2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-0394Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-0848. Reason: This candidate is a duplicate of...
CVE-2006-0947Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via s...
CVE-2006-0946Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers...
CVE-2006-0945PHP remote file include vulnerability in admin/index.php in Archangel Weblog 0.90.02 allows remote authenticated adminis...
CVE-2006-0944Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.
CVE-2006-0943SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbit...
CVE-2006-0942SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to exe...
CVE-2006-0941Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbi...
CVE-2006-0938Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web...
CVE-2006-0940Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to e...
CVE-2006-0939SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id...
CVE-2006-0934Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web scrip...
CVE-2006-0909Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request ...
CVE-2006-0910Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to ...
CVE-2006-0911NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumptio...
CVE-2006-0912Oreka before 0.5 allows remote attackers to cause a denial of service (application crash) via a "certain RTP sequence."
CVE-2006-0913SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users...
CVE-2006-0914Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold par...
CVE-2006-0915Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameter...
CVE-2006-0916Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form...
CVE-2006-0917Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive infor...
CVE-2006-0918Buffer overflow in RITLabs The Bat! 3.60.07 allows remote attackers to execute arbitrary code via a long Subject field.
CVE-2006-0919SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remot...
CVE-2006-0920Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, wh...
CVE-2006-0921Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, a...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now