2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-7214Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (applicatio...
CVE-2006-5752Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when Ex...
CVE-2006-7210Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a...
CVE-2006-7209Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbi...
CVE-2006-7208PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB co...
CVE-2006-7207Buffer overflow in ageet AGEphone before 1.4.0 might allow remote attackers to have an unknown impact via unspecified ve...
CVE-2006-7206Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating...
CVE-2006-4168Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote...
CVE-2006-3974Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 all...
CVE-2006-7205The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a den...
CVE-2006-7204The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users ...
CVE-2006-3894The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other ...
CVE-2006-7203The compat_sys_mount function in fs/compat.c in Linux kernel 2.6.20 and earlier allows local users to cause a denial of ...
CVE-2006-3456The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVir...
CVE-2006-7195Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through...
CVE-2006-7196Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0...
CVE-2006-7202The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, wh...
CVE-2006-7199EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in w...
CVE-2006-7200EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end us...
CVE-2006-7201EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared obj...
CVE-2006-7198Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.1...
CVE-2006-4520ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a ne...
CVE-2006-7197The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the...
CVE-2006-7194PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_glob...
CVE-2006-7193PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute a...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now