2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-0669Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQ...
CVE-2006-0672Unspecified vulnerability in HP PSC 1210 All-in-One Drivers before 1.0.06 has unknown impact and attack vectors.
CVE-2006-0671Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of s...
CVE-2006-0600elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with...
CVE-2006-0664Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inje...
CVE-2006-0659Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen en...
CVE-2006-0665Unspecified vulnerability in (1) query_store.php and (2) manage_proj_create.php in Mantis before 1.0.0 has unknown impac...
CVE-2006-0046squid_redirect script in adzapper before 2006-01-29 allows remote attackers to cause a denial of service (CPU consumptio...
CVE-2006-0056Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2...
CVE-2006-0661Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to injec...
CVE-2006-0647LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attac...
CVE-2006-0648Multiple directory traversal vulnerabilities in PHP iCalendar 2.0.1, 2.1, and 2.2 allow remote attackers to include arbi...
CVE-2006-0649Cross-site scripting (XSS) vulnerability in DataparkSearch before 4.37 allows remote attackers to inject arbitrary web s...
CVE-2006-0650Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scri...
CVE-2006-0651SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID ...
CVE-2006-0652WHMCompleteSolution (WHMCS) before 2.3 assigns incorrect permissions to "resellers", which allows remote authenticated u...
CVE-2006-0653Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary S...
CVE-2006-0654check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attack...
CVE-2006-0655Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht...
CVE-2006-0656Directory traversal vulnerability in HP Systems Insight Manager 4.2 through 5.0 SP3 for Windows allows remote attackers ...
CVE-2006-0657Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inje...
CVE-2006-0658Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows...
CVE-2006-0599The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether...
CVE-2006-0663Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers t...
CVE-2006-0598Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now