2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-0922CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.i...
CVE-2006-0923Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject...
CVE-2006-0924Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script ...
CVE-2006-0925Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to...
CVE-2006-0926Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt...
CVE-2006-0927Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burnin...
CVE-2006-0928The POP3 Server in ArGoSoft Mail Server Pro 1.8 allows remote attackers to obtain sensitive information via the _DUMP co...
CVE-2006-0929Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated use...
CVE-2006-0930Directory traversal vulnerability in Webmail in ArGoSoft Mail Server Pro 1.8 allows remote authenticated users to read a...
CVE-2006-0931Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to ...
CVE-2006-0932Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwr...
CVE-2006-0933Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML vi...
CVE-2006-0935Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demo...
CVE-2006-0936Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and exec...
CVE-2006-0937U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with metho...
CVE-2006-0907SQL injection vulnerability in PHP-Nuke before 7.8 Patched 3.2 allows remote attackers to execute arbitrary SQL commands...
CVE-2006-0908PHP-Nuke 7.8 Patched 3.2 allows remote attackers to bypass SQL injection protection mechanisms via /%2a (/*) sequences w...
CVE-2006-0906SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid para...
CVE-2006-0903MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character...
CVE-2006-0736Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enter...
CVE-2006-0901Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial ...
CVE-2006-0899Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include ...
CVE-2006-0900nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demo...
CVE-2006-0888index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp...
CVE-2006-0890Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.44...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now