CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-6364

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modificarPerfil.php in JLMForo System allows remote authenticated users to inject arbitrary web script or HTML via a signature.

    Published: 15 Dec 2007
    7.1
    High

    CVE-2007-6371

    Last Modified: 23 Apr 2026

    Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to cause a denial of service (device inoperability) via a SIP INVITE message accompanied by an immediately subsequent SIP CANCEL message, followed by a second SIP INVITE message in a different session.

    Published: 15 Dec 2007
    7.5
    High

    CVE-2007-6378

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upload.dll in BadBlue 2.72b and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 15 Dec 2007
    4.6
    Medium

    CVE-2007-6416

    Last Modified: 23 Apr 2026

    The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations.

    Published: 14 Dec 2007
    5
    Medium

    CVE-2007-6437

    Last Modified: 23 Apr 2026

    Balabit syslog-ng 2.0.x before 2.0.6 and 2.1.x before 2.1.8 allows remote attackers to cause a denial of service (crash) via a message with a timestamp that does not contain a trailing space, which triggers a NULL pointer dereference.

    Published: 14 Dec 2007
    4.3
    Medium

    CVE-2007-6351

    Last Modified: 23 Apr 2026

    libexif 0.6.16 and earlier allows context-dependent attackers to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.

    Published: 14 Dec 2007
    4.7
    Medium

    CVE-2007-5963

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in kdebase allows local users to cause a denial of service (KDM login inaccessible, or resource consumption) via unknown vectors.

    Published: 14 Dec 2007
    6.8
    Medium

    CVE-2007-6352

    Last Modified: 23 Apr 2026

    Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.

    Published: 14 Dec 2007
    7.5
    High

    CVE-2007-6345

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in aurora framework before 20071208 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly the value parameter to the pack_var function in module/db.lib/db_mysql.lib. NOTE: some of these details are obtained from third party information.

    Published: 13 Dec 2007
    4.3
    Medium

    CVE-2007-6346

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Rainboard before 2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Dec 2007
    4.3
    Medium

    CVE-2007-6343

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Dec 2007
    6.8
    Medium

    CVE-2007-6347

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third party information.

    Published: 13 Dec 2007
    6.8
    Medium

    CVE-2007-6344

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.

    Published: 13 Dec 2007
    7.5
    High

    CVE-2007-6342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.

    Published: 13 Dec 2007
    6.8
    Medium

    CVE-2007-5989

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the skype4com URI handler in Skype before 3.6 GOLD allows remote attackers to execute arbitrary code via "short string values" that result in heap corruption.

    Published: 13 Dec 2007
    10
    Critical

    CVE-2007-6204

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

    Published: 13 Dec 2007
    5.8
    Medium

    CVE-2007-6333

    Last Modified: 23 Apr 2026

    The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method.

    Published: 13 Dec 2007
    10
    Critical

    CVE-2007-6330

    Last Modified: 23 Apr 2026

    Meridian Prolog Manager 2007, and 7.5 and earlier, sends all usernames and passwords to the client in a (1) cleartext or (2) weakly encrypted format to support client-side login authentication, which makes it easier for remote attackers to obtain database access by capturing credentials via a man-in-the-middle attack.

    Published: 13 Dec 2007
    5
    Medium

    CVE-2007-6326

    Last Modified: 23 Apr 2026

    Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI.

    Published: 13 Dec 2007
    7.5
    High

    CVE-2007-6327

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attackers to execute arbitrary code via a long first argument to the CreateStill method.

    Published: 13 Dec 2007
    9.3
    Critical

    CVE-2007-6331

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp method. NOTE: only a user-assisted attack is possible on Windows Vista.

    Published: 13 Dec 2007
    9.3
    Critical

    CVE-2007-6332

    Last Modified: 23 Apr 2026

    The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the SetRegValue method.

    Published: 13 Dec 2007
    6.4
    Medium

    CVE-2007-6329

    Last Modified: 23 Apr 2026

    Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.

    Published: 13 Dec 2007
    6.8
    Medium

    CVE-2007-6325

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attackers to execute arbitrary PHP code via a URL in the config[fsBase] parameter, a different vector than CVE-2006-2726.

    Published: 13 Dec 2007
    6.8
    Medium

    CVE-2007-6324

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 13 Dec 2007
    5
    Medium

    CVE-2007-6323

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MMS Gallery PHP 1.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) get_image.php or (2) get_file.php in mms_template/.

    Published: 13 Dec 2007
    5
    Medium

    CVE-2007-6322

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in filedownload.php in xml2owl 0.1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 13 Dec 2007
    6.8
    Medium

    CVE-2007-6348

    Last Modified: 23 Apr 2026

    SquirrelMail 1.4.11 and 1.4.12, as distributed on sourceforge.net before 20071213, has been externally modified to create a Trojan Horse that introduces a PHP remote file inclusion vulnerability, which allows remote attackers to execute arbitrary code.

    Published: 13 Dec 2007
    7.2
    High

    CVE-2007-5848

    Last Modified: 23 Apr 2026

    Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code via a crafted URI to the CUPS service.

    Published: 13 Dec 2007
    9.3
    Critical

    CVE-2007-5849

    Last Modified: 23 Apr 2026

    Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.

    Published: 13 Dec 2007
    4.9
    Medium

    CVE-2007-6283

    Last Modified: 23 Apr 2026

    Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.

    Published: 13 Dec 2007
    6.9
    Medium

    CVE-2007-5964

    Last Modified: 23 Apr 2026

    The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which allows local users to gain privileges via a setuid program on a remote NFS server.

    Published: 12 Dec 2007
    4.3
    Medium

    CVE-2007-6320

    Last Modified: 23 Apr 2026

    Feature 4.7.x-dev and 5.x-dev before 20071206, a Drupal module, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks.

    Published: 12 Dec 2007
    5.5
    Medium

    CVE-2007-6317

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a ..\ (dot dot backslash) sequence in the dir parameter to /drive/c/bdusers/USER/.

    Published: 12 Dec 2007
    8.5
    High

    CVE-2007-3901

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted SAMI file.

    Published: 12 Dec 2007
    9.3
    Critical

    CVE-2007-3895

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file.

    Published: 12 Dec 2007
    6.8
    Medium

    CVE-2007-5344

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via a crafted website using Javascript that creates, modifies, deletes, and accesses document objects using the tags property, which triggers heap corruption, related to uninitialized or deleted objects, a different issue than CVE-2007-3902 and CVE-2007-3903, and a variant of "Uninitialized Memory Corruption Vulnerability."

    Published: 12 Dec 2007
    10
    Critical

    CVE-2007-5351

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Server Message Block Version 2 (SMBv2) signing support in Microsoft Windows Vista allows remote attackers to force signature re-computation and execute arbitrary code via a crafted SMBv2 packet, aka "SMBv2 Signing Vulnerability."

    Published: 12 Dec 2007
    4
    Medium

    CVE-2007-6315

    Last Modified: 23 Apr 2026

    Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer dereference.

    Published: 12 Dec 2007
    4.3
    Medium

    CVE-2007-6316

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page.

    Published: 12 Dec 2007
    9.3
    Critical

    CVE-2007-3902

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code by calling the setExpression method and then modifying the outerHTML property of an HTML element, one variant of "Uninitialized Memory Corruption Vulnerability."

    Published: 12 Dec 2007
    6.8
    Medium

    CVE-2007-3903

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344, a variant of "Uninitialized Memory Corruption Vulnerability."

    Published: 12 Dec 2007
    5
    Medium

    CVE-2007-6314

    Last Modified: 23 Apr 2026

    BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in the URL.

    Published: 12 Dec 2007
    2.1
    Low

    CVE-2007-6389

    Last Modified: 23 Apr 2026

    The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard contents and X selection data for a locked session by using ctrl-V.

    Published: 12 Dec 2007
    9.3
    Critical

    CVE-2007-0064

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.

    Published: 12 Dec 2007
    9
    Critical

    CVE-2007-3039

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.

    Published: 12 Dec 2007
    6.8
    Medium

    CVE-2007-5347

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."

    Published: 12 Dec 2007
    7.2
    High

    CVE-2007-5350

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Windows Advanced Local Procedure Call (ALPC) in the kernel in Microsoft Windows Vista allows local users to gain privileges via unspecified vectors involving "legacy reply paths."

    Published: 12 Dec 2007
    4.3
    Medium

    CVE-2007-6307

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject arbitrary web script or HTML via (1) the link parameter or (2) the User-Agent HTTP header.

    Published: 11 Dec 2007
    4.3
    Medium

    CVE-2007-6312

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 allows remote attackers to inject arbitrary web script or HTML via the username field.

    Published: 11 Dec 2007