LiveActive security incident?Get immediate response
CVE archive

2006 CVE Archive

Browse CVE records published in 2006 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 6995 matching CVEs · Page 4 of 140.

Unknown · CVSS Not scored

CVE-2006-6685: Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of se...

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 21, 2006 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-6973: Headstart Solutions DeskPRO does not require authentication for certain files and directories associated wi...

Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/.

Published Feb 7, 2007 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-6971: Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing...

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2) dotted-octal, (3) single decimal integer, (4) single hex integer, or (5) single octal integer format, which is not captured by the blacklist filter.

Published Feb 7, 2007 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-7240: gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings f...

gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532.

Published Sep 7, 2010 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-5529: Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 a...

Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of these details are obtained from third party information.

Published Oct 26, 2006 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-7223: PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user w...

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programming rights, modifying this document to contain a script, and previewing without saving the document.

Published Sep 14, 2007 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-6588: The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts...

The forum implementation in the ecommerce component in the Apache Open For Business Project (OFBiz) trusts the (1) dataResourceTypeId, (2) contentTypeId, and certain other hidden form fields, which allows remote attackers to create unauthorized types of content, modify content, or have other unknown impact.

Published Dec 15, 2006 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-1646: The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Projec...

The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to cause a denial of service (daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

Published Apr 6, 2006 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-0633: The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated f...

The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.

Published Feb 10, 2006 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-7184: Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow...

Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Mar 30, 2007 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-6626: Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers...

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

Published Dec 18, 2006 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2006-7046: PHP remote file inclusion vulnerability in cmpro.intern/login.inc.php for Clan Manager Pro (CMPRO) 1.1.0 al...

PHP remote file inclusion vulnerability in cmpro.intern/login.inc.php for Clan Manager Pro (CMPRO) 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 24, 2007 · Updated Sep 16, 2024