Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0418

Published Jan 23, 2007

BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0419

Published Jan 23, 2007

The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0420

Published Jan 23, 2007

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0421

Published Jan 23, 2007

BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0422

Published Jan 23, 2007

BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0423

Published Jan 23, 2007

BEA WebLogic Portal 9.2 does not properly handle when an administrator deletes entitlements for a role, which causes other role entitlements to be "inadvertently affected," which…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0424

Published Jan 23, 2007

Unspecified vulnerability in the BEA WebLogic Server proxy plug-in for Netscape Enterprise Server before September 2006 for Netscape Enterprise Server allow remote attackers to ca…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0425

Published Jan 23, 2007

Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0426

Published Jan 23, 2007

BEA WebLogic Portal 9.2, when running in a WebLogic Server clustered environment using WebLogic Portal entitlements, does not properly propagate entitlement policy changes if the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0427

Published Jan 23, 2007

Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP fie…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0398

Published Jan 22, 2007

Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0399

Published Jan 22, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0400

Published Jan 22, 2007

Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyw…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0401

Published Jan 22, 2007

SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0402

Published Jan 22, 2007

Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML v…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0403

Published Jan 22, 2007

SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6945

Published Jan 19, 2007

SQL injection vulnerability in Virtuemart 1.0.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) Itemid, (2) product_id,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0368

Published Jan 19, 2007

Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string in the MBSE_ROOT environment variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0369

Published Jan 19, 2007

SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands via the comment forum.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0370

Published Jan 19, 2007

Unrestricted file upload vulnerability in index.php in phpBP RC3 (2.204) and earlier allows remote administrators to inject arbitrary PHP code into an upload/banners/ file via a b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0372

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in Francisco Burzi PHP-Nuke 7.9 allow remote attackers to execute arbitrary SQL commands via (1) the active parameter in admin/modules/modul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0373

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in Joomla! 1.5.0 Beta allow remote attackers to execute arbitrary SQL commands via (1) the searchword parameter in certain files; the where…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0374

Published Jan 19, 2007

SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 6,151-6,175 of 6,516 CVEsPage 247 of 261