Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,718 CVEs tagged with CWE-201,603 Critical, 4,989 High, 5,605 Medium, 515 Low, 6 Unrated.

CVE-2007-5281

Published Oct 9, 2007

The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS…

CVSS 5.0 · Medium

CVE-2007-5283

Published Oct 9, 2007

The TSC Domain Manager in Hitachi TPBroker Object Transaction Monitor and Cosminexus TPBroker Object Transaction Monitor 01-00 through 03-00 might allow attackers to cause a denia…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5275

Published Oct 8, 2007

The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4924

Published Oct 8, 2007

The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5269

Published Oct 8, 2007

Certain chunk handlers in libpng before 1.0.29 and 1.2.x before 1.2.21 allow remote attackers to cause a denial of service (crash) via crafted (1) pCAL (png_handle_pCAL), (2) sCAL…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5253

Published Oct 6, 2007

c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5258

Published Oct 6, 2007

PHP remote file inclusion vulnerability in log.php in phpFreeLog alpha 0.2.0 allows remote attackers to include and execute arbitrary files via unspecified vectors. NOTE: the ori…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5231

Published Oct 5, 2007

Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5226

Published Oct 5, 2007

irc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a N…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5155

Published Oct 1, 2007

IceGUI.DLL in ICEOWS 4.20b invokes a function with incorrect arguments, which allows user-assisted remote attackers to execute arbitrary code via a long filename in the header of…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5168

Published Oct 1, 2007

Multiple PHP remote file inclusion vulnerabilities in ClanLite 1.23.01.2005 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) module…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3753

Published Sep 27, 2007

Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute arbitrary code via crafted Ser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3755

Published Sep 27, 2007

Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make calls to arbitrary telephone numbers via a "tel:" link, which does not prompt the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3757

Published Sep 27, 2007

Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted "tel:" link that causes…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5128

Published Sep 27, 2007

SimpNews 2.41.03 on Windows, when PHP before 5.0.0 is used, allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php, which reveals…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5130

Published Sep 27, 2007

SimpGB 1.46.02 allows remote attackers to obtain sensitive information via (1) an invalid lang parameter to admin/index.php or (2) a direct request to admin/trailer.php, which rev…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4993

Published Sep 27, 2007

pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in d…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5119

Published Sep 27, 2007

JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5066

Published Sep 24, 2007

Unspecified vulnerability in Webmin before 1.370 on Windows allows remote authenticated users to execute arbitrary commands via a crafted URL.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5035

Published Sep 24, 2007

PHP remote file inclusion vulnerability in html/modules/extranet_profile/main.php in openEngine 1.9 beta1 allows remote attackers to execute arbitrary PHP code via a URL in the th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5036

Published Sep 24, 2007

Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated users to cause a denial of service (HTTPS service outage) v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,401-12,425 of 12,718 CVEsPage 497 of 509