Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2006-6951

Published Jan 23, 2007

Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog allows remote attackers to inject arbitrary web script or HTML via the page parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0428

Published Jan 23, 2007

Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probab…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0429

Published Jan 23, 2007

DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0430

Published Jan 23, 2007

The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount val…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0431

Published Jan 23, 2007

AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0432

Published Jan 23, 2007

BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization poli…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0433

Published Jan 23, 2007

Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remot…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0434

Published Jan 23, 2007

BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which mi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0021

Published Jan 23, 2007

Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0022

Published Jan 23, 2007

Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0404

Published Jan 23, 2007

bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0405

Published Jan 23, 2007

The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0406

Published Jan 23, 2007

Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier all…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0407

Published Jan 23, 2007

Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the user…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0408

Published Jan 23, 2007

BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, which allows remote attackers to obtain access via an untru…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0409

Published Jan 23, 2007

BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local…

CVSS 1.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0410

Published Jan 23, 2007

Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0411

Published Jan 23, 2007

BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0412

Published Jan 23, 2007

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or ex…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0413

Published Jan 23, 2007

BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0414

Published Jan 23, 2007

BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to cause a denial of service (server hang) via certain requests…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0415

Published Jan 23, 2007

BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic redeployment of an application that is implemented through expl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0416

Published Jan 23, 2007

The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass appl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0417

Published Jan 23, 2007

BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB contain…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 6,126-6,150 of 6,516 CVEsPage 246 of 261