Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-5502

Published Dec 1, 2007

The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data that is more predictable than…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5742

Published Dec 1, 2007

Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attackers to read arbitrary files via ".."…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6196

Published Dec 1, 2007

Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6197

Published Dec 1, 2007

The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6198

Published Dec 1, 2007

portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6199

Published Dec 1, 2007

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6200

Published Dec 1, 2007

Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, and filter and read or write hi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6201

Published Dec 1, 2007

Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via a "faulty add-on" and possibly execute o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6202

Published Dec 1, 2007

SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parame…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5494

Published Nov 30, 2007

Memory leak in the Red Hat Content Accelerator kernel patch in Red Hat Enterprise Linux (RHEL) 4 and 5 allows local users to cause a denial of service (memory consumption) via a l…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5503

Published Nov 30, 2007

Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image with large width and height val…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6150

Published Nov 30, 2007

The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6170

Published Nov 30, 2007

SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6171

Published Nov 30, 2007

SQL injection vulnerability in the Postgres Realtime Engine (res_config_pgsql) in Asterisk 1.4.x before 1.4.15 and C.x before C.1.0-beta6 allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6187

Published Nov 30, 2007

Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6188

Published Nov 30, 2007

Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6189

Published Nov 30, 2007

A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6190

Published Nov 30, 2007

The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM serv…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6191

Published Nov 30, 2007

Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] p…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6192

Published Nov 30, 2007

The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6193

Published Nov 30, 2007

The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6172

Published Nov 30, 2007

Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6173

Published Nov 30, 2007

Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Enterprise Portal 4.3.1 allows remote attackers to inject arbitrary web script or HTML via the emailAddress p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6174

Published Nov 30, 2007

PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these details are obtained from third…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 6,516 CVEsPage 18 of 261