CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2006-2267

    Last Modified: 16 Apr 2026

    Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "email protocol inspectors," possibly (1) SMTP and (2) POP3.

    Published: 9 May 2006
    6.8
    Medium

    CVE-2006-2245

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2254

    Last Modified: 16 Apr 2026

    Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2255

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2263

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 9 May 2006
    6.5
    Medium

    CVE-2006-2264

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 May 2006
    5
    Medium

    CVE-2006-2274

    Last Modified: 16 Apr 2026

    Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull function.

    Published: 9 May 2006
    7.5
    High

    CVE-2006-2275

    Last Modified: 16 Apr 2026

    Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."

    Published: 9 May 2006
    7.6
    High

    CVE-2006-2236

    Last Modified: 16 Apr 2026

    Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.

    Published: 8 May 2006
    5.1
    Medium

    CVE-2006-2237

    Last Modified: 16 Apr 2026

    The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.

    Published: 8 May 2006
    7.8
    High

    CVE-2006-2271

    Last Modified: 16 Apr 2026

    The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.

    Published: 8 May 2006
    7.8
    High

    CVE-2006-2272

    Last Modified: 16 Apr 2026

    Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks.

    Published: 8 May 2006
    4.3
    Medium

    CVE-2006-3918

    Last Modified: 16 Apr 2026

    http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

    Published: 8 May 2006
    7.5
    High

    CVE-2006-2453

    Last Modified: 16 Apr 2026

    Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.

    Published: 6 May 2006
    4.3
    Medium

    CVE-2006-2227

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 allows remote attackers to inject arbitrary web script or HTML via the req_message parameter, because the value of the redirect_url parameter is not sanitized.

    Published: 5 May 2006
    4.3
    Medium

    CVE-2006-2232

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML via the Comments field when signing the guestbook.

    Published: 5 May 2006
    7.5
    High

    CVE-2006-2233

    Last Modified: 16 Apr 2026

    Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBannerUrl. NOTE: portions of these details are obtained from third party information.

    Published: 5 May 2006
    6.8
    Medium

    CVE-2006-2234

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript URI in an img BBCode tag, or a JavaScript event in a (2) url BBCode tag or (3) color BBCode tag.

    Published: 5 May 2006
    7.6
    High

    CVE-2006-2235

    Last Modified: 16 Apr 2026

    CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is not required for the admin directory, allows remote attackers to gain administrative privileges by appending /admin/ to the top-level URI of the application.

    Published: 5 May 2006
    4.3
    Medium

    CVE-2006-2231

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi.

    Published: 5 May 2006
    5
    Medium

    CVE-2006-2230

    Last Modified: 16 Apr 2026

    Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.

    Published: 5 May 2006
    2.1
    Low

    CVE-2006-2221

    Last Modified: 16 Apr 2026

    A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.

    Published: 5 May 2006
    5
    Medium

    CVE-2006-2226

    Last Modified: 16 Apr 2026

    Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of service via a long argument to the PORT command.

    Published: 5 May 2006
    5
    Medium

    CVE-2006-2222

    Last Modified: 16 Apr 2026

    Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) characters.

    Published: 5 May 2006
    7.5
    High

    CVE-2006-2225

    Last Modified: 16 Apr 2026

    Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username.

    Published: 5 May 2006
    4.3
    Medium

    CVE-2006-2228

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals) character, which bypasses a restrictive regular expression that attempts to remove onmouseover and other events.

    Published: 5 May 2006
    4
    Medium

    CVE-2006-2229

    Last Modified: 16 Apr 2026

    OpenVPN 2.0.7 and earlier, when configured to use the --management option with an IP that is not 127.0.0.1, uses a cleartext password for TCP sessions to the management interface, which might allow remote attackers to view sensitive information or cause a denial of service.

    Published: 5 May 2006
    9.3
    Critical

    CVE-2006-2218

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.

    Published: 5 May 2006
    5
    Medium

    CVE-2006-2216

    Last Modified: 16 Apr 2026

    Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php.

    Published: 5 May 2006
    5.8
    Medium

    CVE-2006-2210

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability.

    Published: 5 May 2006
    7.5
    High

    CVE-2006-2214

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.

    Published: 5 May 2006
    7.5
    High

    CVE-2006-2217

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 May 2006
    6.5
    Medium

    CVE-2006-1518

    Last Modified: 16 Apr 2026

    Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.

    Published: 5 May 2006
    5.5
    Medium

    CVE-2006-2204

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array.

    Published: 5 May 2006
    5
    Medium

    CVE-2006-2211

    Last Modified: 16 Apr 2026

    Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter.

    Published: 5 May 2006
    6.4
    Medium

    CVE-2006-2203

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of attachment filter."

    Published: 5 May 2006
    2.1
    Low

    CVE-2006-2205

    Last Modified: 16 Apr 2026

    The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.

    Published: 5 May 2006
    10
    Critical

    CVE-2006-2206

    Last Modified: 16 Apr 2026

    The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting passwords.

    Published: 5 May 2006
    4.3
    Medium

    CVE-2006-2208

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.

    Published: 5 May 2006
    6.4
    Medium

    CVE-2006-2209

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published: 5 May 2006
    Unknown

    CVE-2006-2215

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2181. Reason: This candidate is a duplicate of CVE-2006-2181. Notes: All CVE users should reference CVE-2006-2181 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 May 2006
    6.4
    Medium

    CVE-2006-2212

    Last Modified: 16 Apr 2026

    Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command.

    Published: 5 May 2006
    5
    Medium

    CVE-2006-2213

    Last Modified: 16 Apr 2026

    Hostapd 0.3.7-2 allows remote attackers to cause a denial of service (segmentation fault) via an unspecified value in the key_data_length field of an EAPoL frame.

    Published: 5 May 2006
    6.4
    Medium

    CVE-2006-2202

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter.

    Published: 4 May 2006
    4.3
    Medium

    CVE-2006-2201

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in CA Resource Initialization Manager (CAIRIM) 1.x before 20060502, as used in z/OS Common Services and the LMP component in multiple products, allows attackers to violate integrity via a certain "problem state program" that uses SVC to gain access to supervisor state, key 0.

    Published: 4 May 2006
    2.6
    Low

    CVE-2006-2163

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.

    Published: 4 May 2006
    4.3
    Medium

    CVE-2006-2167

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.

    Published: 4 May 2006
    7.5
    High

    CVE-2006-2168

    Last Modified: 16 Apr 2026

    FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1.

    Published: 4 May 2006
    6.4
    Medium

    CVE-2006-2170

    Last Modified: 16 Apr 2026

    Buffer overflow in ArgoSoft FTP Server 1.4.3.6 allows remote attackers to execute arbitrary code via Unicode in the RNTO command, as demonstrated by the Infigo FTPStress Fuzzer.

    Published: 4 May 2006
    6.4
    Medium

    CVE-2006-2171

    Last Modified: 16 Apr 2026

    Buffer overflow in WDM.exe in WarFTPD allows remote attackers to execute arbitrary code via unspecified arguments, as demonstrated by the Infigo FTPStress Fuzzer.

    Published: 4 May 2006