CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-5983

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 15 Nov 2007
    7.8
    High

    CVE-2007-5984

    Last Modified: 23 Apr 2026

    classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive calculation."

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-4692

    Last Modified: 23 Apr 2026

    The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-5980

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 15 Nov 2007
    6.8
    Medium

    CVE-2007-5987

    Last Modified: 23 Apr 2026

    details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a direct request, as demonstrated by (1) reading the details of an arbitrary torrent and (2) modifying a torrent owned by a guest.

    Published: 15 Nov 2007
    4.3
    Medium

    CVE-2007-3694

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Miro Project Broadcast Machine 0.9.9.9 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 14 Nov 2007
    4.9
    Medium

    CVE-2007-5957

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 10.00.TC3TL and 11.10.TB4TL on Windows allows attackers to cause a denial of service (application crash) via unspecified SQ_ONASSIST requests.

    Published: 14 Nov 2007
    7.2
    High

    CVE-2007-5956

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable.

    Published: 14 Nov 2007
    4.3
    Medium

    CVE-2007-5955

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in updir.php in UPDIR.NET before 2.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Nov 2007
    4.3
    Medium

    CVE-2007-5948

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters.

    Published: 14 Nov 2007
    7.5
    High

    CVE-2007-5951

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Nov 2007
    6.1
    Medium

    CVE-2007-5954

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Nov 2007
    4.3
    Medium

    CVE-2007-5950

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in NetCommons before 1.0.11, and 1.1.x before 1.1.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-4165.

    Published: 14 Nov 2007
    4
    Medium

    CVE-2007-5942

    Last Modified: 23 Apr 2026

    Bandersnatch 0.4 allows remote attackers to obtain sensitive information via a malformed request for index.php with (1) a certain func parameter value; or (2) certain func, jid, page, and limit parameter values; which reveals the path in various error messages.

    Published: 14 Nov 2007
    7.2
    High

    CVE-2007-3880

    Last Modified: 23 Apr 2026

    Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.

    Published: 14 Nov 2007
    3.5
    Low

    CVE-2007-5949

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action.

    Published: 14 Nov 2007
    10
    Critical

    CVE-2007-5941

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method.

    Published: 14 Nov 2007
    6.4
    Medium

    CVE-2007-3898

    Last Modified: 23 Apr 2026

    The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.

    Published: 14 Nov 2007
    7.2
    High

    CVE-2007-5667

    Last Modified: 23 Apr 2026

    NWFILTER.SYS in Novell Client 4.91 SP 1 through SP 4 for Windows 2000, XP, and Server 2003 makes the \.\nwfilter device available for arbitrary user-mode input via METHOD_NEITHER IOCTLs, which allows local users to gain privileges by passing a kernel address as an argument and overwriting kernel memory locations.

    Published: 14 Nov 2007
    9.3
    Critical

    CVE-2007-5755

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary code via long arguments to unspecified methods.

    Published: 14 Nov 2007
    5
    Medium

    CVE-2007-5943

    Last Modified: 23 Apr 2026

    Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message.

    Published: 14 Nov 2007
    4.3
    Medium

    CVE-2007-5944

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure.

    Published: 14 Nov 2007
    5
    Medium

    CVE-2007-5945

    Last Modified: 23 Apr 2026

    USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors.

    Published: 14 Nov 2007
    7.2
    High

    CVE-2007-5946

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Aries PA-RISC emulator on HP-UX B.11.23 and B.11.31 on the IA-64 platform allows local users to obtain unspecified access.

    Published: 14 Nov 2007
    4.3
    Medium

    CVE-2007-5952

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/index.php in Helios Calendar 1.2.1 Beta allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Nov 2007
    5
    Medium

    CVE-2007-5953

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors.

    Published: 14 Nov 2007
    6.9
    Medium

    CVE-2007-5756

    Last Modified: 23 Apr 2026

    Multiple array index errors in the bpf_filter_init function in NPF.SYS in WinPcap before 4.0.2, when run in monitor mode (aka Table Management Extensions or TME), and as used in Wireshark and possibly other products, allow local users to gain privileges via crafted IOCTL requests.

    Published: 14 Nov 2007
    10
    Critical

    CVE-2007-5902

    Last Modified: 23 Apr 2026

    Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unknown impact via a large length value for a GSS client name in an RPC request.

    Published: 14 Nov 2007
    2.1
    Low

    CVE-2007-6131

    Last Modified: 23 Apr 2026

    buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.

    Published: 14 Nov 2007
    9
    Critical

    CVE-2007-5972

    Last Modified: 23 Apr 2026

    Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has unknown impact and remote authenticated attack vectors. NOTE: the free operations occur in code that stores the krb5kdc master key, and so the attacker must have privileges to store this key.

    Published: 14 Nov 2007
    6.9
    Medium

    CVE-2007-5971

    Last Modified: 23 Apr 2026

    Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.

    Published: 14 Nov 2007
    6.9
    Medium

    CVE-2007-5901

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors. NOTE: this might be the result of a typo in the source code.

    Published: 14 Nov 2007
    9.3
    Critical

    CVE-2007-5894

    Last Modified: 23 Apr 2026

    The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when auth_type has a certain value, which has unknown impact and remote authenticated attack vectors. NOTE: the original disclosure misidentifies the conditions under which the uninitialized variable is used. NOTE: the vendor disputes this issue, stating " The 'length' variable is only uninitialized if 'auth_type' is neither the 'KERBEROS_V4' nor 'GSSAPI'; this condition cannot occur in the unmodified source code.

    Published: 14 Nov 2007
    4.6
    Medium

    CVE-2007-5940

    Last Modified: 23 Apr 2026

    feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the feynmf$$.pl temporary file.

    Published: 13 Nov 2007
    4.3
    Medium

    CVE-2007-5934

    Last Modified: 23 Apr 2026

    The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents of the URL, which might allow remote attackers to use MDB2 as an indirect proxy or obtain sensitive information via a URL into a form field in an MDB2 application, as demonstrated by a file:// URL or a URL for an intranet web site.

    Published: 13 Nov 2007
    7.8
    High

    CVE-2007-5933

    Last Modified: 23 Apr 2026

    Pioneers (formerly gnocatan) before 0.11.3 allows remote attackers to cause a denial of service (crash) by triggering a delete operation while the Session object is still being used, as demonstrated by causing a "Broken pipe" error.

    Published: 13 Nov 2007
    4.3
    Medium

    CVE-2006-7225

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to cause a denial of service (error or crash) via a regular expression that involves a "malformed POSIX character class", as demonstrated via an invalid character after a [[ sequence.

    Published: 13 Nov 2007
    4.3
    Medium

    CVE-2006-7226

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows context-dependent attackers to cause a denial of service (error or crash).

    Published: 13 Nov 2007
    4.3
    Medium

    CVE-2007-5932

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Fatwire Content Server (CS) CMS 6.3.0 allow remote attackers to inject arbitrary web script or HTML via unspecified form fields related to the (1) search function, (2) advanced search function, and possibly other components.

    Published: 10 Nov 2007
    5
    Medium

    CVE-2007-5931

    Last Modified: 23 Apr 2026

    The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remote attackers to obtain access to data via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Nov 2007
    4.3
    Medium

    CVE-2007-5930

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Nov 2007
    6.8
    Medium

    CVE-2007-5915

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the whattodo parameter.

    Published: 10 Nov 2007
    6.8
    Medium

    CVE-2007-5911

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Media Player 3.2 allow remote attackers to execute arbitrary code via a long string argument to the (1) BroadcastKey, (2) BroadcastKeyFileURL, (3) Component, (4) ComponentClassID, (5) ComponentFileName, (6) ExtraProperty, (7) Properties, (8) RequiredVersions, (9) Source, or (10) XMLText method.

    Published: 10 Nov 2007
    9
    Critical

    CVE-2007-5929

    Last Modified: 23 Apr 2026

    Buffer overflow in OpenBase 10.0.5 and earlier might allow remote authenticated users to execute arbitrary code or cause a denial of service (daemon crash) by creating a stored procedure with a long name and invoking this procedure, which triggers heap corruption.

    Published: 10 Nov 2007
    8.1
    High

    CVE-2007-5927

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926.

    Published: 10 Nov 2007
    9
    Critical

    CVE-2007-5926

    Last Modified: 23 Apr 2026

    OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures.

    Published: 10 Nov 2007
    5
    Medium

    CVE-2007-5919

    Last Modified: 23 Apr 2026

    MyWebFTP, possibly 5.3.2, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain an MD5 password hash via a direct request for pass/pass.txt.

    Published: 10 Nov 2007
    6.8
    Medium

    CVE-2007-5913

    Last Modified: 23 Apr 2026

    dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.php via the suppr parameter, and (2) re-create the auth.inc.php file with contents that specify a new account name and password for JBC Explorer via the login and password parameters.

    Published: 10 Nov 2007
    9.3
    Critical

    CVE-2007-5909

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3) DLL or (4) EXE file to exesr.dll, (5) DOC file to mwsr.dll, (6) MIF file to mifsr.dll, (7) SAM file to lasr.dll, or (8) RTF file to rtfsr.dll. NOTE: the WPD (wp6sr.dll) vector is covered by CVE-2007-5910.

    Published: 10 Nov 2007
    8.1
    High

    CVE-2007-5928

    Last Modified: 23 Apr 2026

    OpenBase 10.0.5 and earlier allows remote authenticated users to trigger a free of an arbitrary memory location via long strings in a SELECT statement. NOTE: this might be a buffer overflow, but it is not clear.

    Published: 10 Nov 2007