Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-6671

Published Dec 21, 2006

SQL injection vulnerability in down.asp in Burak Yylmaz Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6672

Published Dec 21, 2006

Multiple SQL injection vulnerabilities in Burak Yylmaz Download Portal allow remote attackers to execute arbitrary SQL commands via the (1) kid or possibly (2) id parameter to (a)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6673

Published Dec 21, 2006

WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6674

Published Dec 21, 2006

Ozeki HTTP-SMS Gateway 1.0, and possibly earlier, stores usernames and passwords in plaintext in the HKLM\Software\Ozeki\SMSServer\CurrentVersion\Plugins\httpsmsgate registry key,…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6675

Published Dec 21, 2006

Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or H…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6676

Published Dec 21, 2006

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB fi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6677

Published Dec 21, 2006

ESET NOD32 Antivirus before 1.1743 allows remote attackers to cause a denial of service (crash) via a crafted .CHM file that triggers a divide-by-zero error.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6678

Published Dec 21, 2006

The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6660

Published Dec 20, 2006

The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malforme…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6661

Published Dec 20, 2006

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via mult…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6663

Published Dec 20, 2006

The server component in Marathon Aleph One before 0.17.1 and 2006-12-17 allows remote attackers to cause a denial of service (application crash) via unspecified vectors related to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6664

Published Dec 20, 2006

Format string vulnerability in Marathon Aleph One before 0.17.1 and 2006-12-17 might allow remote attackers to cause a denial of service (application crash) or execute arbitrary c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6665

Published Dec 20, 2006

Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name tag in a dbr file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6666

Published Dec 20, 2006

PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via a URL in the q parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6667

Published Dec 20, 2006

Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) rep…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6668

Published Dec 20, 2006

Cross-site scripting (XSS) vulnerability in VerliAdmin 0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenanc…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6669

Published Dec 20, 2006

Cross-site scripting (XSS) vulnerability in export_handler.php in WebCalendar 1.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the format param…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6670

Published Dec 20, 2006

Unspecified vulnerability in Nortel CallPilot 4.x Server has unknown impact and attack vectors, aka P-2006-0011-GLOBAL.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4814

Published Dec 20, 2006

The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlo…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5681

Published Dec 20, 2006

QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6475

Published Dec 20, 2006

FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode with SSL enabled, allows remote attackers to cause a denial of service (refused connections) via…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6476

Published Dec 20, 2006

FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, wh…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6477

Published Dec 20, 2006

FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a c…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6642

Published Dec 20, 2006

SQL injection vulnerability in haber.asp in Contra Haber Sistemi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 6,608 CVEsPage 12 of 265