Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,951 CVEs tagged with CWE-201,639 Critical, 5,069 High, 5,717 Medium, 522 Low, 4 Unrated.

CVE-2007-1426

Published Mar 13, 2007

The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7139

Published Mar 7, 2007

Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-7160

Published Mar 7, 2007

The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7113

Published Mar 6, 2007

Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1277

Published Mar 5, 2007

WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externally introduced backdoor that allows remote attackers to exe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1257

Published Mar 3, 2007

The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 7600 allows remote attackers to execute arbitrary commands via certain SNMP packets that are spoofed fro…

CVSS 10.0 · Critical

CVE-2007-1235

Published Mar 3, 2007

Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filename with a double extension such as .php.jpg, which fails v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7070

Published Mar 2, 2007

Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier allows remote attackers to upload and execute arbitrary files…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1136

Published Mar 2, 2007

index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1155

Published Mar 2, 2007

Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature. NOTE: this issue…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1097

Published Feb 26, 2007

Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0908

Published Feb 13, 2007

The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows con…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6979

Published Feb 8, 2007

The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2219

Published Feb 8, 2007

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2220

Published Feb 8, 2007

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LI…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6971

Published Feb 7, 2007

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0802

Published Feb 7, 2007

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "."…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0683

Published Feb 3, 2007

PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6954

Published Jan 29, 2007

Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CV…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6955

Published Jan 29, 2007

Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6956

Published Jan 29, 2007

Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0521

Published Jan 26, 2007

The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a fi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0522

Published Jan 26, 2007

The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over B…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0523

Published Jan 26, 2007

The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 12,751-12,775 of 12,951 CVEsPage 511 of 519