CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-6407

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or (3) involving unspecified vectors related to "error processing."

    Published: 17 Dec 2007
    6.5
    Medium

    CVE-2007-6393

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode.

    Published: 17 Dec 2007
    5
    Medium

    CVE-2007-6397

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username parameter when registering a user account, and (2) read arbitrary PHP files via a .. (dot dot) in (a) the topic parameter in a topic action or (b) the username parameter in a viewprofile action.

    Published: 17 Dec 2007
    9.3
    Critical

    CVE-2007-6402

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6401.

    Published: 17 Dec 2007
    5
    Medium

    CVE-2007-6408

    Last Modified: 23 Apr 2026

    IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames.

    Published: 17 Dec 2007
    5
    Medium

    CVE-2007-6395

    Last Modified: 23 Apr 2026

    Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/.

    Published: 17 Dec 2007
    5
    Medium

    CVE-2007-6400

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read arbitrary files via a .. (dot dot) or absolute pathname in the filename parameter.

    Published: 17 Dec 2007
    9.3
    Critical

    CVE-2007-6401

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402.

    Published: 17 Dec 2007
    4.3
    Medium

    CVE-2007-6406

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CA (formerly Computer Associates) eTrust Threat Management Console allow remote attackers to inject arbitrary web script or HTML via the IP Address field and other unspecified fields.

    Published: 17 Dec 2007
    5.9
    Medium

    CVE-2007-4774

    Last Modified: 21 Nov 2024

    The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptraced process with SIGCONT signals, which can can wake up a PTRACED process.

    Published: 17 Dec 2007
    5.8
    Medium

    CVE-2007-6245

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 allows remote attackers to modify HTTP headers for client requests and conduct HTTP Request Splitting attacks.

    Published: 17 Dec 2007
    4.4
    Medium

    CVE-2007-6246

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges.

    Published: 17 Dec 2007
    4.3
    Medium

    CVE-2007-6244

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToURL function when used with the Flash Player ActiveX Control in Internet Explorer.

    Published: 17 Dec 2007
    6.8
    Medium

    CVE-2007-6242

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Player 9.0.48.0 and earlier might allow remote attackers to execute arbitrary code via unknown vectors, related to "input validation errors."

    Published: 17 Dec 2007
    6.8
    Medium

    CVE-2007-6714

    Last Modified: 23 Apr 2026

    DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty password, which causes the LDAP bind to indicate success based on anonymous authentication.

    Published: 16 Dec 2007
    6.5
    Medium

    CVE-2007-6381

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the indexed_search system extension in TYPO3 3.x, 4.0 through 4.0.7, and 4.1 through 4.1.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Dec 2007
    6.8
    Medium

    CVE-2007-6382

    Last Modified: 23 Apr 2026

    The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbitrary Java code by using a robot to invoke the SwingUtilities.invokeLater method.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6384

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attackers to obtain application file and resource access via unspecified vectors.

    Published: 15 Dec 2007
    2.1
    Low

    CVE-2007-6385

    Last Modified: 23 Apr 2026

    The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 15 Dec 2007
    7.2
    High

    CVE-2007-6386

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in PccScan.dll before build 1451 in Trend Micro AntiVirus plus AntiSpyware 2008, Internet Security 2008, and Internet Security Pro 2008 allows user-assisted remote attackers to cause a denial of service (SfCtlCom.exe crash), and allows local users to gain privileges, via a malformed .zip archive with a long name, as demonstrated by a .zip file created via format string specifiers in a crafted .uue file.

    Published: 15 Dec 2007
    9.3
    Critical

    CVE-2007-6387

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1) GetHistory, (2) GetSeedQuery, (3) SetSeedQuery, and possibly other methods. NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2007
    5.5
    Medium

    CVE-2007-6383

    Last Modified: 23 Apr 2026

    The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to create arbitrary resources in another user's home collection.

    Published: 15 Dec 2007
    9.3
    Critical

    CVE-2007-4707

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Flash media handler in Apple QuickTime before 7.3.1 allow remote attackers to execute arbitrary code or have other unspecified impacts via a crafted QuickTime movie.

    Published: 15 Dec 2007
    4.3
    Medium

    CVE-2007-5582

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login page in Cisco CiscoWorks Server (CS), possibly 2.6 and earlier, when using CiscoWorks Common Services 3.0.x and 3.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Dec 2007
    2.1
    Low

    CVE-2007-6249

    Last Modified: 23 Apr 2026

    etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.

    Published: 15 Dec 2007
    7.8
    High

    CVE-2007-6360

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Sun eXtended System Control Facility (XSCF) Control Package (XCP) firmware before 1050 on SPARC Enterprise M4000, M5000, M8000, and M9000 servers allows remote attackers to cause a denial of service (reboot) via (1) telnet, (2) ssh, or (3) http network traffic that triggers memory exhaustion.

    Published: 15 Dec 2007
    5
    Medium

    CVE-2007-6361

    Last Modified: 23 Apr 2026

    Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6362

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an inline page action.

    Published: 15 Dec 2007
    4.3
    Medium

    CVE-2007-6367

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the guestbook in SineCMS 2.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username (user) or (2) comment (commento) field, different vectors than CVE-2007-2357.

    Published: 15 Dec 2007
    5
    Medium

    CVE-2007-6368

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the link parameter.

    Published: 15 Dec 2007
    5
    Medium

    CVE-2007-6369

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) size or (2) path parameter.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6366

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to mods/Calendar/index.php, accessed through a Calendar info action to mods.php; the id parameter to admin/mods_adm.php in a (2) Guestbook modifica or (3) Calendar modify action; or the (4) mese or (5) anno parameter to admin/mods_adm.php in a Calendar action. NOTE: the component for vectors 2 through 5 might be limited to administrators.

    Published: 15 Dec 2007
    Unknown

    CVE-2007-6370

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-5583. Reason: This candidate is a duplicate of CVE-2007-5583. Notes: All CVE users should reference CVE-2007-5583 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6373

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in GestDown 1.00 Beta allow remote attackers to execute arbitrary SQL commands via the (1) categorie parameter to catdownload.php, or the id parameter to (2) download.php or (3) hitcounter.php.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6375

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sort_mode parameter to wiki/list_pages.php and the (2) highlight parameter to search/index.php. NOTE: the researcher also reported injection via JavaScript code in the Search box, but this is probably a forced SQL error or other separate primary issue.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6377

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attackers to execute arbitrary code via a long query string.

    Published: 15 Dec 2007
    10
    Critical

    CVE-2007-6195

    Last Modified: 23 Apr 2026

    Buffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 and B.11.23 allows remote attackers to execute arbitrary code or cause a denial of service via malformed arguments in an opcode 0x04 DCE RPC request.

    Published: 15 Dec 2007
    4.9
    Medium

    CVE-2007-6358

    Last Modified: 23 Apr 2026

    pdftops.pl before 1.20 in alternate pdftops filter allows local users to overwrite arbitrary files via a symlink attack on the pdfin.[PID].tmp temporary file, which is created when pdftops reads a PDF file from stdin, such as when pdftops is invoked by CUPS.

    Published: 15 Dec 2007
    2.1
    Low

    CVE-2007-6363

    Last Modified: 23 Apr 2026

    IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without entering a password.

    Published: 15 Dec 2007
    4.3
    Medium

    CVE-2007-6365

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 allows remote attackers to inject arbitrary web script or HTML via the month parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: the day and year vectors are covered by CVE-2007-6274.

    Published: 15 Dec 2007
    5
    Medium

    CVE-2007-6379

    Last Modified: 23 Apr 2026

    BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.

    Published: 15 Dec 2007
    6.8
    Medium

    CVE-2007-4706

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.3.1 allows remote attackers to execute arbitrary code via a crafted QTL file.

    Published: 15 Dec 2007
    10
    Critical

    CVE-2007-5580

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6338

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2007
    4.9
    Medium

    CVE-2007-6359

    Last Modified: 23 Apr 2026

    The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allows local users to cause a denial of service (failed assertion and system crash) via a crafted signed Mach-O binary that causes the hashes function to return NULL.

    Published: 15 Dec 2007
    7.8
    High

    CVE-2007-6372

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that trigger session flapping.

    Published: 15 Dec 2007
    4.3
    Medium

    CVE-2007-6374

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) users/register.php or (2) search/index.php, or an editcomments action in (3) wiki/index.php or (4) forums/index.php. NOTE: the error parameter to users/login.php is covered by CVE-2006-3103.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6376

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in autohtml.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the filename parameter, a different vector than CVE-2006-4190. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6380

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) mylinks/ratelink.php, (b) adresses/ratefile.php, (c) mydownloads/ratefile.php, (d) mysections/ratefile.php, and (e) myalbum/ratephoto.php in modules/; the (2) bid parameter to (f) modules/banners/click.php; and the (3) gid parameter to (g) modules/arcade/index.php in a show_stats and play_game action, related issues to CVE-2007-5104 and CVE-2007-6266.

    Published: 15 Dec 2007
    5.8
    Medium

    CVE-2007-6357

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.

    Published: 15 Dec 2007