Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,725 CVEs tagged with CWE-201,606 Critical, 4,992 High, 5,606 Medium, 515 Low, 6 Unrated.

CVE-2007-6179

Published Nov 30, 2007

Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the ccms_library_path parameter to (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6165

Published Nov 29, 2007

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6133

Published Nov 27, 2007

PHP remote file inclusion vulnerability in admin/kfm/initialise.php in DevMass Shopping Cart 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6146

Published Nov 27, 2007

Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-02 on Windows might allow remote attackers to cause a denial of service (service stop) via a "specific file" argument…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6122

Published Nov 26, 2007

The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long pas…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6129

Published Nov 26, 2007

Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) i…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6101

Published Nov 23, 2007

Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, an…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6103

Published Nov 23, 2007

I Hear U (IHU) 0.5.6 and earlier allows remote attackers to cause (1) a denial of service (infinite loop) via a packet that contains zero in the size field in its header, which is…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6062

Published Nov 20, 2007

irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6060

Published Nov 20, 2007

AhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP header, which allows remote at…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6039

Published Nov 20, 2007

PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6036

Published Nov 20, 2007

The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash) via a short RTSP query, whic…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6010

Published Nov 15, 2007

Unspecified vulnerability in pioneers (formerly gnocatan) 0.11.3 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors that trigger an assert…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4695

Published Nov 15, 2007

Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5984

Published Nov 15, 2007

classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the di…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5933

Published Nov 13, 2007

Pioneers (formerly gnocatan) before 0.11.3 allows remote attackers to cause a denial of service (crash) by triggering a delete operation while the Session object is still being us…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5925

Published Nov 10, 2007

The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (da…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5926

Published Nov 10, 2007

OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, an…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5928

Published Nov 10, 2007

OpenBase 10.0.5 and earlier allows remote authenticated users to trigger a free of an arbitrary memory location via long strings in a SELECT statement. NOTE: this might be a buff…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4570

Published Nov 10, 2007

Algorithmic complexity vulnerability in the MCS translation daemon in mcstrans 0.2.3 allows local users to cause a denial of service (temporary daemon outage) via a large range of…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort
Showing 12,351-12,375 of 12,725 CVEsPage 495 of 509