2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-2479The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allo...
CVE-2006-2476Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows ...
CVE-2006-2477Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attacke...
CVE-2006-2474SQL injection vulnerability in lshop.cgi in Cosmoshop 8.11.106 and earlier allows remote attackers to execute arbitrary ...
CVE-2006-2478Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a H...
CVE-2006-2460Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variable...
CVE-2006-2459SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to exec...
CVE-2006-2466BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages durin...
CVE-2006-2471Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive inf...
CVE-2006-2470Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console...
CVE-2006-2469The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and pa...
CVE-2006-2468The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain na...
CVE-2006-2467BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 displays the internal IP address of the WebLogic ser...
CVE-2006-2465Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if ...
CVE-2006-2464stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrato...
CVE-2006-2463view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain requ...
CVE-2006-2462BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure cha...
CVE-2006-2461BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, whi...
CVE-2006-2472Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allo...
CVE-2006-2458Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code...
CVE-2006-1528Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver...
CVE-2006-1855choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a ...
CVE-2006-2440Heap-based buffer overflow in the libMagick component of ImageMagick 6.0.6.2 might allow attackers to execute arbitrary ...
CVE-2006-2442kphone 4.2 creates .qt/kphonerc with world-readable permissions, which allows local users to read usernames and SIP pass...
CVE-2006-2443The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local us...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now