2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-0662Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary...
CVE-2006-0660Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary ...
CVE-2006-0597Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of servi...
CVE-2006-0646ld in SUSE Linux 9.1 through 10.0, and SLES 9, in certain circumstances when linking binaries, can leave an empty RPATH ...
CVE-2006-0645Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) G...
CVE-2006-0643Cross-site scripting (XSS) vulnerability in WiredRed e/pop Web Conferencing 4.1.0.755 allows remote authenticated users ...
CVE-2006-0644Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 al...
CVE-2006-0635Tiny C Compiler (TCC) 0.9.23 (aka TinyCC) evaluates the "i>sizeof(int)" expression to false when i equals -1, which migh...
CVE-2006-0638SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, wit...
CVE-2006-0640Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command t...
CVE-2006-0630RITLabs The Bat! before 3.0.0.15 displays certain important headers from encapsulated data in message/partial MIME messa...
CVE-2006-0636desktop.php in eyeOS 0.8.9 and earlier tests for the existence of the _SESSION variable before calling the session_start...
CVE-2006-0631CRLF injection vulnerability in mailback.pl in Erik C. Thauvin mailback allows remote attackers to use mailback as a "sp...
CVE-2006-0639Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with ...
CVE-2006-0632The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activatio...
CVE-2006-0637Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IM...
CVE-2006-0629Unspecified vulnerability in AOL Instant Messenger (AIM) 5.9.3861 allows user-assisted remote attackers to cause a denia...
CVE-2006-0633The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially...
CVE-2006-0628myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the ...
CVE-2006-0641Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing th...
CVE-2006-0634Borland C++Builder 6 (BCB6) with Update Pack 4 Enterprise edition (ent_upd4) evaluates the "i>sizeof(int)" expression to...
CVE-2006-0642Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a...
CVE-2006-0627Cross-site scripting (XSS) vulnerability in Clever Copy 2.0, 2.0a, and 3.0 allows remote attackers to inject arbitrary w...
CVE-2006-0626SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitra...
CVE-2006-0625Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include ...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now