CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2007-5900

    Last Modified: 23 Apr 2026

    PHP before 5.2.5 allows local users to bypass protection mechanisms configured through php_admin_value or php_admin_flag in httpd.conf by using ini_set to modify arbitrary configuration variables, a different issue than CVE-2006-4625.

    Published: 20 Nov 2007
    7.1
    High

    CVE-2007-6036

    Last Modified: 23 Apr 2026

    The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash) via a short RTSP query, which causes a negative number to be used during memory allocation.

    Published: 20 Nov 2007
    Unknown

    CVE-2007-6034

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6062. Reason: This candidate is a duplicate of CVE-2007-6062. Notes: All CVE users should reference CVE-2007-6062 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Nov 2007
    6.8
    Medium

    CVE-2007-6038

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 20 Nov 2007
    4.3
    Medium

    CVE-2007-6037

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters.

    Published: 20 Nov 2007
    7.5
    High

    CVE-2007-6032

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in calendar/page.asp in Aleris Web Publishing Server 3.0 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

    Published: 20 Nov 2007
    8.8
    High

    CVE-2007-6033

    Last Modified: 23 Apr 2026

    Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.

    Published: 20 Nov 2007
    10
    Critical

    CVE-2007-6030

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Weird Solutions BOOTPTurbo 1.2 has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 20 Nov 2007
    7.8
    High

    CVE-2007-6031

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in VanDyke VShell 3.0.1 allows remote attackers to cause a denial of service via unspecified vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 20 Nov 2007
    Unknown

    CVE-2007-5670

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-5956. Reason: This candidate is a duplicate of CVE-2007-5956. Notes: All CVE users should reference CVE-2007-5956 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Nov 2007
    6.8
    Medium

    CVE-2007-6028

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values.

    Published: 20 Nov 2007
    6.8
    Medium

    CVE-2007-6027

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 20 Nov 2007
    9.3
    Critical

    CVE-2007-6026

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microsoft msjet40.dll 4.0.8618.0 (aka Microsoft Jet Engine), as used by Access 2003 in Microsoft Office 2003 SP3, allows user-assisted attackers to execute arbitrary code via a crafted MDB file database file containing a column structure with a modified column count. NOTE: this might be the same issue as CVE-2005-0944.

    Published: 20 Nov 2007
    5
    Medium

    CVE-2007-6061

    Last Modified: 23 Apr 2026

    Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

    Published: 20 Nov 2007
    5
    Medium

    CVE-2007-5938

    Last Modified: 23 Apr 2026

    The iwl_set_rate function in compatible/iwl3945-base.c in iwlwifi 1.1.21 and earlier dereferences an iwl_get_hw_mode return value without checking for NULL, which might allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors during module initialization.

    Published: 20 Nov 2007
    6.9
    Medium

    CVE-2007-6063

    Last Modified: 23 Apr 2026

    Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.

    Published: 20 Nov 2007
    9.8
    Critical

    CVE-2007-6013

    Last Modified: 23 Apr 2026

    Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

    Published: 19 Nov 2007
    4.3
    Medium

    CVE-2007-6591

    Last Modified: 23 Apr 2026

    KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the product, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

    Published: 18 Nov 2007
    7.5
    High

    CVE-2007-6035

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.

    Published: 17 Nov 2007
    7.5
    High

    CVE-2007-6012

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SearchR.asp in DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary SQL commands via the artnr parameter (aka the search section). NOTE: some of these details are obtained from third party information.

    Published: 16 Nov 2007
    4.9
    Medium

    CVE-2007-5500

    Last Modified: 23 Apr 2026

    The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 16 Nov 2007
    10
    Critical

    CVE-2007-6011

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain administrative access via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Nov 2007
    5
    Medium

    CVE-2007-6059

    Last Modified: 23 Apr 2026

    Javamail does not properly handle a series of invalid login attempts in which the same e-mail address is entered as username and password, and the domain portion of this address yields a Java UnknownHostException error, which allows remote attackers to cause a denial of service (connection pool exhaustion) via a large number of requests, resulting in a SQLNestedException. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products.

    Published: 16 Nov 2007
    7.8
    High

    CVE-2007-6010

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in pioneers (formerly gnocatan) 0.11.3 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors that trigger an assert error. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-5933.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-5990

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ExoPHPdesk allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a user profile, possibly the (1) name and (2) website parameters to register.php.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5991

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ExoPHPdesk allows remote attackers to execute arbitrary SQL commands via the user parameter in a profile fn action.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-5993

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Visionary Technology in Library Solutions (VTLS) vtls.web.gateway before 48.1.1 allows remote attackers to inject arbitrary web script or HTML via the searchtype parameter.

    Published: 15 Nov 2007
    6.5
    Medium

    CVE-2007-5997

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5999

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_desc.php in Softbiz Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 15 Nov 2007
    5
    Medium

    CVE-2007-6000

    Last Modified: 23 Apr 2026

    KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-6002

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Fenriru (1) Sleipnir 2.5.17 R2 and earlier and (2) Grani 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field in a search for additions to the Favorites section.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-6004

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an artikel action or (2) the katid parameter in a produk action.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-6005

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory access violation and crash) via (1) an invalid argument to the InitParam method or (2) an unspecified vector involving the SetParam method.

    Published: 15 Nov 2007
    10
    Critical

    CVE-2007-6006

    Last Modified: 23 Apr 2026

    TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-6007

    Last Modified: 23 Apr 2026

    Integer overflow in the ID_PSP.apl plug-in for ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted PSP image that triggers a heap-based buffer overflow.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-6008

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in emlsr.dll before 2.0.0.4 in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK allows remote attackers to execute arbitrary code via a long Content-Type header line in an EML file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5992

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewcat s action on the forums page.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-5995

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in examples/patExampleGen/bbcodeSource.php in patBBcode 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the example parameter.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-6009

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-4344

    Last Modified: 23 Apr 2026

    Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an LHA archive to the AM_LHA.apl plug-in, resulting in a heap-based buffer overflow.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5996

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter, a related issue to CVE-2007-5449.

    Published: 15 Nov 2007
    6.5
    Medium

    CVE-2007-5998

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-6001

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Bandersnatch 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) func or (2) date parameter, or the jid parameter in a (3) log or (4) user action, a different vulnerability than CVE-2007-3910.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-5994

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in check_noimage.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the config[path_src_include] parameter.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-6003

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Nov 2007
    10
    Critical

    CVE-2007-4703

    Last Modified: 23 Apr 2026

    The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions.

    Published: 15 Nov 2007
    10
    Critical

    CVE-2007-4704

    Last Modified: 23 Apr 2026

    The Application Firewall in Apple Mac OS X 10.5 does not apply changed settings to processes that are started by launchd until the processes are restarted, which might allow attackers to bypass intended access restrictions.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-4702

    Last Modified: 23 Apr 2026

    The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions.

    Published: 15 Nov 2007
    7.8
    High

    CVE-2007-5501

    Last Modified: 23 Apr 2026

    The tcp_sacktag_write_queue function in net/ipv4/tcp_input.c in Linux kernel 2.6.21 through 2.6.23.7, and 2.6.24-rc through 2.6.24-rc2, allows remote attackers to cause a denial of service (crash) via crafted ACK responses that trigger a NULL pointer dereference.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-5905

    Last Modified: 23 Apr 2026

    Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability.

    Published: 15 Nov 2007