Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,718 CVEs tagged with CWE-201,603 Critical, 4,989 High, 5,605 Medium, 515 Low, 6 Unrated.

CVE-2006-3450

Published Aug 8, 2006

Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (C…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3451

Published Aug 8, 2006

Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3633

Published Jul 27, 2006

OSSP shiela 1.1.5 and earlier allows remote authenticated users to execute arbitrary commands on the CVS server via shell metacharacters in a filename that is committed.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3281

Published Jun 28, 2006

Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file shar…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3014

Published Jun 22, 2006

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Play…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2006-2782

Published Jun 2, 2006

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1858

Published May 22, 2006

SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a chunk length that is inconsistent with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1528

Published May 18, 2006

Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2223

Published May 5, 2006

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1957

Published Apr 21, 2006

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple reque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0744

Published Apr 18, 2006

Linux kernel before 2.6.16.5 does not properly handle uncanonical return addresses on Intel EM64T CPUs, which reports an exception in the SYSRET instead of the next instruction, w…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1721

Published Apr 11, 2006

digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1522

Published Apr 10, 2006

The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via key…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0047

Published Mar 7, 2006

packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0914

Published Feb 28, 2006

Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, which allows remote attackers to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0884

Published Feb 24, 2006

The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensiti…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-0298

Published Feb 2, 2006

The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0321

Published Jan 24, 2006

fetchmail 6.3.0 and other versions before 6.3.2 allows remote attackers to cause a denial of service (crash) via crafted e-mail messages that cause a free of an invalid pointer wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,576-12,600 of 12,718 CVEsPage 504 of 509