2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2006-0869——Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Reposito...
CVE-2006-0860——Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow...
CVE-2006-0870——SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute ar...
CVE-2006-0859——Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestb...
CVE-2006-0858——Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified ins...
CVE-2006-0857——Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary...
CVE-2006-0720——Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service...
CVE-2006-0855——Stack-based buffer overflow in the fullpath function in misc.c for zoo 2.10 and earlier, as used in products such as Bar...
CVE-2006-0812——The VisNetic AntiVirus Plug-in (DKAVUpSch.exe) for Mail Server 4.6.0.4, 4.6.1.1, and possibly other versions before 4.6....
CVE-2006-0803——The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is...
CVE-2006-0850——SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execu...
CVE-2006-0854——PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to incl...
CVE-2006-0853——Buffer overflow in the IMAP service of TrueNorth Internet Anywhere (IA) eMailserver 5.3.4 allows remote authenticated us...
CVE-2006-0852——Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute ...
CVE-2006-0851——SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitra...
CVE-2006-0848——The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to ex...
CVE-2006-0840——manage_user_page.php in Mantis 1.00rc4 and earlier does not properly handle a sort parameter containing a ' (quote) char...
CVE-2006-0841——Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4 and earlier allow remote attackers to inject arbit...
CVE-2006-0836——Mozilla Thunderbird 1.5 allows user-assisted attackers to cause an unspecified denial of service by tricking the user in...
CVE-2006-0842——Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or...
CVE-2006-0847——Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read...
CVE-2006-0846——Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitr...
CVE-2006-0845——Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs...
CVE-2006-0844——Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which a...
CVE-2006-0843——Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now