CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-6311

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows remote attackers to execute arbitrary SQL commands via the nav_ID parameter.

    Published: 11 Dec 2007
    4.3
    Medium

    CVE-2007-6310

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbitrary web script or HTML via the handler parameter to (1) index.php and possibly (2) admin/index.php, and (3) the topic parameter to modules/feed/feed.php (aka modules/feed.php).

    Published: 11 Dec 2007
    4.3
    Medium

    CVE-2007-6309

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the galleryID parameter in a usergallery upload action; or the (2) upID, (3) tag, (4) month, (5) userID, or (6) year parameter in a calendar announce action.

    Published: 11 Dec 2007
    4.3
    Medium

    CVE-2007-6308

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HttpLogger 0.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Dec 2007
    4.3
    Medium

    CVE-2007-6205

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a link in an RSS feed.

    Published: 11 Dec 2007
    4.3
    Medium

    CVE-2007-5000

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Dec 2007
    4.6
    Medium

    CVE-2007-6305

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attackers to gain privileges via "some HMC commands."

    Published: 10 Dec 2007
    6.8
    Medium

    CVE-2007-6302

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote attackers to execute arbitrary code via unspecified ASCII integers used as memory allocation arguments, aka "ZDI-CAN-162."

    Published: 10 Dec 2007
    7.5
    High

    CVE-2007-6288

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TCExam before 5.1.000 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 10 Dec 2007
    4.3
    Medium

    CVE-2007-6297

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML via the (1) LIMIT parameter to chat/deluser.php3, the (2) Link parameter to chat/edituser.php3, or the (3) LastCheck or (4) B parameter to chat/users_popupL.php3. NOTE: the FontName vectors for start_page.css.php3 and style.css.php3 are already covered by CVE-2005-1619. The medium vectors for start_page.css.php3 (start_page.css.php) and style.css.php3 (style.css.php), and the From vector for users_popupL.php3 (users_popupL.php), are already covered by CVE-2005-3991.

    Published: 10 Dec 2007
    7.5
    High

    CVE-2007-6299

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Drupal and vbDrupal 4.7.x before 4.7.9 and 5.x before 5.4 allow remote attackers to execute arbitrary SQL commands via modules that pass input to the taxonomy_select_nodes function, as demonstrated by the (1) taxonomy_menu, (2) ajaxLoader, and (3) ubrowser contributed modules.

    Published: 10 Dec 2007
    5
    Medium

    CVE-2007-6290

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod and (2) js parameters.

    Published: 10 Dec 2007
    6.8
    Medium

    CVE-2007-6289

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SERWEB[configdir] parameter to load_lang.php, (2) _SERWEB[functionsdir] parameter to main_prepend.php, and the (3) _PHPLIB[libdir] parameter to load_phplib.php, different vectors than CVE-2007-3359 and CVE-2007-3358.

    Published: 10 Dec 2007
    4.3
    Medium

    CVE-2007-6298

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.

    Published: 10 Dec 2007
    4.3
    Medium

    CVE-2007-6301

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

    Published: 10 Dec 2007
    7.5
    High

    CVE-2007-6291

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in abm.aspx in Xigla Absolute Banner Manager .NET 4.0 allows remote attackers to execute arbitrary SQL commands via the z parameter.

    Published: 10 Dec 2007
    7.5
    High

    CVE-2007-6292

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in leggi_commenti.asp in MWOpen 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 10 Dec 2007
    10
    Critical

    CVE-2007-6293

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands."

    Published: 10 Dec 2007
    4.9
    Medium

    CVE-2007-6294

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 3 R3.7 allow attackers to gain privileges via "some HMC commands."

    Published: 10 Dec 2007
    4.3
    Medium

    CVE-2007-6295

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the WebRunMenuFrame page in the online meeting center template in IBM Lotus Sametime before 8.0 allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 10 Dec 2007
    5
    Medium

    CVE-2007-6296

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in users_popupL.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the From parameter.

    Published: 10 Dec 2007
    5
    Medium

    CVE-2007-6300

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Fusion News 3.9.0 allows remote attackers to perform unauthorized actions via unspecified vectors.

    Published: 10 Dec 2007
    4.3
    Medium

    CVE-2007-6287

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login page in Lxlabs HyperVM 2.0 allows remote attackers to inject arbitrary web script or HTML via the frm_emessage parameter, a different vector than CVE-2006-6649. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Dec 2007
    9.3
    Critical

    CVE-2007-6015

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.

    Published: 10 Dec 2007
    7.2
    High

    CVE-2007-6328

    Last Modified: 23 Apr 2026

    DOSBox 0.72 and earlier allows local users to obtain access to the filesystem on the host operating system via the mount command. NOTE: the researcher reports a vendor response stating that this is not a security problem

    Published: 10 Dec 2007
    6.8
    Medium

    CVE-2007-6318

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the s parameter, when DB_CHARSET is set to (1) Big5, (2) GBK, or possibly other character set encodings that support a "\" in a multibyte character.

    Published: 10 Dec 2007
    4.3
    Medium

    CVE-2007-6321

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in RoundCube webmail 0.1rc2, 2007-12-09, and earlier versions, when using Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via style sheets containing expression commands.

    Published: 9 Dec 2007
    7.5
    High

    CVE-2007-6272

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Joomla! 1.5 RC3 allow remote attackers to execute arbitrary SQL commands via (1) the view parameter to the com_content component, (2) the task parameter to the com_search component, or (3) the option parameter in a search action to the com_search component.

    Published: 7 Dec 2007
    4.3
    Medium

    CVE-2007-6274

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) day or (2) year parameter.

    Published: 7 Dec 2007
    9.3
    Critical

    CVE-2007-6273

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in the (1) Hostname tag or the (2) name attribute in the Connection tag. NOTE: there might not be any realistic circumstances in which this issue crosses privilege boundaries.

    Published: 7 Dec 2007
    7.5
    High

    CVE-2007-6266

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter to modules/arcade/index.php in a show_stats action, or the lid parameter to (2) modules/myalbum/ratephoto.php or (3) modules/mylinks/ratelink.php, different vectors than CVE-2007-5104.

    Published: 7 Dec 2007
    7.8
    High

    CVE-2007-6276

    Last Modified: 23 Apr 2026

    The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112.

    Published: 7 Dec 2007
    7.5
    High

    CVE-2007-6275

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the lid parameter, a different vector than CVE-2007-6266.

    Published: 7 Dec 2007
    6.8
    Medium

    CVE-2007-6265

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in avast! 4 Home and Professional Editions before 4.7.1098 allows remote attackers to have an unknown impact via a crafted TAR archive.

    Published: 7 Dec 2007
    5
    Medium

    CVE-2007-6271

    Last Modified: 23 Apr 2026

    Absolute News Manager.NET 5.1 allows remote attackers to obtain sensitive information via a direct request to getpath.aspx, which reveals the installation path in an error message.

    Published: 7 Dec 2007
    4.3
    Medium

    CVE-2007-6270

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx.

    Published: 7 Dec 2007
    7.5
    High

    CVE-2007-6269

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.

    Published: 7 Dec 2007
    5
    Medium

    CVE-2007-6268

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Published: 7 Dec 2007
    2.1
    Low

    CVE-2007-6267

    Last Modified: 23 Apr 2026

    Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.

    Published: 7 Dec 2007
    7.2
    High

    CVE-2007-5966

    Last Modified: 23 Apr 2026

    Integer overflow in the hrtimer_start function in kernel/hrtimer.c in the Linux kernel before 2.6.23.10 allows local users to execute arbitrary code or cause a denial of service (panic) via a large relative timeout value. NOTE: some of these details are obtained from third party information.

    Published: 7 Dec 2007
    10
    Critical

    CVE-2007-6109

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.

    Published: 7 Dec 2007
    9.3
    Critical

    CVE-2007-6263

    Last Modified: 23 Apr 2026

    The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769.

    Published: 6 Dec 2007
    10
    Critical

    CVE-2007-5939

    Last Modified: 23 Apr 2026

    The gss_userok function in appl/ftp/ftpd/gss_userok.c in Heimdal 0.7.2 does not allocate memory for the ticketfile pointer before calling free, which allows remote attackers to have an unknown impact via an invalid username. NOTE: the vulnerability was originally reported for ftpd.c, but this is incorrect.

    Published: 6 Dec 2007
    4.9
    Medium

    CVE-2007-6261

    Last Modified: 23 Apr 2026

    Integer overflow in the load_threadstack function in the Mach-O loader (mach_loader.c) in the xnu kernel in Apple Mac OS X 10.4 through 10.5.1 allows local users to cause a denial of service (infinite loop) via a crafted Mach-O binary.

    Published: 6 Dec 2007
    6.8
    Medium

    CVE-2007-6260

    Last Modified: 23 Apr 2026

    The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to obtain login access by connecting to the Listener. NOTE: at the end of the installation, if performed using the Database Configuration Assistant (DBCA), most accounts are disabled or their passwords are changed.

    Published: 6 Dec 2007
    10
    Critical

    CVE-2007-6194

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Select Identity 4.01 before 4.01.012 and 4.1x before 4.13.003 allows remote attackers to obtain unspecified access via unknown vectors.

    Published: 6 Dec 2007
    6.8
    Medium

    CVE-2007-6262

    Last Modified: 23 Apr 2026

    A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary code via crafted arguments to the (1) addTarget, (2) getVariable, or (3) setVariable function, resulting from a "bad initialized pointer," aka a "recursive plugin release vulnerability."

    Published: 6 Dec 2007
    4.3
    Medium

    CVE-2007-6306

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area.

    Published: 6 Dec 2007
    10
    Critical

    CVE-2008-2928

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted Accept-Language HTTP header.

    Published: 6 Dec 2007
    5.8
    Medium

    CVE-2007-5355

    Last Modified: 23 Apr 2026

    The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three or more components is configured, resolves an unqualified wpad hostname in a second-level domain outside this configured DNS domain, which allows remote WPAD servers to conduct man-in-the-middle (MITM) attacks.

    Published: 5 Dec 2007