CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-6115

    Last Modified: 23 Apr 2026

    Buffer overflow in the ANSI MAP dissector for Wireshark (formerly Ethereal) 0.99.5 to 0.99.6, when running on unspecified platforms, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unknown vectors.

    Published: 22 Nov 2007
    5
    Medium

    CVE-2007-6116

    Last Modified: 23 Apr 2026

    The Firebird/Interbase dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite loop or crash) via unknown vectors.

    Published: 22 Nov 2007
    10
    Critical

    CVE-2007-6112

    Last Modified: 23 Apr 2026

    Buffer overflow in the PPP dissector Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

    Published: 22 Nov 2007
    5
    Medium

    CVE-2007-6120

    Last Modified: 23 Apr 2026

    The Bluetooth SDP dissector Wireshark (formerly Ethereal) 0.99.2 to 0.99.6 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.

    Published: 22 Nov 2007
    5
    Medium

    CVE-2007-6121

    Last Modified: 23 Apr 2026

    Wireshark (formerly Ethereal) 0.8.16 to 0.99.6 allows remote attackers to cause a denial of service (crash) via a malformed RPC Portmap packet.

    Published: 22 Nov 2007
    7.8
    High

    CVE-2007-6119

    Last Modified: 23 Apr 2026

    The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.

    Published: 22 Nov 2007
    2.1
    Low

    CVE-2007-6207

    Last Modified: 23 Apr 2026

    Xen 3.x, possibly before 3.1.2, when running on IA64 systems, does not check the RID value for mov_to_rr, which allows a VTi domain to read memory of other domains.

    Published: 22 Nov 2007
    9.3
    Critical

    CVE-2007-6089

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

    Published: 22 Nov 2007
    4.3
    Medium

    CVE-2007-6090

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Nuked-Klan 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Nov 2007
    4
    Medium

    CVE-2007-6095

    Last Modified: 23 Apr 2026

    The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT Traversal is employed, does not properly perform user registration and message distribution, which might allow remote authenticated users to receive messages intended for other users.

    Published: 22 Nov 2007
    7.1
    High

    CVE-2007-6111

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) allow remote attackers to cause a denial of service (crash) via (1) a crafted MP3 file or (2) unspecified vectors to the NCP dissector.

    Published: 22 Nov 2007
    4.3
    Medium

    CVE-2007-6113

    Last Modified: 23 Apr 2026

    Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.

    Published: 22 Nov 2007
    7.8
    High

    CVE-2007-6118

    Last Modified: 23 Apr 2026

    The MEGACO dissector in Wireshark (formerly Ethereal) 0.9.14 to 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.

    Published: 22 Nov 2007
    10
    Critical

    CVE-2008-5317

    Last Modified: 23 Apr 2026

    Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

    Published: 22 Nov 2007
    7.5
    High

    CVE-2007-6091

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field.

    Published: 22 Nov 2007
    10
    Critical

    CVE-2007-6097

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ICMP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and remote attack vectors, related to ICMP packets that are "incorrectly accepted."

    Published: 22 Nov 2007
    9.3
    Critical

    CVE-2007-6088

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 22 Nov 2007
    5
    Medium

    CVE-2007-6096

    Last Modified: 23 Apr 2026

    Ingate Firewall before 4.6.0 and SIParator before 4.6.0 use cleartext storage for passwords of "administrators with less privileges," which might allow attackers to read these passwords via unknown vectors.

    Published: 22 Nov 2007
    10
    Critical

    CVE-2007-6114

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Wireshark (formerly Ethereal) 0.99.0 through 0.99.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) the SSL dissector or (2) the iSeries (OS/400) Communication trace file parser.

    Published: 22 Nov 2007
    5
    Medium

    CVE-2007-6117

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HTTP dissector for Wireshark (formerly Ethereal) 0.10.14 to 0.99.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted chunked messages.

    Published: 22 Nov 2007
    7.5
    High

    CVE-2007-6081

    Last Modified: 23 Apr 2026

    AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs. Fixed in EventLog Analyzer Build 6000.

    Published: 21 Nov 2007
    7.5
    High

    CVE-2007-6078

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SkyPortal RC6 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) nc_top.asp; (2) inc_bookmarks.asp, possibly involving a parameter passed from cp_main.asp; (3) inc_profile_functions.asp; or (4) inc_SUBSCRIPTIONS.asp; or the (5) Avatar_URL, (6) LINK1, or (7) LINK2 parameter to cp_main.asp in an EditIt action.

    Published: 21 Nov 2007
    7.5
    High

    CVE-2007-6080

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the bid parameter. NOTE: it was later reported that 1.0.13 is also affected.

    Published: 21 Nov 2007
    7.8
    High

    CVE-2007-5612

    Last Modified: 23 Apr 2026

    CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and daemon crash) via a large number of idle connections.

    Published: 21 Nov 2007
    6.8
    Medium

    CVE-2007-6079

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file.

    Published: 21 Nov 2007
    Unknown

    CVE-2007-5499

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 21 Nov 2007
    6.8
    Medium

    CVE-2007-6077

    Last Modified: 23 Apr 2026

    The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEFAULT_SESSION_OPTIONS constant, which effectively causes cookie_only to be applied only to the first instantiation of CgiRequest, which allows remote attackers to conduct session fixation attacks. NOTE: this is due to an incomplete fix for CVE-2007-5380.

    Published: 21 Nov 2007
    5
    Medium

    CVE-2007-6062

    Last Modified: 23 Apr 2026

    irc-channel.c in ngIRCd before 0.10.3 allows remote attackers to cause a denial of service (crash) via a JOIN command without a channel argument.

    Published: 20 Nov 2007
    10
    Critical

    CVE-2007-6044

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of 20071116, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 20 Nov 2007
    7.2
    High

    CVE-2007-6049

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to dlopen when the effective uid is root.

    Published: 20 Nov 2007
    7.2
    High

    CVE-2007-6050

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure directory."

    Published: 20 Nov 2007
    10
    Critical

    CVE-2007-6051

    Last Modified: 23 Apr 2026

    IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

    Published: 20 Nov 2007
    5
    Medium

    CVE-2007-6056

    Last Modified: 23 Apr 2026

    frame.html in Aida-Web (Aida Web) allows remote attackers to bypass a protection mechanism and obtain comment and task details via modified values to the (1) Mehr and (2) SUPER parameters.

    Published: 20 Nov 2007
    6.8
    Medium

    CVE-2007-6057

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.

    Published: 20 Nov 2007
    7.5
    High

    CVE-2007-6058

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module.

    Published: 20 Nov 2007
    9.3
    Critical

    CVE-2007-6060

    Last Modified: 23 Apr 2026

    AhnLab Antivirus 3 Internet Security 2008 Platinum appends data to a filename string at a location indicated by the "Filename length" field in a ZIP header, which allows remote attackers to cause a denial of service (machine crash) and possibly execute arbitrary code via a ZIP file in which this field's value is larger than the actual number of bytes in the filename.

    Published: 20 Nov 2007
    7.2
    High

    CVE-2007-6046

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in unspecified setuid programs in IBM DB2 UDB 9.1 before Fixpak 4 allows local users to have an unknown impact.

    Published: 20 Nov 2007
    10
    Critical

    CVE-2007-6047

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.

    Published: 20 Nov 2007
    10
    Critical

    CVE-2007-6048

    Last Modified: 23 Apr 2026

    IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

    Published: 20 Nov 2007
    7.8
    High

    CVE-2007-6052

    Last Modified: 23 Apr 2026

    IBM DB2 UDB 9.1 before Fixpak 4 does not properly perform vector aggregation, which might allow attackers to cause a denial of service (divide-by-zero error and DBMS crash), related to an "overflow." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

    Published: 20 Nov 2007
    4.3
    Medium

    CVE-2007-6054

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the /screens URI, related to the url variable.

    Published: 20 Nov 2007
    4.3
    Medium

    CVE-2007-6055

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in c/portal/login in Liferay Portal 4.1.0 and 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter. NOTE: this issue reportedly exists because of a regression that followed a fix at an unspecified earlier date.

    Published: 20 Nov 2007
    10
    Critical

    CVE-2007-6045

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.

    Published: 20 Nov 2007
    9.3
    Critical

    CVE-2007-6053

    Last Modified: 23 Apr 2026

    IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown impact involving "memory corruption." NOTE: the vendor description of this issue is too vague to be certain that it is security-related.

    Published: 20 Nov 2007
    8.5
    High

    CVE-2007-5361

    Last Modified: 23 Apr 2026

    The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.

    Published: 20 Nov 2007
    6.8
    Medium

    CVE-2007-6042

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fehler.inc.php in SWSoft Confixx Professional 3.2.1 allows remote attackers to execute arbitrary PHP code via a URL in an unspecified parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Nov 2007
    2.1
    Low

    CVE-2007-6039

    Last Modified: 23 Apr 2026

    PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in (1) the domain parameter to the dgettext function, the message parameter to the (2) dcgettext or (3) gettext function, the msgid1 parameter to the (4) dngettext or (5) ngettext function, or (6) the classname parameter to the stream_wrapper_register function. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

    Published: 20 Nov 2007
    5
    Medium

    CVE-2007-6040

    Last Modified: 23 Apr 2026

    The Belkin F5D7230-4 Wireless G Router allows remote attackers to cause a denial of service (degraded networking and logging) via a flood of TCP SYN packets, a related issue to CVE-1999-0116.

    Published: 20 Nov 2007
    7.5
    High

    CVE-2007-6041

    Last Modified: 23 Apr 2026

    Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code by sending a nickname, then a vehicle name in a MSG2_USE_VEHICLE message, in which the combined length triggers the overflow.

    Published: 20 Nov 2007
    7.1
    High

    CVE-2007-6043

    Last Modified: 23 Apr 2026

    The CryptGenRandom function in Microsoft Windows 2000 generates predictable values, which makes it easier for context-dependent attackers to reduce the effectiveness of cryptographic mechanisms, as demonstrated by attacks on (1) forward security and (2) backward security, related to use of eight instances of the RC4 cipher, and possibly a related issue to CVE-2007-3898.

    Published: 20 Nov 2007