CVE-2006-3675
Estado: ModificadaBaja (2.1)—
Password Safe 2.11, 2.16 and 3.0BETA1 does not respect the configuration settings for locking the password database when certain dialogue windows are open, which might allow attackers with physical access to obtain the database contents.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.45%
- Percentil entre todas las CVEs puntuadas: 37
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://securityreason.com/securityalert/1308
- http://securitytracker.com/id?1016565
- http://www.securityfocus.com/archive/1/441040/100/0/threaded
- http://www.securityfocus.com/bid/19078
- http://www.symantec.com/enterprise/research/SYMSA-2006-008.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27933
- http://securityreason.com/securityalert/1308
- http://securitytracker.com/id?1016565
- http://www.securityfocus.com/archive/1/441040/100/0/threaded
- http://www.securityfocus.com/bid/19078
- http://www.symantec.com/enterprise/research/SYMSA-2006-008.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27933
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-3675",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-07-28T22:04:00.000",
"references": [
{
"url": "http://securityreason.com/securityalert/1308",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1016565",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/441040/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/19078",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.symantec.com/enterprise/research/SYMSA-2006-008.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27933",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1308",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1016565",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/441040/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/19078",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.symantec.com/enterprise/research/SYMSA-2006-008.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27933",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Password Safe 2.11, 2.16 and 3.0BETA1 does not respect the configuration settings for locking the password database when certain dialogue windows are open, which might allow attackers with physical access to obtain the database contents."
},
{
"lang": "es",
"value": "Password Safe 2.11, 2.16 y 3.0BETA1 no respeta la configuración de los ajustes para cerrar la base de datos de contraseñas cuando ciertos diálogos de windows son abiertos, lo cual permitiría a atacantes con acceso físico obtener contenido de la base de datos."
}
],
"lastModified": "2026-06-16T22:27:32.300",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:counterpane:passwordsafe:2.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "316B0240-3E68-4BC6-9E4F-3115A8A73B0A"
},
{
"criteria": "cpe:2.3:a:counterpane:passwordsafe:2.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF681B18-AF36-49CF-9A31-1EA3613A0C32"
},
{
"criteria": "cpe:2.3:a:counterpane:passwordsafe:3.0beta1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D516C6B5-7824-466B-A5B8-5260ABBA5351"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}