Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,719 CVEs tagged with CWE-201,604 Critical, 4,989 High, 5,605 Medium, 515 Low, 6 Unrated.

CVE-2007-5734

Published Oct 30, 2007

Unrestricted file upload vulnerability in eFileMan 7.1.0.87-88 allows remote attackers to upload arbitrary files, with "uploads/upload_file." destination filenames, via unspecifie…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5736

Published Oct 30, 2007

Unrestricted file upload vulnerability in upload.php in SeeBlick 1.0 Beta allows remote attackers to upload arbitrary files via unspecified vectors. NOTE: these files are stored…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5737

Published Oct 30, 2007

Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified vectors, probably involving a di…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5738

Published Oct 30, 2007

The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass rest…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5711

Published Oct 30, 2007

Massive Entertainment World in Conflict 1.001 and earlier allows remote attackers to cause a denial of service (failed assertion and daemon crash) via a large packet to TCP or UDP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4999

Published Oct 29, 2007

libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5691

Published Oct 29, 2007

ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, relat…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5570

Published Oct 18, 2007

Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5556

Published Oct 18, 2007

Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5557

Published Oct 18, 2007

Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5563

Published Oct 18, 2007

Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5540

Published Oct 18, 2007

Unspecified vulnerability in Opera before 9.24 allows remote attackers to overwrite functions on pages from other domains and bypass the same-origin policy via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5541

Published Oct 18, 2007

Unspecified vulnerability in Opera before 9.24, when using an "external" newsgroup or e-mail client, allows remote attackers to execute arbitrary commands via unknown vectors.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5507

Published Oct 17, 2007

The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a de…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5462

Published Oct 15, 2007

Unspecified vulnerability in the Sun Solaris RPC services library (librpcsvc) on Solaris 8 through 10 allows remote attackers to cause a denial of service (mountd crash) via unspe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5448

Published Oct 14, 2007

Madwifi 0.9.3.2 and earlier allows remote attackers to cause a denial of service (panic) via a beacon frame with a large length value in the extended supported rates (xrates) elem…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5440

Published Oct 14, 2007

Multiple PHP remote file inclusion vulnerabilities in CRS Manager allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) index.php or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5208

Published Oct 13, 2007

hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharac…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5375

Published Oct 11, 2007

Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 12,376-12,400 of 12,719 CVEsPage 496 of 509