CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2006-2360

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 15 May 2006
    5.8
    Medium

    CVE-2006-2368

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 15 May 2006
    Unknown

    CVE-2006-2350

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2344. Reason: This candidate is a duplicate of CVE-2006-2344. Notes: All CVE users should reference CVE-2006-2344 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 May 2006
    5
    Medium

    CVE-2006-2355

    Last Modified: 16 Apr 2026

    Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 May 2006
    5
    Medium

    CVE-2006-2356

    Last Modified: 16 Apr 2026

    NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter.

    Published: 15 May 2006
    5
    Medium

    CVE-2006-2357

    Last Modified: 16 Apr 2026

    Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp.

    Published: 15 May 2006
    4.3
    Medium

    CVE-2006-2358

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter and (2) unspecified fields related to e-mail alerts. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 May 2006
    5
    Medium

    CVE-2006-2353

    Last Modified: 16 Apr 2026

    NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters.

    Published: 15 May 2006
    5
    Medium

    CVE-2006-2354

    Last Modified: 16 Apr 2026

    NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 May 2006
    Unknown

    CVE-2006-1519

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2224. Reason: This candidate is a duplicate of CVE-2006-2224. Notes: All CVE users should reference CVE-2006-2224 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 May 2006
    4.3
    Medium

    CVE-2006-2351

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.

    Published: 15 May 2006
    4.3
    Medium

    CVE-2006-2352

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 May 2006
    5
    Medium

    CVE-2006-0747

    Last Modified: 16 Apr 2026

    Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue values, which causes the underflow when decrementing by 2 in a context that assumes an even number of values.

    Published: 15 May 2006
    7.5
    High

    CVE-2006-1861

    Last Modified: 16 Apr 2026

    Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to (1) bdf/bdflib.c, (2) sfnt/ttcmap.c, (3) cff/cffgload.c, and (4) the read_lwfn function and a crafted LWFN file in base/ftmac.c. NOTE: item 4 was originally identified by CVE-2006-2493.

    Published: 15 May 2006
    5
    Medium

    CVE-2006-2661

    Last Modified: 16 Apr 2026

    ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.

    Published: 15 May 2006
    6.4
    Medium

    CVE-2006-2426

    Last Modified: 16 Apr 2026

    Sun Java Runtime Environment (JRE) 1.5.0_6 and earlier, JDK 1.5.0_6 and earlier, and SDK 1.5.0_6 and earlier allows remote attackers to cause a denial of service (disk consumption) by using the Font.createFont function to create temporary files of arbitrary size in the %temp% directory.

    Published: 14 May 2006
    7.5
    High

    CVE-2006-1442

    Last Modified: 16 Apr 2026

    The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

    Published: 12 May 2006
    2.1
    Low

    CVE-2006-1444

    Last Modified: 16 Apr 2026

    CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Event Services.

    Published: 12 May 2006
    6.5
    Medium

    CVE-2006-1445

    Last Modified: 16 Apr 2026

    Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server path name handling."

    Published: 12 May 2006
    5
    Medium

    CVE-2006-1446

    Last Modified: 16 Apr 2026

    Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference after the Keychain has been locked.

    Published: 12 May 2006
    5
    Medium

    CVE-2006-1447

    Last Modified: 16 Apr 2026

    LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

    Published: 12 May 2006
    7.2
    High

    CVE-2006-1451

    Last Modified: 16 Apr 2026

    MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.

    Published: 12 May 2006
    4.6
    Medium

    CVE-2006-1452

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.

    Published: 12 May 2006
    7.8
    High

    CVE-2006-1455

    Last Modified: 16 Apr 2026

    QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.

    Published: 12 May 2006
    2.1
    Low

    CVE-2006-1440

    Last Modified: 16 Apr 2026

    BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-1449

    Last Modified: 16 Apr 2026

    Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-1441

    Last Modified: 16 Apr 2026

    Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.

    Published: 12 May 2006
    6.5
    Medium

    CVE-2006-1443

    Last Modified: 16 Apr 2026

    Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.

    Published: 12 May 2006
    6.5
    Medium

    CVE-2006-1448

    Last Modified: 16 Apr 2026

    Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-1450

    Last Modified: 16 Apr 2026

    Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initialize arbitrary classes.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-1456

    Last Modified: 16 Apr 2026

    Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.

    Published: 12 May 2006
    2.6
    Low

    CVE-2006-1457

    Last Modified: 16 Apr 2026

    Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2238

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.

    Published: 12 May 2006
    2.1
    Low

    CVE-2006-1439

    Last Modified: 16 Apr 2026

    NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1453

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1454

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1461

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1462

    Last Modified: 16 Apr 2026

    Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1463

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1464

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1465

    Last Modified: 16 Apr 2026

    Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1458

    Last Modified: 16 Apr 2026

    Integer overflow in Apple QuickTime Player before 7.1 allows remote attackers to execute arbitrary code via a crafted JPEG image.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1460

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.

    Published: 12 May 2006
    5.1
    Medium

    CVE-2006-1459

    Last Modified: 16 Apr 2026

    Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2342

    Last Modified: 16 Apr 2026

    IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root.

    Published: 12 May 2006
    5.8
    Medium

    CVE-2006-2343

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine OpManager 6.0 allows remote attackers to inject arbitrary web script or HTML via the searchTerm parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 12 May 2006
    6.4
    Medium

    CVE-2006-2344

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in inc/elementz.php in AliPAGER 1.5, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the ubild parameter.

    Published: 12 May 2006
    4.3
    Medium

    CVE-2006-2345

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in inc/elementz.php in AliPAGER 1.5 allows remote attackers to inject arbitrary web script or HTML via the ubild parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. NOTE: this issue might be resultant from SQL injection.

    Published: 12 May 2006
    7.5
    High

    CVE-2006-2346

    Last Modified: 16 Apr 2026

    vpopmail 5.4.14 and 5.4.15, with cleartext passwords enabled, allows remote attackers to authenticate to an account that does not have a cleartext password set by using a blank password to (1) SMTP AUTH or (2) APOP.

    Published: 12 May 2006
    2.6
    Low

    CVE-2006-2348

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.

    Published: 12 May 2006