2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2006-0652——WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated u...
CVE-2006-0651——SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID ...
CVE-2006-0650——Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scri...
CVE-2006-0649——Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web s...
CVE-2006-0648——Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbi...
CVE-2006-0647——LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attac...
CVE-2006-0600——elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with...
CVE-2006-0599——The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether...
CVE-2006-0598——Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when...
CVE-2006-0046——squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumptio...
CVE-2006-0056——Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2...
CVE-2006-0661——Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to injec...
CVE-2006-0597——Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of servi...
CVE-2006-0646——ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH ...
CVE-2006-0645——Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) G...
CVE-2006-0638——SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, wit...
CVE-2006-0636——desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start...
CVE-2006-0637——Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IM...
CVE-2006-0629——Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denia...
CVE-2006-0628——myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the ...
CVE-2006-0644——Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 al...
CVE-2006-0643——Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users ...
CVE-2006-0630——RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messa...
CVE-2006-0642——Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a...
CVE-2006-0641——Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing th...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now