Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-6505

Published Dec 20, 2006

Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary code via (1) external message mod…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6506

Published Dec 20, 2006

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6507

Published Dec 20, 2006

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6641

Published Dec 20, 2006

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion B…

CVSS 7.5 · High

CVE-2006-6636

Published Dec 19, 2006

Unspecified vulnerability in the Utility Classes for IBM WebSphere Application Server (WAS) before 5.1.1.13 and 6.x before 6.0.2.17 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6637

Published Dec 19, 2006

The Servlet Engine and Web Container in IBM WebSphere Application Server (WAS) before 6.0.2.17, when ibm-web-ext.xmi sets fileServingEnabled to true and servlet caching is enabled…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6638

Published Dec 19, 2006

IBM DB2 8.1 before FixPak 14 allows remote attackers to cause a denial of service via a crafted SQLJRA packet, which causes a NULL pointer dereference in the sqle_db2ra_as_recvreq…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6639

Published Dec 19, 2006

Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail progra…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6640

Published Dec 19, 2006

Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3896

Published Dec 19, 2006

The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6106

Published Dec 19, 2006

Multiple buffer overflows in the cmtp_recv_interopmsg function in the Bluetooth driver (net/bluetooth/cmtp/capi.c) in the Linux kernel 2.4.22 up to 2.4.33.4 and 2.6.2 before 2.6.1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6617

Published Dec 18, 2006

projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database via a GetInitializati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6624

Published Dec 18, 2006

The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) via a long series of "./" sequences in the SIZE command.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6625

Published Dec 18, 2006

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE:…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6626

Published Dec 18, 2006

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6628

Published Dec 18, 2006

Integer overflow in OpenOffice.org (OOo) 2.1 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted DOC file, as demonstrated by the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6629

Published Dec 18, 2006

lib/WeBWorK/PG/Translator.pm in WeBWorK Program Generation (PG) Language before 2.3.1 uses an insufficiently restrictive regular expression to determine valid macro filenames, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 6,608 CVEsPage 14 of 265