2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-1135Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script...
CVE-2006-0040GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) vi...
CVE-2006-0667lscfg in IBM AIX 5.2 and 5.3 allows local users to modify arbitrary files via a symlink attack.
CVE-2006-1128Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows r...
CVE-2006-1127Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script...
CVE-2006-1126Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR)...
CVE-2006-1125Grisoft AVG Free 7.1, and other versions including 7.0.308, sets Everyone/Full Control permissions for certain update fi...
CVE-2006-1120Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allo...
CVE-2006-1121Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTM...
CVE-2006-1122Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject a...
CVE-2006-1123SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via t...
CVE-2006-1124Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER ...
CVE-2006-0743Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denia...
CVE-2006-1119fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, w...
CVE-2006-1096Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web sc...
CVE-2006-0742The die_if_kernel function in arch/ia64/kernel/unaligned.c in Linux kernel 2.6.x before 2.6.15.6, possibly when compiled...
CVE-2006-1094SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execut...
CVE-2006-1118SQL injection vulnerability in bmail before Aardvark PR9.1 allows remote attackers to execute arbitrary SQL commands via...
CVE-2006-1117nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Doc...
CVE-2006-1116The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a ...
CVE-2006-1115nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGro...
CVE-2006-1114Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary...
CVE-2006-1113SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL comm...
CVE-2006-1112Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which...
CVE-2006-1111Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now