Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,727 CVEs tagged with CWE-201,607 Critical, 4,993 High, 5,608 Medium, 515 Low, 4 Unrated.

CVE-2007-6527

Published Dec 27, 2007

uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attacker…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6509

Published Dec 21, 2007

Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 54…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4567

Published Dec 21, 2007

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6488

Published Dec 20, 2007

Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6492

Published Dec 20, 2007

The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to cause a denial of service (In…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6493

Published Dec 20, 2007

The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to execute arbitrary code via a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6494

Published Dec 20, 2007

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, f…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6242

Published Dec 20, 2007

Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation error…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6433

Published Dec 18, 2007

The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6371

Published Dec 15, 2007

Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to cause a denial of service (device inoperability) via a SIP INVITE message accompanied by an immediate…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6372

Published Dec 15, 2007

Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6325

Published Dec 13, 2007

PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attackers to execute arbitrary PHP code via a URL in the config[fs…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6326

Published Dec 13, 2007

Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6299

Published Dec 10, 2007

Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6271

Published Dec 7, 2007

Absolute News Manager.NET 5.1 allows remote attackers to obtain sensitive information via a direct request to getpath.aspx, which reveals the installation path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6278

Published Dec 7, 2007

Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6263

Published Dec 6, 2007

The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, wh…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6235

Published Dec 4, 2007

A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6239

Published Dec 4, 2007

The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6218

Published Dec 4, 2007

Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) instal…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6207

Published Dec 4, 2007

Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-7225

Published Dec 3, 2007

Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,326-12,350 of 12,727 CVEsPage 494 of 510