{"api_version":"1","generated_at":"2026-07-23T09:02:43+00:00","cve":"CVE-2006-0964","urls":{"html":"https://cve.report/CVE-2006-0964","api":"https://cve.report/api/cve/CVE-2006-0964.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0964","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0964"},"summary":{"title":"CVE-2006-0964","description":"Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-02 23:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/19082","name":"http://secunia.com/advisories/19082","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - NCP Secure Entry/Enterprise Client Two Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16906","name":"http://www.securityfocus.com/bid/16906","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NCP Secure Client Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/426480/100/0/threaded","name":"http://www.securityfocus.com/archive/1/426480/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-disclosure] NCP VPN/PKI Client - various Bugs","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25242","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25242","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0964","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0964","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"964","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ncp_network_communications","cpe5":"secure_client","cpe6":"8.11_build_146","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"964","cve":"CVE-2006-0964","epss":"0.000710000","percentile":"0.217570000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:56:14.984Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"16906","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16906"},{"name":"20060301 NCP VPN/PKI Client - various Bugs","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/426480/100/0/threaded"},{"name":"ncp-client-firewall-bypass-security(25242)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25242"},{"name":"19082","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19082"},{"name":"20060301 NCP VPN/PKI Client - various Bugs","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"16906","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16906"},{"name":"20060301 NCP VPN/PKI Client - various Bugs","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/426480/100/0/threaded"},{"name":"ncp-client-firewall-bypass-security(25242)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25242"},{"name":"19082","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19082"},{"name":"20060301 NCP VPN/PKI Client - various Bugs","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0964","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"16906","refsource":"BID","url":"http://www.securityfocus.com/bid/16906"},{"name":"20060301 NCP VPN/PKI Client - various Bugs","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/426480/100/0/threaded"},{"name":"ncp-client-firewall-bypass-security(25242)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25242"},{"name":"19082","refsource":"SECUNIA","url":"http://secunia.com/advisories/19082"},{"name":"20060301 NCP VPN/PKI Client - various Bugs","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042640.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0964","datePublished":"2006-03-02T23:00:00.000Z","dateReserved":"2006-03-02T00:00:00.000Z","dateUpdated":"2024-08-07T16:56:14.984Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-02 23:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ncp_network_communications:secure_client:8.11_build_146:*:*:*:*:*:*:*","matchCriteriaId":"1EAEBC12-E164-45AE-98AD-BF746BC4B425"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"964","Ordinal":"1","Title":"CVE-2006-0964","CVE":"CVE-2006-0964","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"964","Ordinal":"1","NoteData":"Client Firewall in NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to bypass firewall program execution rules by replacing an allowed program with an arbitrary program.","Type":"Description","Title":"CVE-2006-0964"},{"CveYear":"2006","CveId":"964","Ordinal":"2","NoteData":"2006-03-02","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"964","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}