2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-5990VMWare VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), when se...
CVE-2006-5976Multiple SQL injection vulnerabilities in admin_login.asp in BlogMe 3.0 allow remote attackers to execute arbitrary SQL ...
CVE-2006-5979Renasoft NetJetServer 2.5.3.939, and possibly earlier, uses insecure permissions for Global.asa, which allows remote att...
CVE-2006-5975Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbit...
CVE-2006-5980adm_lgn_admin.asp in Renasoft NetJetServer 2.5.3.939, and possibly earlier, does not properly perform login authenticati...
CVE-2006-5977Multiple SQL injection vulnerabilities in MultiCalendars allow remote attackers to execute arbitrary SQL commands via th...
CVE-2006-5978Unspecified vulnerability in E-Xoopport before 2.2.0 has unknown impact and attack vectors, as addressed by "Some securi...
CVE-2006-5981Multiple directory traversal vulnerabilities in SeleniumServer FTP Server 1.0, and possibly earlier, allow remote attack...
CVE-2006-5982SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which ...
CVE-2006-5983Multiple cross-site scripting (XSS) vulnerabilities in JBMC Software DirectAdmin 1.28.1 allow remote authenticated users...
CVE-2006-5984Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 allow remote authenticated ...
CVE-2006-5985Multiple cross-site scripting (XSS) vulnerabilities in admin/options.php in Extreme CMS 0.9, and possibly earlier, allow...
CVE-2006-5986admin/options.php in Extreme CMS 0.9, and possibly earlier, does not require authentication, which might allow remote at...
CVE-2006-5987SQL injection vulnerability in default.asp in ASPintranet, possibly 1.2, allows remote attackers to execute arbitrary SQ...
CVE-2006-5988Unspecified vulnerability in Windows 2000 Advanced Server SP4 running Active Directory allows remote attackers to cause ...
CVE-2006-5989Off-by-one error in the der_get_oid function in mod_auth_kerb 5.0 allows remote attackers to cause a denial of service (...
CVE-2006-5973Off-by-one buffer overflow in Dovecot 1.0test53 through 1.0.rc14, and possibly other versions, when index files are used...
CVE-2006-4413Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an ...
CVE-2006-5972Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute ...
CVE-2006-5819Verity Ultraseek before 5.7 allows remote attackers to use the server as a proxy for web attacks and host scanning via a...
CVE-2006-5970Verity Ultraseek before 5.7 allows remote attackers to obtain sensitive information via direct requests with (1) a null ...
CVE-2006-5971Absolute path traversal vulnerability in admin/logfile.txt in Verity Ultraseek before 5.6.2 allows remote attackers to r...
CVE-2006-5793The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator o...
CVE-2006-5969CRLF injection vulnerability in the evalFolderLine function in fvwm 2.5.18 and earlier allows local users to execute arb...
CVE-2006-5966Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the ...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now