2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-7214——Multiple unspecified vulnerabilities in Firebird 1.5 allow remote attackers to (1) cause a denial of service (applicatio...
CVE-2006-5752——Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when Ex...
CVE-2006-7210——Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a...
CVE-2006-7209——Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbi...
CVE-2006-7208——PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB co...
CVE-2006-7207——Buffer overflow in ageet AGEphone before 1.4.0 might allow remote attackers to have an unknown impact via unspecified ve...
CVE-2006-7206——Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating...
CVE-2006-4168——Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote...
CVE-2006-3974——Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 all...
CVE-2006-7205——The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a den...
CVE-2006-7204——The imap_body function in PHP before 4.4.4 does not implement safemode or open_basedir checks, which allows local users ...
CVE-2006-3894——The RSA Crypto-C before 6.3.1 and Cert-C before 2.8 libraries, as used by RSA BSAFE, multiple Cisco products, and other ...
CVE-2006-7203——The compat_sys_mount function in fs/compat.c in Linux kernel 2.6.20 and earlier allows local users to cause a denial of ...
CVE-2006-3456——The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVir...
CVE-2006-7195——Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through...
CVE-2006-7196——Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0...
CVE-2006-7202——The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, wh...
CVE-2006-7199——EMC RSA Security SiteKey allows remote attackers to display the correct image via a man-in-the-middle (MITM) attack in w...
CVE-2006-7200——EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end us...
CVE-2006-7201——EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared obj...
CVE-2006-7198——Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 5.1.1.14, and WAS for z/OS 601 before 6.0.2.1...
CVE-2006-4520——ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a ne...
CVE-2006-7197——The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the...
CVE-2006-7194——PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_glob...
CVE-2006-7193——PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute a...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now