CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2006-7230

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate the amount of memory needed for a compiled regular expression pattern when the (1) -x or (2) -i UTF-8 options change within the pattern, which allows context-dependent attackers to cause a denial of service (PCRE or glibc crash) via crafted regular expressions.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-4572

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-5398

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-4699

    Last Modified: 23 Apr 2026

    The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other applications to access the key without warning the user, which might allow other applications to bypass intended access restrictions.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-4700

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors.

    Published: 15 Nov 2007
    2.1
    Low

    CVE-2007-4701

    Last Modified: 23 Apr 2026

    WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file.

    Published: 15 Nov 2007
    7.2
    High

    CVE-2007-4267

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted IOCTL request that adds an AppleTalk zone to a routing table.

    Published: 15 Nov 2007
    7.2
    High

    CVE-2007-4269

    Last Modified: 23 Apr 2026

    Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow.

    Published: 15 Nov 2007
    7.1
    High

    CVE-2007-4678

    Last Modified: 23 Apr 2026

    AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-4682

    Last Modified: 23 Apr 2026

    CoreText in Apple Mac OS X 10.4 through 10.4.10 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted text content that triggers an access of an uninitialized object pointer.

    Published: 15 Nov 2007
    4.6
    Medium

    CVE-2007-4683

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to bypass the chroot mechanism via a relative path when changing the current working directory.

    Published: 15 Nov 2007
    6.9
    Medium

    CVE-2007-4684

    Last Modified: 23 Apr 2026

    Integer overflow in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a large num_sels argument to the i386_set_ldt system call.

    Published: 15 Nov 2007
    7.2
    High

    CVE-2007-4685

    Last Modified: 23 Apr 2026

    The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are "in an unexpected state."

    Published: 15 Nov 2007
    7.2
    High

    CVE-2007-4686

    Last Modified: 23 Apr 2026

    Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-4687

    Last Modified: 23 Apr 2026

    The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.

    Published: 15 Nov 2007
    10
    Critical

    CVE-2007-4691

    Last Modified: 23 Apr 2026

    The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs.

    Published: 15 Nov 2007
    7.2
    High

    CVE-2007-4693

    Last Modified: 23 Apr 2026

    The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields."

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-4694

    Last Modified: 23 Apr 2026

    Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs.

    Published: 15 Nov 2007
    10
    Critical

    CVE-2007-4689

    Last Modified: 23 Apr 2026

    Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets.

    Published: 15 Nov 2007
    7.8
    High

    CVE-2007-4268

    Last Modified: 23 Apr 2026

    Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk message with a negative value, which satisfies a signed comparison during mbuf allocation but is later interpreted as an unsigned value, which triggers a heap-based buffer overflow.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-4680

    Last Modified: 23 Apr 2026

    CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted SSL certificates via a man-in-the-middle attack.

    Published: 15 Nov 2007
    6.9
    Medium

    CVE-2007-4681

    Last Modified: 23 Apr 2026

    Buffer overflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted directory hierarchy.

    Published: 15 Nov 2007
    5
    Medium

    CVE-2007-4688

    Last Modified: 23 Apr 2026

    The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addresses, via a Node Information Query.

    Published: 15 Nov 2007
    9
    Critical

    CVE-2007-4690

    Last Modified: 23 Apr 2026

    Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote authenticated users to execute arbitrary code via a crafted AUTH_UNIX RPC packet.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-4695

    Last Modified: 23 Apr 2026

    Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to file uploads.

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-4697

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption.

    Published: 15 Nov 2007
    7.8
    High

    CVE-2007-3749

    Last Modified: 23 Apr 2026

    The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid program, which allows local users to execute arbitrary code by creating the port before launching the setuid program, then writing to the address space of the setuid process.

    Published: 15 Nov 2007
    2.6
    Low

    CVE-2007-4679

    Last Modified: 23 Apr 2026

    CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-4696

    Last Modified: 23 Apr 2026

    Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5986

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in include/functions.php in BtiTracker before 1.4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-5985

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BtiTracker before 1.4.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) account.php, (2) moresmiles.php, or (3) recover.php; or (4) the "to" parameter to usercp.php.

    Published: 15 Nov 2007
    3.3
    Low

    CVE-2007-5981

    Last Modified: 23 Apr 2026

    Lantronix SCS3200 does not properly handle public-key requests, which allows remote attackers to cause a denial of service (unresponsive device) via unspecified keyscan requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Nov 2007
    7.1
    High

    CVE-2007-5969

    Last Modified: 23 Apr 2026

    MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and gain privileges via a RENAME TABLE statement that changes the symlink to point to an existing file.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-6279

    Last Modified: 23 Apr 2026

    Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seektable values or (2) Seektable Data Offsets in a .FLAC file.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-6278

    Last Modified: 23 Apr 2026

    Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-6029

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5988

    Last Modified: 23 Apr 2026

    blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary users via a modified nick field.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-5982

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) room parameter to sources/frame.php, the (2) theme_c parameter to help/index.php, or the (3) INSTALL_X7CHATVERSION parameter to upgradev1.php.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-5979

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary web script or HTML via the backurl parameter.

    Published: 15 Nov 2007
    5.8
    Medium

    CVE-2007-5970

    Last Modified: 23 Apr 2026

    MySQL 5.1.x before 5.1.23 and 6.0.x before 6.0.4 allows remote authenticated users to gain privileges on arbitrary tables via unspecified vectors involving use of table-level DATA DIRECTORY and INDEX DIRECTORY options when creating a partitioned table with the same name as a table on which the user lacks privileges.

    Published: 15 Nov 2007
    10
    Critical

    CVE-2007-5769

    Last Modified: 23 Apr 2026

    Double free vulnerability in the getreply function in ftp.c in netkit ftp (netkit-ftp) 0.17 20040614 and later allows remote FTP servers to cause a denial of service (application crash) and possibly have unspecified other impact via some types of FTP protocol behavior. NOTE: the netkit-ftpd issue is covered by CVE-2007-6263.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-4698

    Last Modified: 23 Apr 2026

    Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to conduct cross-site scripting (XSS) attacks by causing JavaScript events to be associated with the wrong frame.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2006-7229

    Last Modified: 23 Apr 2026

    The skge driver 1.5 in Linux kernel 2.6.15 on Ubuntu does not properly use the spin_lock and spin_unlock functions, which allows remote attackers to cause a denial of service (machine crash) via a flood of network traffic.

    Published: 15 Nov 2007
    9.3
    Critical

    CVE-2007-6277

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via large (1) Metadata Block Size, (2) VORBIS Comment String Size, (3) Picture Metadata MIME-TYPE Size, (4) Picture Description Size, (5) Picture Data Length, (6) Padding Length, and (7) PICTURE Metadata width and height values in a .FLAC file, which result in a heap-based overflow; and large (8) VORBIS Comment String Size Length, (9) Picture MIME-Type, (10) Picture MIME-Type URL, and (11) Picture Description Length values in a .FLAC file, which result in a stack-based overflow. NOTE: some of these issues may overlap CVE-2007-4619.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5973

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5974

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.

    Published: 15 Nov 2007
    6.5
    Medium

    CVE-2007-5975

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in TBSource, as used in (1) TBDev and (2) TorrentStrike 0.4, allows remote authenticated users to execute arbitrary SQL commands via the choice parameter. NOTE: some of these details are obtained from third party information.

    Published: 15 Nov 2007
    6.5
    Medium

    CVE-2007-5976

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to execute arbitrary SQL commands via the db parameter.

    Published: 15 Nov 2007
    3.5
    Low

    CVE-2007-5977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

    Published: 15 Nov 2007
    7.5
    High

    CVE-2007-5978

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in brokenlink.php in the mylinks module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.

    Published: 15 Nov 2007