LiveActive security incident?Get immediate response
CVE archive

May 2006

Browse CVE records published in May 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 594 matching CVEs · Page 11 of 12.

Unknown · CVSS Not scored

CVE-2006-2109: Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2....

Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are set as global variables within the program, as demonstrated using the table parameter to login.php.

Published May 2, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2139: Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary...

Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename parameter to (d) searchnews.php.

Published May 2, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2082: Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to...

Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote attackers to read arbitrary files from the server via ".." sequences in a .pk3 file request.

Published May 10, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1861: Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (cras...

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493.

Published May 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-1526: Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause...

Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.

Published May 2, 2006 · Updated Aug 7, 2024