LiveActive security incident?Get immediate response
CVE archive

2006 CVE Archive

Browse CVE records published in 2006 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 6995 matching CVEs · Page 22 of 140.

Unknown · CVSS Not scored

CVE-2006-6346: Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 P...

Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote attackers to cause a denial of service (service shutdown), obtain sensitive information (configuration files), and conduct certain other unauthorized activities, related to "Undocumented Features." NOTE: it is possible that there are multiple issues. This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. This is likely a different issue than CVE-2006-4134.

Published Dec 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6345: Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, an...

Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.

Published Dec 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6342: Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L.

Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp.

Published Dec 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6344: Multiple unspecified vulnerabilities in Neocrome Seditio 1.10 and earlier have unknown impact and attack ve...

Multiple unspecified vulnerabilities in Neocrome Seditio 1.10 and earlier have unknown impact and attack vectors related to (1) plugins/ipsearch/ipsearch.admin.php, and (2) pfs/pfs.edit.inc.php, (3) users/users.register.inc.php in system/core. NOTE: the users.profile.inc.php vector is identified by CVE-2006-6177. NOTE: these issues might be related to SQL injection.

Published Dec 7, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6308: Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe...

Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may be necessary to terminate shstart.exe. If this is the case, then no privilege escalation occurs, and this is not a vulnerability

Published Dec 6, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6302: fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arb...

fail2ban 0.7.4 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a login name containing certain strings with an IP address.

Published Dec 6, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6335: Multiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execut...

Multiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive with a long filename that is not null-terminated, which triggers a heap-based overflow in veex.dll due to improper length calculation, and (2) a CPIO archive, with a long filename that is not null-terminated, which triggers a stack-based overflow in veex.dll.

Published Dec 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6265: Teredo clients, when located behind a restricted NAT, allow remote attackers to establish an inbound connec...

Teredo clients, when located behind a restricted NAT, allow remote attackers to establish an inbound connection without the guessing required to find a port mapping for a traditional restricted NAT client, by (1) using the client port number contained in the Teredo address or (2) following the bubble-to-open procedure.

Published Dec 4, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6310: Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash...

Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 6, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6291: Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through...

Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.

Published Dec 5, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6286: Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, whic...

Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 4, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6301: DenyHosts 2.5 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts...

DenyHosts 2.5 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a login name containing certain strings with an IP address, which is not properly handled by a regular expression.

Published Dec 6, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6259: Multiple directory traversal vulnerabilities in (a) class/functions.php and (b) class/m_bro.php in AlternC...

Multiple directory traversal vulnerabilities in (a) class/functions.php and (b) class/m_bro.php in AlternC 0.9.5 and earlier allow remote attackers to (1) create arbitrary files and directories via a .. (dot dot) in the "create name" field and (2) read arbitrary files via a .. (dot dot) in the "web root" field when configuring a subdomain.

Published Dec 4, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6255: Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Pr...

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

Published Dec 4, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6288: Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbit...

Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via (1) a playlist file with long song names, because of an overflow in the CPL_AddPrefixedFile function in CPI_Playlist.c; (2) a skin file with long button names, because of an overflow in the main_skin_check_ini_value function in skin.c; and (3) a skin file with long bitmap filenames, because of an overflow in the main_skin_open function in skin.c.

Published Dec 4, 2006 · Updated Aug 7, 2024