2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-0436Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown at...
CVE-2006-0426BEA WebLogic Server and WebLogic Express 8.1 through SP4, when configuration auditing is enabled and a password change o...
CVE-2006-0419BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6 allows anonymous binds to the embedde...
CVE-2006-0424BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticat...
CVE-2006-0423BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config...
CVE-2006-0422Multiple unspecified vulnerabilities in BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6...
CVE-2006-0421By design, BEA WebLogic Server and WebLogic Express 7.0 and 6.1, when creating multiple domains from the same WebLogic i...
CVE-2006-0420BEA WebLogic Server and WebLogic Express 8.1 through SP4 and 7.0 through SP6 does not properly handle when servlets use ...
CVE-2006-0432Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0, when an Administrator uses the WebLogic Admin...
CVE-2006-0431Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain th...
CVE-2006-0430Certain configurations of BEA WebLogic Server and WebLogic Express 9.0, 8.1 through SP5, and 7.0 through SP6, when conne...
CVE-2006-0428Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), al...
CVE-2006-0427Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or s...
CVE-2006-0425BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via un...
CVE-2006-0429BEA WebLogic Server and WebLogic Express 9.0 causes new security providers to appear active even if they have not been a...
CVE-2006-0379FreeBSD kernel 5.4-STABLE and 6.0 does not completely initialize a buffer before making it available to userland, which ...
CVE-2006-0380A logic error in FreeBSD kernel 5.4-STABLE and 6.0 causes the kernel to calculate an incorrect buffer length, which caus...
CVE-2006-0381A logic error in the IP fragment cache functionality in pf in FreeBSD 5.3, 5.4, and 6.0, and OpenBSD, when a 'scrub frag...
CVE-2006-0414Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large...
CVE-2006-0418Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a craft...
CVE-2006-0417SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remot...
CVE-2006-0416SleeperChat 0.3f and earlier allows remote attackers to bypass authentication and create new entries via the txt paramet...
CVE-2006-0415Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject ...
CVE-2006-0413Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands ...
CVE-2006-0412SQL injection vulnerability in CyberShop allows remote attackers to execute arbitrary SQL commands and bypass authentica...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now