Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0552

Published Jan 29, 2007

Cross-site scripting (XSS) vulnerability in install/default/error404.html in Oh no! Not another CMS (Onnac) 0.0.8.4 and earlier allows remote attackers to inject arbitrary web scr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0553

Published Jan 29, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.inc.php in PHProxy before 0.5 beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) data[re…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6953

Published Jan 29, 2007

The virtual keyboard implementation in GlobeTrotter Mobility Manager changes the color of a key as it is pressed, which allows local users to capture arbitrary keystrokes, such as…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6954

Published Jan 29, 2007

Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CV…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6955

Published Jan 29, 2007

Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6956

Published Jan 29, 2007

Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6957

Published Jan 29, 2007

PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PH…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6958

Published Jan 29, 2007

Multiple PHP remote file inclusion vulnerabilities in phpBlueDragon 2.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter to (1) t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6959

Published Jan 29, 2007

WebRoot Spy Sweeper 4.5.9 and earlier allows local users to bypass the "Startup-Shield" security restrictions by modifying certain registry keys.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6960

Published Jan 29, 2007

The Compression Sweep feature in WebRoot Spy Sweeper 4.5.9 and earlier does not handle non-ZIP archives, which allows remote attackers to bypass the malware detection via files wi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6961

Published Jan 29, 2007

WebRoot Spy Sweeper 4.5.9 and earlier does not detect malware based on file contents, which allows remote attackers to bypass malware detection by changing a file's name.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6962

Published Jan 29, 2007

PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for Joomla! allows attackers to execute arbitrary PHP code via…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6963

Published Jan 29, 2007

Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 3.0.3 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_lms] parameter to (1) cl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6964

Published Jan 29, 2007

MailEnable Professional before 1.78 provides a cleartext user password when an administrator edits the user's settings, which allows remote authenticated administrators to obtain…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0463

Published Jan 29, 2007

Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0537

Published Jan 29, 2007

The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0536

Published Jan 27, 2007

The chroot helper in rMake for rPath Linux 1 does not drop supplemental groups, which causes packages to be installed with insecure permissions and might allow local users to gain…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0462

Published Jan 26, 2007

The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of s…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0516

Published Jan 26, 2007

Yana Framework before 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vect…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0517

Published Jan 26, 2007

Scriptsez Random PHP Quote 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password information via a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0518

Published Jan 26, 2007

Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0519

Published Jan 26, 2007

Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0520

Published Jan 26, 2007

SQL injection vulnerability in banner.php in Unique Ads (UDS) 1.x allows remote attackers to execute arbitrary SQL commands via the bid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0521

Published Jan 26, 2007

The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a fi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 6,026-6,050 of 6,516 CVEsPage 242 of 261