Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-1305

Published Dec 31, 2006

Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail he…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4097

Published Dec 31, 2006

Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4098

Published Dec 31, 2006

Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4220

Published Dec 31, 2006

Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4575

Published Dec 31, 2006

Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4576

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in The Address Book 1.04e allows remote attackers to inject arbitrary web script or HTML by uploading the HTML file with a GIF or JPG exte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4577

Published Dec 31, 2006

Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4578

Published Dec 31, 2006

export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4579

Published Dec 31, 2006

Directory traversal vulnerability in users.php in The Address Book 1.04e allows remote attackers to include arbitrary files via a .. (dot dot) in the language parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4580

Published Dec 31, 2006

register.php in The Address Book 1.04e allows remote attackers to bypass the "Allow User Self-Registration" setting and create arbitrary users by setting the mode parameter to "co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4581

Published Dec 31, 2006

Unrestricted file upload vulnerability in The Address Book 1.04e validates the Content-Type header but not the file extension, which allows remote attackers to upload arbitrary PH…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4582

Published Dec 31, 2006

Cross-site request forgery (CSRF) vulnerability in The Address Book 1.04e allows remote attackers to perform unauthorized actions as other users via unspecified vectors, as demons…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4695

Published Dec 31, 2006

Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Of…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4727

Published Dec 31, 2006

Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remot…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5265

Published Dec 31, 2006

Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5266

Published Dec 31, 2006

Multiple buffer overflows in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allow remote attackers to execute arbitrary code via (1) a crafted Distributed Process M…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5749

Published Dec 31, 2006

The isdn_ppp_ccp_reset_alloc_state function in drivers/isdn/isdn_ppp.c in the Linux 2.4 kernel before 2.4.34-rc4 does not call the init_timer function for the ISDN PPP CCP reset s…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5755

Published Dec 31, 2006

Linux kernel before 2.6.18, when running on x86_64 systems, does not properly save or restore EFLAGS during a context switch, which allows local users to cause a denial of service…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5857

Published Dec 31, 2006

Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corruption and overwrites a subroutine…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5867

Published Dec 31, 2006

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5870

Published Dec 31, 2006

Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow user-assisted remote attackers to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5974

Published Dec 31, 2006

fetchmail 6.3.5 and 6.3.6 before 6.3.6-rc4, when refusing a message delivered via the mda option, allows remote attackers to cause a denial of service (crash) via unknown vectors…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6101

Published Dec 31, 2006

Integer overflow in the ProcRenderAddGlyphs function in the Render extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary co…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 6,608 CVEsPage 1 of 265