Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-6175

Published Nov 30, 2007

Buffer overflow in Lhaplus 1.55 and earlier allows remote attackers to execute arbitrary code via a crafted LZH archive, a different vector than CVE-2007-5048.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6176

Published Nov 30, 2007

kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6177

Published Nov 30, 2007

PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the webappcfg[APPPATH] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6179

Published Nov 30, 2007

Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_library_path parameter to (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6180

Published Nov 30, 2007

Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL dereference and panic) via uns…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6181

Published Nov 30, 2007

Heap-based buffer overflow in cygwin1.dll in Cygwin 1.5.7 and earlier allows context-dependent attackers to execute arbitrary code via a filename with a certain length, as demonst…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6182

Published Nov 30, 2007

The responder program in ISPsystem ISPmanager (aka ISPmgr) 4.2.15.1 allows local users to gain privileges via shell metacharacters in command line arguments.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6183

Published Nov 30, 2007

Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows con…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6184

Published Nov 30, 2007

Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6185

Published Nov 30, 2007

Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a download action…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6186

Published Nov 30, 2007

Unspecified vulnerability in PHPDevShell before 0.7.0 has unknown impact and attack vectors, involving a "minor security bug in repair & optimize database."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4346

Published Nov 29, 2007

The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers to cause a denial of service (N…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4347

Published Nov 29, 2007

Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allow remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6157

Published Nov 29, 2007

Cross-site scripting (XSS) vulnerability in index.php in SimpleGallery 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6158

Published Nov 29, 2007

Multiple SQL injection vulnerabilities in caladmin.inc.php in Proverbs Web Calendar 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) loginname…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6159

Published Nov 29, 2007

SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6160

Published Nov 29, 2007

Cross-site scripting (XSS) vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via the aarstal parameter in a ye…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6161

Published Nov 29, 2007

index.php in Tilde CMS 4.x and earlier allows remote attackers to obtain sensitive information via a certain search parameter value in a search action, which reveals the path.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6162

Published Nov 29, 2007

Cross-site scripting (XSS) vulnerability in index.php in FMDeluxe 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a category action.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6163

Published Nov 29, 2007

SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6164

Published Nov 29, 2007

Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) reviews.php, (2) links.php and (3) art…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6165

Published Nov 29, 2007

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 451-475 of 6,516 CVEsPage 19 of 261