Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,967 CVEs tagged with CWE-201,639 Critical, 5,075 High, 5,724 Medium, 522 Low, 7 Unrated.

CVE-2007-1155

Published Mar 2, 2007

Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbitrary PHP code via the add squad feature. NOTE: this issue…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1097

Published Feb 26, 2007

Unrestricted file upload vulnerability in the onAttachFiles function in the upload tool (inc/lib/attachment.lib.php) in Wiclear before 0.11.1 allows remote attackers to upload and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0908

Published Feb 13, 2007

The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows con…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6979

Published Feb 8, 2007

The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2219

Published Feb 8, 2007

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2220

Published Feb 8, 2007

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LI…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6971

Published Feb 7, 2007

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0802

Published Feb 7, 2007

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "."…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0683

Published Feb 3, 2007

PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6954

Published Jan 29, 2007

Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CV…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6955

Published Jan 29, 2007

Opera allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6956

Published Jan 29, 2007

Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0521

Published Jan 26, 2007

The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a fi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0522

Published Jan 26, 2007

The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over B…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0523

Published Jan 26, 2007

The Nokia N70 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-0524

Published Jan 26, 2007

The LG Chocolate KG800 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Blu…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6943

Published Jan 19, 2007

PhpMyAdmin before 2.9.1.1 allows remote attackers to obtain the full server path via direct requests to (a) scripts/check_lang.php and (b) themes/darkblue_orange/layout.inc.php; a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0197

Published Jan 11, 2007

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0102

Published Jan 9, 2007

The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop),…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0103

Published Jan 9, 2007

The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite lo…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0104

Published Jan 9, 2007

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to h…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5265

Published Dec 31, 2006

Unspecified vulnerability in Microsoft Dynamics GP (formerly Great Plains) 9.0 and earlier allows remote attackers to cause a denial of service (crash) via an invalid magic number…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5867

Published Dec 31, 2006

fetchmail before 6.3.6-rc4 does not properly enforce TLS and may transmit cleartext passwords over unsecured links if certain circumstances occur, which allows remote attackers to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 12,776-12,800 of 12,967 CVEsPage 512 of 519