CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-6625

    Last Modified: 23 Apr 2026

    The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.

    Published: 4 Jan 2008
    6.8
    Medium

    CVE-2007-6632

    Last Modified: 23 Apr 2026

    showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter.

    Published: 4 Jan 2008
    4.3
    Medium

    CVE-2007-6633

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to inject arbitrary web script or HTML via (1) the cat_name parameter to faq.php; and unspecified parameters to the (2) add categories, (3) edit categories, (4) delete categories, (5) add faq, (6) edit faq, and (7) delete faq Admin scripts.

    Published: 4 Jan 2008
    6.8
    Medium

    CVE-2007-6614

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/frontpage_right.php in Agares Media phpAutoVideo 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter, a related issue to CVE-2007-6542.

    Published: 3 Jan 2008
    7.5
    High

    CVE-2007-6619

    Last Modified: 23 Apr 2026

    The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows remote attackers to change the default language.

    Published: 3 Jan 2008
    4.3
    Medium

    CVE-2007-6616

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in simpleforum.cgi in SimpleForum 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchkey parameter in a search action. NOTE: some of these details are obtained from third party information.

    Published: 3 Jan 2008
    4.3
    Medium

    CVE-2007-6617

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input originally sent in the URI to secure/CreateIssue. NOTE: some of these details are obtained from third party information.

    Published: 3 Jan 2008
    5
    Medium

    CVE-2007-6618

    Last Modified: 23 Apr 2026

    JIRA Enterprise Edition before 3.12.1 allows remote attackers to delete another user's shared filter via a modified filter ID.

    Published: 3 Jan 2008
    6.8
    Medium

    CVE-2007-6615

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the selected_provider parameter.

    Published: 3 Jan 2008
    6.4
    Medium

    CVE-2007-6612

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in DirHandler (lib/mongrel/handlers.rb) in Mongrel 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to read arbitrary files via an HTTP request containing double-encoded sequences (".%252e").

    Published: 3 Jan 2008
    5
    Medium

    CVE-2008-0061

    Last Modified: 23 Apr 2026

    MaraDNS 1.0 before 1.0.41, 1.2 before 1.2.12.08, and 1.3 before 1.3.07.04 allows remote attackers to cause a denial of service via a crafted DNS packet that prevents an authoritative name (CNAME) record from resolving, aka "improper rotation of resource records."

    Published: 3 Jan 2008
    10
    Critical

    CVE-2007-6610

    Last Modified: 23 Apr 2026

    unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument. NOTE: this might only be a vulnerability when unp is invoked by a third party product.

    Published: 3 Jan 2008
    4.3
    Medium

    CVE-2008-1619

    Last Modified: 23 Apr 2026

    The ssm_i emulation in Xen 5.1 on IA64 architectures allows attackers to cause a denial of service (dom0 panic) via certain traffic, as demonstrated using an FTP stress test tool.

    Published: 3 Jan 2008
    4.3
    Medium

    CVE-2008-0564

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administrator interface, a different vulnerability than CVE-2006-3636.

    Published: 3 Jan 2008
    4.3
    Medium

    CVE-2007-6637

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web script or HTML via a crafted SWF file, related to "pre-generated SWF files" and Adobe Dreamweaver CS3 or Adobe Acrobat Connect. NOTE: the asfunction: vector is already covered by CVE-2007-6244.1.

    Published: 3 Jan 2008
    3.5
    Low

    CVE-2007-6421

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.

    Published: 2 Jan 2008
    4.3
    Medium

    CVE-2008-0005

    Last Modified: 23 Apr 2026

    mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.

    Published: 2 Jan 2008
    4
    Medium

    CVE-2007-6422

    Last Modified: 23 Apr 2026

    The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.

    Published: 1 Jan 2008
    5
    Medium

    CVE-2007-6603

    Last Modified: 23 Apr 2026

    Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.

    Published: 31 Dec 2007
    5
    Medium

    CVE-2007-6604

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password hash in a .dtb file under dati/membri/ or by executing embedded PHP code in images under uploads/avatar/.

    Published: 31 Dec 2007
    5.8
    Medium

    CVE-2007-6605

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers to execute arbitrary code via long strings in the first four arguments to the Start method.

    Published: 31 Dec 2007
    5
    Medium

    CVE-2007-6606

    Last Modified: 23 Apr 2026

    OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Published: 31 Dec 2007
    5
    Medium

    CVE-2007-6609

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.

    Published: 31 Dec 2007
    7.5
    High

    CVE-2007-6602

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in app/models/identity.php in NoseRub 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username field to the login script.

    Published: 31 Dec 2007
    5
    Medium

    CVE-2007-6607

    Last Modified: 23 Apr 2026

    OpenBiblio 0.5.2-pre4 and earlier allows remote attackers to obtain sensitive information via a direct request for (1) shared/footer.php, (2) circ/mbr_fields.php, or (3) admin/custom_marc_form_fields.php, which reveals the path in various error messages.

    Published: 31 Dec 2007
    4.3
    Medium

    CVE-2007-6608

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in OpenBiblio 0.5.2-pre4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) LAST and (2) FIRST parameters to admin/staff_del_confirm.php, (3) the name parameter to admin/theme_del_confirm.php, or (4) the themeName parameter to admin/theme_preview.php.

    Published: 31 Dec 2007
    2.1
    Low

    CVE-2007-6595

    Last Modified: 23 Apr 2026

    ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.

    Published: 31 Dec 2007
    5
    Medium

    CVE-2007-6596

    Last Modified: 23 Apr 2026

    ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.

    Published: 31 Dec 2007
    4.3
    Medium

    CVE-2007-6597

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IPortalX before Build 033 allow remote attackers to inject arbitrary web script or HTML via the (1) KW and (2) SF parameters to forum/login_user.asp, and (3) the Date parameter to blogs.asp.

    Published: 31 Dec 2007
    5
    Medium

    CVE-2007-6613

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and possibly execute arbitrary code via a disk or image that contains a long joilet file name.

    Published: 30 Dec 2007
    6.8
    Medium

    CVE-2007-6598

    Last Modified: 23 Apr 2026

    Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might allow remote authenticated users to login as a different user who has the same password.

    Published: 29 Dec 2007
    4.3
    Medium

    CVE-2007-6388

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Dec 2007
    7.5
    High

    CVE-2007-6566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6568

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6576

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Adult Script 1.6.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) videolink_count.php or (2) links.php.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6577

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the categ parameter in a categ action or (2) the article parameter in an articles action.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6578

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Dec 2007
    6.4
    Medium

    CVE-2007-6582

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6583

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/ops/findip/ajax/search.php in 1024 CMS 1.3.1 allows remote attackers to execute arbitrary SQL commands via the ip parameter.

    Published: 28 Dec 2007
    6.8
    Medium

    CVE-2007-6585

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6586

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a sezione page action to index.php.

    Published: 28 Dec 2007
    6.4
    Medium

    CVE-2007-6581

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang parameter to (1) header_album.php, (2) header_blog.php, or (3) header_group.php; or (4) admin_header_album.php, (5) admin_header_blog.php, or (6) admin_header_group.php in admin/.

    Published: 28 Dec 2007
    Unknown

    CVE-2007-6590

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-2809. Reason: This candidate is a duplicate of CVE-2008-2809. Notes: All CVE users should reference CVE-2008-2809 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Dec 2007
    6.9
    Medium

    CVE-2007-6594

    Last Modified: 23 Apr 2026

    IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6570

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6572

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6574

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6580

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.

    Published: 28 Dec 2007
    4.3
    Medium

    CVE-2007-6592

    Last Modified: 23 Apr 2026

    Apple Safari 2, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

    Published: 28 Dec 2007
    7.5
    High

    CVE-2007-6565

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to an arbitrary component.

    Published: 28 Dec 2007