CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-5613

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies.

    Published: 5 Dec 2007
    5
    Medium

    CVE-2007-5615

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 5 Dec 2007
    7.5
    High

    CVE-2007-6014

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t_dedupe parameter.

    Published: 5 Dec 2007
    7.5
    High

    CVE-2007-6240

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter.

    Published: 5 Dec 2007
    7.5
    High

    CVE-2007-6241

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Beehive Forum 0.7.1 have unknown "critical" impact and attack vectors, different issues than CVE-2007-6014.

    Published: 5 Dec 2007
    7.5
    High

    CVE-2007-5614

    Last Modified: 23 Apr 2026

    Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

    Published: 5 Dec 2007
    9.3
    Critical

    CVE-2007-6243

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks.

    Published: 5 Dec 2007
    5.8
    Medium

    CVE-2007-5497

    Last Modified: 23 Apr 2026

    Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image.

    Published: 5 Dec 2007
    7.5
    High

    CVE-2007-6231

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the tm_includepath parameter to (1) Classes.inc.php, (2) statistic.inc.php, (3) status.inc.php, (4) status_top_x.inc.php, or (5) libchart-1.1/libchart.php in include/. NOTE: access to include/ is blocked by .htaccess in most deployments that use Apache HTTP Server.

    Published: 4 Dec 2007
    9
    Critical

    CVE-2007-6237

    Last Modified: 23 Apr 2026

    cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows remote authenticated users to change the e-mail addresses of arbitrary accounts via a modified membercookie parameter, a different vector than CVE-2006-4078. NOTE: this can be leveraged for administrative access by requesting password-reset e-mail through a lostpw action to misc.php.

    Published: 4 Dec 2007
    7.1
    High

    CVE-2007-6226

    Last Modified: 23 Apr 2026

    The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the other client exits.

    Published: 4 Dec 2007
    4.9
    Medium

    CVE-2007-6225

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Solaris 10, when 64bit mode is used on the x86 platform, allows local users in a Linux (lx) branded zone to cause a denial of service (panic) via unspecified vectors.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6224

    Last Modified: 23 Apr 2026

    The RealNetworks RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll, as shipped with RealPlayer 11, allows remote attackers to cause a denial of service (browser crash) via a certain argument to the GetSourceTransport method.

    Published: 4 Dec 2007
    7.2
    High

    CVE-2007-6227

    Last Modified: 23 Apr 2026

    QEMU 0.9.0 allows local users of a Windows XP SP2 guest operating system to overwrite the TranslationBlock (code_gen_buffer) buffer, and probably have unspecified other impacts related to an "overflow," via certain Windows executable programs, as demonstrated by qemu-dos.com.

    Published: 4 Dec 2007
    6.8
    Medium

    CVE-2007-6228

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to cause a denial of service (browser crash) via a long argument to the c method.

    Published: 4 Dec 2007
    7.5
    High

    CVE-2007-6229

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the CFG[site][project_path] parameter.

    Published: 4 Dec 2007
    7.5
    High

    CVE-2007-6230

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the CFG[site][project_path] parameter.

    Published: 4 Dec 2007
    10
    Critical

    CVE-2007-6234

    Last Modified: 23 Apr 2026

    index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.

    Published: 4 Dec 2007
    4.9
    Medium

    CVE-2007-6233

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 4 Dec 2007
    4.3
    Medium

    CVE-2007-6232

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6235

    Last Modified: 23 Apr 2026

    A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. NOTE: this might be related to CVE-2007-4904.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6236

    Last Modified: 23 Apr 2026

    Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff.

    Published: 4 Dec 2007
    10
    Critical

    CVE-2007-6238

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release advisories with actionable information. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine. However, the organization has stated that this is different than CVE-2007-6166.

    Published: 4 Dec 2007
    4.3
    Medium

    CVE-2007-6219

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Tivoli Netcool Security Manager 1.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6220

    Last Modified: 23 Apr 2026

    typespeed before 0.6.4 allows remote attackers to cause a denial of service (application crash) via unspecified network behavior that triggers a divide-by-zero error.

    Published: 4 Dec 2007
    7.8
    High

    CVE-2007-6221

    Last Modified: 23 Apr 2026

    TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Dec 2007
    6.5
    Medium

    CVE-2007-6222

    Last Modified: 23 Apr 2026

    The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, which allows remote authenticated users with the LIMITTOCUSTOMERS privilege to bypass intended access restrictions and edit non-active user settings. NOTE: some of these details are obtained from third party information.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6218

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) level parameter to (a) install_module.php and (b) uninstall_module.php in upload/xax/admin/modules/, (c) upload/xax/admin/patch/index.php, and (d) install_module.php and (e) uninstall_module.php in upload/xax/ossigeno/admin/; and the (2) ossigeno parameter to (f) ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php, different vectors than CVE-2007-5234.

    Published: 4 Dec 2007
    7.5
    High

    CVE-2007-6223

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL commands via the make_id parameter in a search action in browse mode.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6212

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the layer parameter.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6213

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) Root and (2) Path parameters.

    Published: 4 Dec 2007
    4.3
    Medium

    CVE-2007-6214

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read arbitrary files via a .. (dot dot) in the sFilePath parameter. NOTE: exploitation requires that the product is configured, but has zero files in the database.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6215

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) roomNo and possibly the (2) bookid parameter.

    Published: 4 Dec 2007
    7.5
    High

    CVE-2007-6217

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execute arbitrary SQL commands via the (1) login (aka Username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Published: 4 Dec 2007
    4.7
    Medium

    CVE-2007-6216

    Last Modified: 23 Apr 2026

    Race condition in the Fibre Channel protocol (fcp) driver and Devices filesystem (devfs) in Sun Solaris 10 allows local users to cause a denial of service (system hang) via some programs that access hardware resources, as demonstrated by the (1) cfgadm and (2) format programs.

    Published: 4 Dec 2007
    2.1
    Low

    CVE-2007-6210

    Last Modified: 23 Apr 2026

    zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.

    Published: 4 Dec 2007
    7.2
    High

    CVE-2007-6211

    Last Modified: 23 Apr 2026

    Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users to append to arbitrary files and gain privileges via the -L (output log file) option. NOTE: this issue is only a vulnerability in limited environments, since sing is not installed setuid, and the administrator would need to override a non-setuid default during installation.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2008-1927

    Last Modified: 23 Apr 2026

    Double free vulnerability in Perl 5.8.8 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a crafted regular expression containing UTF8 characters. NOTE: this issue might only be present on certain operating systems.

    Published: 4 Dec 2007
    9.3
    Critical

    CVE-2007-4575

    Last Modified: 23 Apr 2026

    HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."

    Published: 4 Dec 2007
    3.6
    Low

    CVE-2007-6208

    Last Modified: 23 Apr 2026

    sylprint.pl in claws mail tools (claws-mail-tools) allows local users to overwrite arbitrary files via a symlink attack on the sylprint.[USER].[PID] temporary file.

    Published: 4 Dec 2007
    5
    Medium

    CVE-2007-6239

    Last Modified: 23 Apr 2026

    The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.

    Published: 4 Dec 2007
    2.1
    Low

    CVE-2007-6434

    Last Modified: 23 Apr 2026

    Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function.

    Published: 4 Dec 2007
    4.6
    Medium

    CVE-2007-6209

    Last Modified: 23 Apr 2026

    Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 2 Dec 2007
    7.5
    High

    CVE-2007-6201

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via a "faulty add-on" and possibly execute other commands via unknown vectors related to the turn_cmd option.

    Published: 1 Dec 2007
    6.8
    Medium

    CVE-2007-6202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php.

    Published: 1 Dec 2007
    5
    Medium

    CVE-2007-6197

    Last Modified: 23 Apr 2026

    The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page.

    Published: 1 Dec 2007
    5
    Medium

    CVE-2007-6198

    Last Modified: 23 Apr 2026

    portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter.

    Published: 1 Dec 2007
    4.3
    Medium

    CVE-2007-6196

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter.

    Published: 1 Dec 2007
    7.2
    High

    CVE-2007-6151

    Last Modified: 23 Apr 2026

    The isdn_ioctl function in isdn_common.c in Linux kernel 2.6.23 allows local users to cause a denial of service via a crafted ioctl struct in which iocts is not null terminated, which triggers a buffer overflow.

    Published: 1 Dec 2007
    6.8
    Medium

    CVE-2007-6191

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Armin Burger p.mapper 3.2.0 beta3 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[PM_INCPHP] parameter to (1) incphp/globals.php or (2) plugins/export/mc_table.php. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in p.mapper.

    Published: 30 Nov 2007