Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-6712

Published Dec 23, 2006

Cross-site scripting (XSS) vulnerability in SugarCRM Open Source 4.5.0f and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in craft…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6713

Published Dec 23, 2006

Buffer overflow in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allows remote attackers to execute arbitrary code v…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6714

Published Dec 23, 2006

Multiple memory leaks in Hitachi Directory Server 2 P-2444-A124 before 02-11-/K on Windows, and P-1B44-A121 before 02-10-/V on HP-UX, allow remote attackers to cause a denial of s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6715

Published Dec 23, 2006

PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code v…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6698

Published Dec 22, 2006

The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on the username, even when GCONF_GLOBAL_LOCKS is not set, which allows local u…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6697

Published Dec 22, 2006

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6686

Published Dec 21, 2006

PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6687

Published Dec 21, 2006

Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6688

Published Dec 21, 2006

Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET) allows remote attackers to bypass filtering mechanisms via unknown vectors. NOTE:…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6689

Published Dec 21, 2006

Multiple PHP remote file inclusion vulnerabilities in Paristemi 0.8.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the SERVER_DIRECTORY parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6690

Published Dec 21, 2006

rtehtmlarea/pi1/class.tx_rtehtmlarea_pi1.php in Typo3 4.0.0 through 4.0.3, 3.7 and 3.8 with the rtehtmlarea extension, and 4.1 beta allows remote authenticated users to execute ar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6691

Published Dec 21, 2006

Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the commonIncludeP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6692

Published Dec 21, 2006

Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format st…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6693

Published Dec 21, 2006

Multiple buffer overflows in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long strings to the (1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6694

Published Dec 21, 2006

Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6695

Published Dec 21, 2006

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) error or (2…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6104

Published Dec 21, 2006

The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by appen…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6679

Published Dec 21, 2006

Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6680

Published Dec 21, 2006

Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6681

Published Dec 21, 2006

Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6682

Published Dec 21, 2006

Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6683

Published Dec 21, 2006

Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the PAM configuration, which might…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6684

Published Dec 21, 2006

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd before 2.4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6685

Published Dec 21, 2006

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 6,608 CVEsPage 11 of 265