buffer overflow in the RPC interface in Mediasvr.exe in Computer Associates (CA) Brightstor ARCserve Backup ...
CVE-2006-6487Cross-site scripting (XSS) vulnerability in index.php in DT Guestbook (dt_guestbook) 1.0f, when register_globals is enab...
CVE-2006-5876The soup_headers_parse function in soup-headers.c for libsoup HTTP library before 2.2.99 allows remote attackers to caus...
CVE-2006-6767HIGH7.5oftpd before 0.3.7 allows remote attackers to cause a denial of service (daemon abort) via a (1) LPRT or (2) LPASV comma...
CVE-2006-6928Multiple cross-site scripting (XSS) vulnerabilities in Rialto 1.6 allow remote attackers to inject arbitrary web script ...
CVE-2006-6927Multiple SQL injection vulnerabilities in Rialto 1.6 allow remote attackers to execute arbitrary SQL commands via (1) th...
CVE-2006-6926Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack. NOTE: The pr...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now