Vulnerabilities (CVE)

Total 367614 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-6127 1 Apple 2 Mac Os X, Mac Os X Server 2026-06-16 2.1 LOW N/A
Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.
CVE-2006-6126 1 Apple 2 Mac Os X, Mac Os X Server 2026-06-16 2.1 LOW N/A
Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.
CVE-2006-6125 1 Netgear 1 Wg311v1 2026-06-16 7.5 HIGH N/A
Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID.
CVE-2006-6124 1 Biba Software 1 Seleniumserver Web Server 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2006-6123 1 Coppermine 1 Coppermine Photo Gallery 2026-06-16 2.6 LOW N/A
Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected.
CVE-2006-6122 1 Tin 1 Tin 2026-06-16 7.5 HIGH N/A
Multiple buffer overflows in TIN before 1.8.2 have unspecified impact and attack vectors, a different vulnerability than CVE-2006-0804.
CVE-2006-6121 1 Acer 1 Lunchapp.aplunch 2026-06-16 9.3 HIGH N/A
Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method.
CVE-2006-6120 1 Kde 1 Koffice 2026-06-16 6.8 MEDIUM N/A
Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows user-assisted remote attackers to execute arbitrary code via a crafted PPT file, which results in a heap-based buffer overflow.
CVE-2006-6119 1 Mmgallery 1 Mmgallery 2026-06-16 5.0 MEDIUM N/A
mmgallery 1.55 allows remote attackers to obtain sensitive information via a direct request for thumbs.php, which reveals the installation path in various error messages.
CVE-2006-6118 1 Mmgallery 1 Mmgallery 2026-06-16 6.8 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in thumbs.php in mmgallery 1.55 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
CVE-2006-6117 1 Fipsasp 1 Fipsgallery 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the which parameter.
CVE-2006-6116 1 Fipsasp 1 Fipsforum 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter.
CVE-2006-6115 1 Fipsasp 1 Fipscms 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.
CVE-2006-6113 1 James Greenwood 1 Monkey Boards 2026-06-16 5.0 MEDIUM N/A
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
CVE-2006-6112 1 Lifetype 1 Lifetype 2026-06-16 5.0 MEDIUM N/A
LifeType 1.0.x and 1.1.x have insufficient access control for all of the PHP scripts under (1) class/ and (2) plugins/, which allows remote attackers to obtain the installation path via a direct request to any of the scripts, as demonstrated by (a) bayesianfilter.class.php and (b) bootstrap.php, which leaks the path in an error message.
CVE-2006-6111 1 Alan Ward 1 A-cart 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Alan Ward A-Cart Pro 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) productid parameter in product.asp or (2) search parameter in search.asp. NOTE: the category.asp vector is already covered by CVE-2004-1873.
CVE-2006-6110 1 Bpg-infotech 1 Content Management System 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp.
CVE-2006-6109 1 Candypress 1 Candypress Store 2026-06-16 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in CandyPress Store 3.5.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) policy parameter in openPolicy.asp or the (2) brand parameter in prodList.asp.
CVE-2006-6108 1 Ec-cube 1 Ec-cube 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
CVE-2006-6107 1 D-bus 1 D-bus 2026-06-16 1.7 LOW N/A
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).