Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-6603

Published Dec 15, 2006

Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML d…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6604

Published Dec 15, 2006

Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the alias param…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6574

Published Dec 15, 2006

Mantis before 1.1.0a2 does not implement per-item access control for Issue History (Bug History), which allows remote attackers to obtain sensitive information by reading the Chan…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6575

Published Dec 15, 2006

PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote attackers to execute arbitrary PHP cod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6576

Published Dec 15, 2006

Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6577

Published Dec 15, 2006

SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6578

Published Dec 15, 2006

Microsoft Internet Information Services (IIS) 5.1 permits the IUSR_Machine account to execute non-EXE files such as .COM files, which allows attackers to execute arbitrary command…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6580

Published Dec 15, 2006

admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and pos…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6581

Published Dec 15, 2006

PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLoc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6582

Published Dec 15, 2006

Multiple cross-site scripting (XSS) vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) members_us…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6583

Published Dec 15, 2006

ScriptMate User Manager 2.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors related to (1) the Logins box and (2) the Search box.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6584

Published Dec 15, 2006

Multiple buffer overflows in italkplus (Italk+) before 0.92.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspe…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6585

Published Dec 15, 2006

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by findin…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6586

Published Dec 15, 2006

Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers to execute arbitrary PHP code via a URL in the cfgProgDir pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6587

Published Dec 15, 2006

Cross-site scripting (XSS) vulnerability in the forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) allows remote attackers to inject a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6588

Published Dec 15, 2006

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6589

Published Dec 15, 2006

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject ar…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6590

Published Dec 15, 2006

PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6591

Published Dec 15, 2006

PHP remote file inclusion vulnerability in fonctions/template.php in EXlor 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the repphp parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6592

Published Dec 15, 2006

Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code via a URL in the page[path] parameter to (1) index.php, (2) a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6593

Published Dec 15, 2006

PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6594

Published Dec 15, 2006

SQL injection vulnerability in utilities/usermessages.asp in ScriptMate User Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the mesid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6595

Published Dec 15, 2006

Multiple SQL injection vulnerabilities in ScriptMate User Manager 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via "Manage Resources" and possibly othe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6563

Published Dec 15, 2006

Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1.3.1rc1 allows local users to execute arbitrary code via a…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 6,608 CVEsPage 16 of 265