Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0522

Published Jan 26, 2007

The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over B…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0523

Published Jan 26, 2007

The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0524

Published Jan 26, 2007

The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Blu…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0525

Published Jan 26, 2007

Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0526

Published Jan 26, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the URL (PATH_INFO) to (1) articles/edit.p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0527

Published Jan 26, 2007

SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the R…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0528

Published Jan 26, 2007

The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require pa…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0529

Published Jan 26, 2007

Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0530

Published Jan 26, 2007

Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0531

Published Jan 26, 2007

PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0532

Published Jan 26, 2007

Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0533

Published Jan 26, 2007

The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread ha…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0535

Published Jan 26, 2007

Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0504

Published Jan 26, 2007

Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0507

Published Jan 26, 2007

SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree alb…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0508

Published Jan 26, 2007

PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0509

Published Jan 26, 2007

Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in ma…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0510

Published Jan 26, 2007

Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors. NOTE: some of these details are o…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0511

Published Jan 26, 2007

Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0512

Published Jan 26, 2007

Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,051-6,075 of 6,516 CVEsPage 243 of 261