Skip to main content

Year archive

CVEs published in 2007

Archive summary

6,516 CVEs published in 2007 — 994 Critical, 2,189 High, 3,101 Medium, 232 Low, 0 Unrated.

CVE-2007-0375

Published Jan 19, 2007

Joomla! 1.5.0 Beta allows remote attackers to obtain sensitive information via a direct request for (1) plugins/user/example.php; (2) gmail.php, (3) example.php, or (4) ldap.php i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0376

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in Virtuemart 1.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0377

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in Xoops 2.0.16 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in kernel/group.php in core, (2) the lid p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0378

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0379

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0380

Published Jan 19, 2007

DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0381

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in ATutor 1.5.3.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. NOTE: CVE analysis suggests that the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0382

Published Jan 19, 2007

Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0383

Published Jan 19, 2007

WDaemon 9.5.4 allows remote attackers to access the /WorldClient.dll URI on TCP port 3000, which has unknown impact. NOTE: The researcher reports that the vendor response was "th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0384

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in preview in the reviews section in PostNuke 0.764 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0385

Published Jan 19, 2007

The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefine…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0386

Published Jan 19, 2007

Unspecified vulnerability in the rating section in PostNuke 0.764 has unknown impact and attack vectors, related to "an interesting bug."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0387

Published Jan 19, 2007

SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0388

Published Jan 19, 2007

SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the 2.x series, allows remote attackers to execute arbitrary S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0390

Published Jan 19, 2007

Cross-site scripting (XSS) vulnerability in index.php in sabros.us 1.7 allows remote attackers to inject arbitrary web script or HTML via the tag parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0391

Published Jan 19, 2007

Format string vulnerability in the log creation functionality of BitDefender Client Professional Plus 8.02 allows attackers to execute arbitrary code via certain scan job settings.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0392

Published Jan 19, 2007

IBM AIX 5.3 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 and…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0393

Published Jan 19, 2007

Sun Solaris 9 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2 an…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0394

Published Jan 19, 2007

HP HP-UX B11.11 does not properly verify the status of file descriptors before setuid execution, which allows local users to gain privileges by closing file descriptor 0, 1, or 2…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0395

Published Jan 19, 2007

PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0396

Published Jan 19, 2007

Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecifi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0019

Published Jan 19, 2007

Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecif…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0367

Published Jan 19, 2007

Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknow…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,176-6,200 of 6,516 CVEsPage 248 of 261