Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,957 CVEs1,717 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026
17,157 results · page 301 of 344
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2006-5578 | Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure… | LOW 2.6EPSS 21.9% | 12 December 2006 |
| CVE-2006-5577 | Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure… | MEDIUM 4.3EPSS 25.8% | 12 December 2006 |
| CVE-2006-6423 | Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a… | EXPLOIT ×3 ✓HIGH 10.0EPSS 70.7% | 12 December 2006 |
| CVE-2006-6478 | Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c)… | EXPLOIT ×3 ✓HIGH 7.5EPSS 10.6% | 12 December 2006 |
| CVE-2006-6456 | Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than… | HIGH 9.3EPSS 32.2% | 11 December 2006 |
| CVE-2006-6450 | Multiple SQL injection vulnerabilities in dagent/downloadreport.asp in Novell ZENworks Patch Management (ZPM) before 6.3.2.700 allow remote attackers to execute arbitrary SQL commands via the (1) agentid and (2) pass parameters. | HIGH 7.5EPSS 21.7% | 10 December 2006 |
| CVE-2006-6379 | Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCserve Backup r11.5 SP1 and earlier, ARCserve Backup 9.01 up to 11.1, Enterprise Backup 10.5, and CA Server Protection Suite r2, allows remote attackers to… | EXPLOIT ✓HIGH 7.5EPSS 21.1% | 10 December 2006 |
| CVE-2006-6421 | Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user. | EXPLOIT ✓MEDIUM 6.0EPSS 15.6% | 10 December 2006 |
| CVE-2006-6332 | Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execute arbitrary code via unspecified vectors, related to the encode_ie and giwscan_cb functions. | EXPLOIT ×3 ✓HIGH 7.5EPSS 20.3% | 10 December 2006 |
| CVE-2006-6334 | Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of… | EXPLOIT ✓MEDIUM 6.8EPSS 34.8% | 8 December 2006 |
| CVE-2006-6311 | Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service via a style attribute in an HTML table tag with a width value that is dynamically calculated using JavaScript. | EXPLOIT ✓MEDIUM 5.0EPSS 26.5% | 6 December 2006 |
| CVE-2006-6310 | Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (crash) via an invalid src attribute value ("?") in an HTML frame tag that is in a frameset tag with a large rows attribute. | EXPLOIT ✓MEDIUM 5.0EPSS 15.8% | 6 December 2006 |
| CVE-2006-5994 | Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. | HIGH 9.3EPSS 32.0% | 6 December 2006 |
| CVE-2006-5856 | Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long section name in the dm.ini file, which is populated via an AOM file. | MEDIUM 6.8EPSS 14.7% | 6 December 2006 |
| CVE-2006-5855 | Multiple buffer overflows in IBM Tivoli Storage Manager (TSM) before 5.2.9 and 5.3.x before 5.3.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in (1) the language field at logon that… | HIGH 10.0EPSS 26.7% | 6 December 2006 |
| CVE-2006-6296 | The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via an RPC request… | EXPLOIT ✓MEDIUM 6.1EPSS 22.0% | 5 December 2006 |
| CVE-2006-6293 | Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file. | EXPLOIT ✓HIGH 7.5EPSS 16.4% | 5 December 2006 |
| CVE-2006-6287 | Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file. | EXPLOIT ✓HIGH 7.5EPSS 10.2% | 4 December 2006 |
| CVE-2006-6266 | Teredo clients, when following item 6 of RFC4380 section 5.2.3, start direct IPv6 connectivity tests (aka ping tests) in response to packets from non-Teredo source addresses, which might allow remote attackers to induce Teredo clients to send packets to… | MEDIUM 6.8EPSS 11.8% | 4 December 2006 |
| CVE-2006-6264 | Teredo creates trusted peer entries for arbitrary incoming source Teredo addresses, even if the low 32 bits represent an intranet address, which might allow remote attackers to send IPv4 traffic to intranet hosts that use non-RFC1918 addresses,… | HIGH 7.5EPSS 14.3% | 4 December 2006 |
| CVE-2006-6263 | Teredo clients, when source routing is enabled, recognize a Routing header in an encapsulated IPv6 packet and send the packet to the next hop, which might allow remote attackers to bypass policies of certain Internet gateways that drop all source-routed… | MEDIUM 6.8EPSS 12.5% | 4 December 2006 |
| CVE-2006-6252 | Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons. | MEDIUM 4.3EPSS 11.2% | 4 December 2006 |
| CVE-2006-6251 | Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack. | EXPLOIT ×3 ✓HIGH 7.5EPSS 67.5% | 4 December 2006 |
| CVE-2006-6236 | Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the (1) src, (2) setPageMode, (3) setLayoutMode, and (4) setNamedDest methods in… | HIGH 9.3EPSS 20.1% | 3 December 2006 |
| CVE-2006-5854 | Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions. | EXPLOIT ×2 ✓HIGH 7.5EPSS 57.5% | 3 December 2006 |
| CVE-2006-6199 | Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist. | EXPLOIT ×9 ✓HIGH 7.5EPSS 65.3% | 1 December 2006 |
| CVE-2006-6184 | Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command. | EXPLOIT ×4 ✓HIGH 10.0EPSS 65.9% | 1 December 2006 |
| CVE-2006-6183 | Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command. | EXPLOIT ×5 ✓HIGH 10.0EPSS 70.3% | 1 December 2006 |
| CVE-2006-6170 | Buffer overflow in the tls_x509_name_oneline function in the mod_tls module, as used in ProFTPD 1.3.0a and earlier, and possibly other products, allows remote attackers to execute arbitrary code via a large data length argument, a different… | HIGH 7.5EPSS 17.1% | 30 November 2006 |
| CVE-2006-6134 | Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash)… | HIGH 7.5EPSS 42.1% | 28 November 2006 |
| CVE-2006-6133 | Stack-based buffer overflow in Visual Studio Crystal Reports for Microsoft Visual Studio .NET 2002 and 2002 SP1, .NET 2003 and 2003 SP1, and 2005 and 2005 SP1 (formerly Business Objects Crystal Reports XI Professional) allows user-assisted remote… | EXPLOIT ✓HIGH 7.6EPSS 52.0% | 28 November 2006 |
| CVE-2006-5750 | Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified… | HIGH 7.5EPSS 13.9% | 27 November 2006 |
| CVE-2006-6125 | Heap-based buffer overflow in the wireless driver (WG311ND5.SYS) 2.3.1.10 for NetGear WG311v1 wireless adapter allows remote attackers to execute arbitrary code via an 802.11 management frame with a long SSID. | EXPLOIT ✓HIGH 7.5EPSS 14.6% | 27 November 2006 |
| CVE-2006-6121 | Acer Notebook LunchApp.APlunch ActiveX control allows remote attackers to execute arbitrary commands by calling the Run method. | EXPLOIT ✓HIGH 9.3EPSS 12.2% | 26 November 2006 |
| CVE-2006-6097 | GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in… | EXPLOIT ✓MEDIUM 4.0EPSS 11.0% | 24 November 2006 |
| CVE-2006-6076 | Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to execute arbitrary code via certain RPC requests to TCP port 6502. | EXPLOIT ✓HIGH 10.0EPSS 70.9% | 24 November 2006 |
| CVE-2006-6063 | Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName. | EXPLOIT ×3 ✓HIGH 7.5EPSS 58.3% | 22 November 2006 |
| CVE-2006-6059 | Buffer overflow in MA521nd5.SYS driver 5.148.724.2003 for NetGear MA521 PCMCIA adapter allows remote attackers to execute arbitrary code via (1) beacon or (2) probe 802.11 frame responses with an long supported rates information element. | EXPLOIT ✓HIGH 10.0EPSS 18.9% | 22 November 2006 |
| CVE-2006-6027 | Adobe Reader (Adobe Acrobat Reader) 7.0 through 7.0.8 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument string to the LoadFile method in an AcroPDF ActiveX control. | EXPLOIT ✓HIGH 9.3EPSS 43.2% | 21 November 2006 |
| CVE-2006-6026 | Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request… | EXPLOIT ✓HIGH 10.0EPSS 10.7% | 21 November 2006 |
| CVE-2006-6010 | SAP allows remote attackers to obtain potentially sensitive information such as operating system and SAP version via an RFC_SYSTEM_INFO RfcCallReceive request, a different vulnerability than CVE-2003-0747. | MEDIUM 5.0EPSS 13.9% | 21 November 2006 |
| CVE-2006-3890 | Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW… | EXPLOIT ✓HIGH 9.3EPSS 14.6% | 21 November 2006 |
| CVE-2006-5988 | Unspecified vulnerability in Windows 2000 Advanced Server SP4 running Active Directory allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain VulnDisco Pack module. | MEDIUM 5.0EPSS 13.0% | 20 November 2006 |
| CVE-2006-5972 | Stack-based buffer overflow in WG111v2.SYS in NetGear WG111v2 wireless adapter (USB) allows remote attackers to execute arbitrary code via a long 802.11 beacon request. | EXPLOIT ✓HIGH 10.0EPSS 19.4% | 18 November 2006 |
| CVE-2006-4689 | Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka… | MEDIUM 5.0EPSS 34.7% | 14 November 2006 |
| CVE-2006-4688 | Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability." | EXPLOIT ×2 ✓HIGH 7.5EPSS 75.0% | 14 November 2006 |
| CVE-2006-5198 | The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods." | EXPLOIT ✓MEDIUM 4.0EPSS 60.4% | 14 November 2006 |
| CVE-2006-4691 | Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname. | EXPLOIT ×4 ✓HIGH 10.0EPSS 78.9% | 14 November 2006 |
| CVE-2006-4687 | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption… | MEDIUM 5.1EPSS 25.4% | 14 November 2006 |
| CVE-2006-3445 | Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a large length value in an .ACF file, which results… | HIGH 7.5EPSS 41.0% | 14 November 2006 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.