Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0495

Published Jan 25, 2007

PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0496

Published Jan 25, 2007

PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0497

Published Jan 25, 2007

PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0498

Published Jan 25, 2007

PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] paramet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0499

Published Jan 25, 2007

PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0500

Published Jan 25, 2007

PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0501

Published Jan 25, 2007

PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute ar…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0502

Published Jan 25, 2007

SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0503

Published Jan 25, 2007

Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0493

Published Jan 25, 2007

Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0494

Published Jan 25, 2007

ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0476

Published Jan 25, 2007

The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary direc…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0477

Published Jan 25, 2007

Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0478

Published Jan 25, 2007

WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0479

Published Jan 25, 2007

Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0480

Published Jan 25, 2007

Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in th…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0482

Published Jan 25, 2007

cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a differ…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0483

Published Jan 25, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0484

Published Jan 25, 2007

Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0485

Published Jan 25, 2007

PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0486

Published Jan 25, 2007

Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0487

Published Jan 25, 2007

PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0488

Published Jan 25, 2007

The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,076-6,100 of 6,516 CVEsPage 244 of 261