Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-6235

Published Dec 4, 2007

A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6236

Published Dec 4, 2007

Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6237

Published Dec 4, 2007

cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6238

Published Dec 4, 2007

Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability tha…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6239

Published Dec 4, 2007

The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6218

Published Dec 4, 2007

Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) instal…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6219

Published Dec 4, 2007

Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool Security Manager 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6221

Published Dec 4, 2007

TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6222

Published Dec 4, 2007

The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, which allows remote authenticated…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6223

Published Dec 4, 2007

SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in bro…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6212

Published Dec 4, 2007

Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6213

Published Dec 4, 2007

Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6214

Published Dec 4, 2007

Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot dot) in the sFilePath parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6215

Published Dec 4, 2007

Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) roomNo and possibly the (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6216

Published Dec 4, 2007

Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some p…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6217

Published Dec 4, 2007

Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) login (aka Username)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6210

Published Dec 4, 2007

zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6211

Published Dec 4, 2007

Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users to append to arbitrary files and gain privileges via the -L (output log file) option. NOTE: this issue is on…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6207

Published Dec 4, 2007

Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6208

Published Dec 4, 2007

sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6203

Published Dec 3, 2007

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error mess…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7225

Published Dec 3, 2007

Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 6,516 CVEsPage 17 of 261