2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-0364Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web scrip...
CVE-2006-0363The "Remember my Password" feature in MSN Messenger 7.5 stores passwords in an encrypted format under the HKEY_CURRENT_U...
CVE-2006-0362TippingPoint Intrusion Prevention System (IPS) TOS before 2.1.4.6324, and TOS 2.2.x before 2.2.1.6506, allow remote atta...
CVE-2006-0376The 802.11 wireless client in certain operating systems including Windows 2000, Windows XP, and Windows Server 2003 does...
CVE-2006-0361Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrar...
CVE-2006-0360MPM SIP HP-180W Wireless IP Phone WE.00.17 allows remote attackers to obtain sensitive information and possibly cause a ...
CVE-2006-0359Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device cr...
CVE-2006-0358Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute ...
CVE-2006-0357Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified d...
CVE-2006-0356Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER co...
CVE-2006-0355Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a lo...
CVE-2006-0354Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial ...
CVE-2006-0375Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Net...
CVE-2006-0374Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports...
CVE-2006-0353unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users...
CVE-2006-0351Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.
CVE-2006-0350Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML vi...
CVE-2006-0349SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id paramete...
CVE-2006-0352The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient ac...
CVE-2006-0347Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the ...
CVE-2006-0346Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML...
CVE-2006-0345Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the...
CVE-2006-0348Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial...
CVE-2006-0329SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execut...
CVE-2006-0344Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arb...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now