Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-0336

Published Jan 21, 2006

Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0339

Published Jan 21, 2006

Buffer overflow in BitComet Client 0.60 allows remote attackers to execute arbitrary code, when the publisher's name link is clicked, via a long publisher URI in a torrent file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0340

Published Jan 21, 2006

Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote atta…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0342

Published Jan 21, 2006

RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string contai…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0344

Published Jan 21, 2006

Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RET…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0019

Published Jan 20, 2006

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0045

Published Jan 20, 2006

crawl before 4.0.0 does not securely call programs when saving and loading games, which allows local users to gain privileges.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0325

Published Jan 20, 2006

Etomite Content Management System 0.6, and possibly earlier versions, when downloaded from the web site in January 2006 after January 10, contains a back door in manager/includes/…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0322

Published Jan 19, 2006

Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0324

Published Jan 19, 2006

SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0226

Published Jan 19, 2006

Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-0309

Published Jan 19, 2006

Linksys BEFVP41 VPN Router 2.0 with firmware 1.01.04 allows remote attackers on the local network, to cause a denial of service via IP packets with a null IP option length.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0310

Published Jan 19, 2006

Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0311

Published Jan 19, 2006

SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0312

Published Jan 19, 2006

create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0313

Published Jan 19, 2006

Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0314

Published Jan 19, 2006

PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0315

Published Jan 19, 2006

index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct director…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0316

Published Jan 19, 2006

Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-0317

Published Jan 19, 2006

Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0318

Published Jan 19, 2006

SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0319

Published Jan 19, 2006

Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,351-6,375 of 6,608 CVEsPage 255 of 265