CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-6732

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) plen arrays.

    Published: 27 Dec 2007
    7.5
    High

    CVE-2007-6631

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in LScube libnemesi 0.6.4-rc1 and earlier allow remote attackers to execute arbitrary code via (1) a reply that begins with a long version string, which triggers an overflow in handle_rtsp_pkt in rtsp_handlers.c; long headers that trigger overflows in (2) send_pause_request, (3) send_play_request, (4) send_setup_request, or (5) send_teardown_request in rtsp_send.c, as demonstrated by the Content-Base header; or a long Transport header, which triggers an overflow in (6) get_transport_str_sctp, (7) get_transport_str_tcp, or (8) get_transport_str_udp in rtsp_transport.c.

    Published: 27 Dec 2007
    10
    Critical

    CVE-2007-6731

    Last Modified: 23 Apr 2026

    Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.

    Published: 27 Dec 2007
    7.8
    High

    CVE-2007-6419

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 24 Dec 2007
    4.9
    Medium

    CVE-2007-6519

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the File-on-File Mounting File System (FFM) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows local users to cause a denial of service (system crash) via unspecified vectors.

    Published: 24 Dec 2007
    4.3
    Medium

    CVE-2007-6520

    Last Modified: 23 Apr 2026

    Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins.

    Published: 24 Dec 2007
    10
    Critical

    CVE-2007-6521

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.

    Published: 24 Dec 2007
    4.3
    Medium

    CVE-2007-6522

    Last Modified: 23 Apr 2026

    The rich text editing functionality in Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks by using designMode to modify contents of pages in other domains.

    Published: 24 Dec 2007
    7.5
    High

    CVE-2007-6517

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the forget password section (LostPwd.asp) in Eagle Software Aeries Browser Interface (ABI) 3.7.9.17 allows remote attackers to execute arbitrary SQL commands via the EmailAddress parameter. NOTE: some of these details are obtained from third party information.

    Published: 24 Dec 2007
    7.8
    High

    CVE-2007-6524

    Last Modified: 23 Apr 2026

    Opera before 9.25 allows remote attackers to obtain potentially sensitive memory contents via a crafted bitmap (BMP) file, as demonstrated using a CANVAS element and JavaScript in an HTML document for copying these contents from 9.50 beta, a related issue to CVE-2008-0420.

    Published: 24 Dec 2007
    7.5
    High

    CVE-2007-6518

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in search.php in WoltLab Burning Board (wBB) Lite 1.0.2 pl3e allow remote attackers to execute arbitrary SQL commands via the (1) showposts, (2) sortby, and (3) sortorder parameters.

    Published: 24 Dec 2007
    7.8
    High

    CVE-2007-6523

    Last Modified: 23 Apr 2026

    Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) via a crafted bitmap (BMP) file that triggers a large number of calculations and checks.

    Published: 24 Dec 2007
    9.3
    Critical

    CVE-2008-0668

    Last Modified: 23 Apr 2026

    The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file containing XLS HLINK opcodes, possibly because of an integer signedness error that leads to an integer overflow. NOTE: some of these details are obtained from third party information.

    Published: 24 Dec 2007
    6.4
    Medium

    CVE-2007-5342

    Last Modified: 23 Apr 2026

    The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

    Published: 23 Dec 2007
    5
    Medium

    CVE-2007-6512

    Last Modified: 23 Apr 2026

    PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc.

    Published: 21 Dec 2007
    4.3
    Medium

    CVE-2007-6513

    Last Modified: 23 Apr 2026

    HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method.

    Published: 21 Dec 2007
    7.5
    High

    CVE-2007-6515

    Last Modified: 23 Apr 2026

    support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string.

    Published: 21 Dec 2007
    6.8
    Medium

    CVE-2007-6516

    Last Modified: 23 Apr 2026

    Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property.

    Published: 21 Dec 2007
    7.5
    High

    CVE-2007-6508

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (dot dot slash) in the list parameter.

    Published: 21 Dec 2007
    7.8
    High

    CVE-2007-6509

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp.

    Published: 21 Dec 2007
    6.8
    Medium

    CVE-2007-6510

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file to the (1) AMOS-MusicBank, (2) FuzzacPacker, and (3) QuadraComposer rippers; and (4) have an unknown impact via a crafted file to the SkytPacker ripper.

    Published: 21 Dec 2007
    5
    Medium

    CVE-2007-6511

    Last Modified: 23 Apr 2026

    Websense Enterprise 6.3.1 allows remote attackers to bypass content filtering by visiting http URLs with a (1) RealPlayer G2, (2) MSMSGS, or (3) StoneHttpAgent User-Agent header, which results in a Non-HTTP categorization.

    Published: 21 Dec 2007
    4.3
    Medium

    CVE-2007-5965

    Last Modified: 23 Apr 2026

    QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid server certificate for a spoofed service, or trick a service into accepting an invalid client certificate for a user.

    Published: 21 Dec 2007
    5
    Medium

    CVE-2007-6334

    Last Modified: 23 Apr 2026

    Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the same as the first user, which allows remote attackers to gain privileges.

    Published: 20 Dec 2007
    7.8
    High

    CVE-2007-6349

    Last Modified: 23 Apr 2026

    P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with an empty body and a Content-Length greater than 0.

    Published: 20 Dec 2007
    3.5
    Low

    CVE-2007-6505

    Last Modified: 23 Apr 2026

    Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root, which makes it easier for attackers to avoid detection and can make it more difficult to conduct forensics activities.

    Published: 20 Dec 2007
    9.3
    Critical

    CVE-2007-6506

    Last Modified: 23 Apr 2026

    The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile method.

    Published: 20 Dec 2007
    10
    Critical

    CVE-2007-6507

    Last Modified: 23 Apr 2026

    SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.dll in the DCE/RPC interface, which allows remote attackers to obtain "full file system access" and execute arbitrary code.

    Published: 20 Dec 2007
    5.8
    Medium

    CVE-2007-6473

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command.

    Published: 20 Dec 2007
    4.3
    Medium

    CVE-2007-6474

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors.

    Published: 20 Dec 2007
    6.8
    Medium

    CVE-2007-6478

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Rosoft Media Player 4.1.7, 4.1.8, and possibly earlier versions allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a .M3U file. NOTE: some of these details are obtained from third party information.

    Published: 20 Dec 2007
    4.9
    Medium

    CVE-2007-6479

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/.

    Published: 20 Dec 2007
    9.4
    Critical

    CVE-2007-6480

    Last Modified: 23 Apr 2026

    The Oracle database component in Sun Management Center (Sun MC) 3.6.1, 3.6, and 3.5 Update 1 has a default account, which allows remote attackers to obtain database access and execute arbitrary code.

    Published: 20 Dec 2007
    6.4
    Medium

    CVE-2007-6481

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to create or delete arbitrary directories via unspecified vectors.

    Published: 20 Dec 2007
    7.8
    High

    CVE-2007-6482

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Device Manager daemon (utdevmgrd) in Sun Ray Server Software 2.0, 3.0, 3.1, and 3.1.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 20 Dec 2007
    4.3
    Medium

    CVE-2007-6486

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information.

    Published: 20 Dec 2007
    6.8
    Medium

    CVE-2007-6488

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.

    Published: 20 Dec 2007
    7.5
    High

    CVE-2007-6489

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors.

    Published: 20 Dec 2007
    4.3
    Medium

    CVE-2007-6490

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.

    Published: 20 Dec 2007
    6.5
    Medium

    CVE-2007-6495

    Last Modified: 23 Apr 2026

    inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser action to accounts/AccountActions.asp. NOTE: this can be leveraged for remote code execution by changing the permissions of \Forum\db, which is configured for execution of ASP scripts with administrative privileges, and then uploading a script to \Forum\db.

    Published: 20 Dec 2007
    6.8
    Medium

    CVE-2007-6496

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests to hosting/default.asp and hosting/selectdomain.asp, a related issue to CVE-2005-1654.

    Published: 20 Dec 2007
    7.5
    High

    CVE-2007-6497

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219.

    Published: 20 Dec 2007
    5.5
    Medium

    CVE-2007-6501

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp.

    Published: 20 Dec 2007
    5.5
    Medium

    CVE-2007-6503

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an arbitrary plan via a request to hosting/AutoSignUpPlans.asp with the (a) save, (b) 30, and (c) d_30 parameters.

    Published: 20 Dec 2007
    5.5
    Medium

    CVE-2007-6504

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitrary hosts via an unspecified parameter.

    Published: 20 Dec 2007
    7.1
    High

    CVE-2007-6492

    Last Modified: 23 Apr 2026

    The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earlier allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via an empty string in the argument to the ProcessRequestEx method.

    Published: 20 Dec 2007
    10
    Critical

    CVE-2007-6494

    Last Modified: 23 Apr 2026

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.

    Published: 20 Dec 2007
    5.5
    Medium

    CVE-2007-6499

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbitrary account via a request to fp2002/UNINSTAL.asp with a "host id (IIS) value."

    Published: 20 Dec 2007
    7.5
    High

    CVE-2007-6472

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some of these details are obtained from third party information.

    Published: 20 Dec 2007
    5
    Medium

    CVE-2007-6476

    Last Modified: 23 Apr 2026

    GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function.

    Published: 20 Dec 2007