Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0489

Published Jan 25, 2007

PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0490

Published Jan 25, 2007

index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0491

Published Jan 25, 2007

PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] para…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0492

Published Jan 25, 2007

Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6952

Published Jan 24, 2007

Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by usin…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0010

Published Jan 24, 2007

The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image fil…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0020

Published Jan 24, 2007

Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0023

Published Jan 24, 2007

The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges vi…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0460

Published Jan 24, 2007

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calcu…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0461

Published Jan 24, 2007

Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0468

Published Jan 24, 2007

Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0469

Published Jan 24, 2007

The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to over…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0470

Published Jan 24, 2007

Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0471

Published Jan 24, 2007

sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0003

Published Jan 23, 2007

pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0441

Published Jan 23, 2007

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0442

Published Jan 23, 2007

Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6946

Published Jan 23, 2007

The web server in the NEC MultiWriter 1700C allows remote attackers to modify the device configuration via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6947

Published Jan 23, 2007

The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6948

Published Jan 23, 2007

MyODBC Japanese conversion edition 3.51.06, 2.50.29, and 2.50.25 allows remote attackers to cause a denial of service via a certain string in a response, which has unspecified imp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6949

Published Jan 23, 2007

Conti FTPServer 1.0 Build 2.8 stores user passwords in cleartext in MyServerSettings.ini, which allows local users to obtain sensitive information by reading this file.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6950

Published Jan 23, 2007

Directory traversal vulnerability in Conti FTPServer 1.0 Build 2.8 allows remote attackers to read arbitrary files and list arbitrary directories via a .. (dot dot) in a filename…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,101-6,125 of 6,516 CVEsPage 245 of 261