Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-6167

Published Nov 29, 2007

Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 module in the current working direc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6168

Published Nov 29, 2007

SQL injection vulnerability in default.asp in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the username parameter, a different vector than CVE-200…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6169

Published Nov 29, 2007

SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the uname parameter, a different vector than CVE-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4674

Published Nov 27, 2007

An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, wh…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6133

Published Nov 27, 2007

PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6134

Published Nov 27, 2007

SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article acti…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6135

Published Nov 27, 2007

Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6136

Published Nov 27, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6137

Published Nov 27, 2007

SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. NOTE: some of these…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6138

Published Nov 27, 2007

SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6139

Published Nov 27, 2007

PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitrary PHP code via a URL in the skin_file parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6140

Published Nov 27, 2007

Multiple SQL injection vulnerabilities in Dora Emlak 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) emlak_detay.asp and (b) haber_det…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6141

Published Nov 27, 2007

Cross-site scripting (XSS) vulnerability in vBTube.php in vBTube 1.1 Beta allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6142

Published Nov 27, 2007

Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6143

Published Nov 27, 2007

SQL injection vulnerability in default.asp (aka the Login Page) in VU Case Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6144

Published Nov 27, 2007

Heap-based buffer overflow in the PPlayer.XPPlayer.1 ActiveX control in pplayer.dll_1_work in Xunlei Thunder 5.7.4.401 allows remote attackers to execute arbitrary code via a long…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6145

Published Nov 27, 2007

Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "view files" via unspecified vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6146

Published Nov 27, 2007

Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-02 on Windows might allow remote attackers to cause a denial of service (service stop) via a "specific file" argument…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6147

Published Nov 27, 2007

Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5959

Published Nov 26, 2007

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5960

Published Nov 26, 2007

Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6122

Published Nov 26, 2007

The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long pas…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6123

Published Nov 26, 2007

Unspecified vulnerability in IRC Services 5.1.8 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6124

Published Nov 26, 2007

Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6125

Published Nov 26, 2007

SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitrary SQL commands via the sb_protype parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 6,516 CVEsPage 20 of 261