CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-5116

    Last Modified: 23 Apr 2026

    Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.

    Published: 5 Nov 2007
    6.8
    Medium

    CVE-2007-1660

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 7.0 does not properly calculate sizes for unspecified "multiple forms of character class", which triggers a buffer overflow that allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code.

    Published: 5 Nov 2007
    6.4
    Medium

    CVE-2007-1661

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d" patterns.

    Published: 5 Nov 2007
    5
    Medium

    CVE-2007-1662

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 7.3 reads past the end of the string when searching for unmatched brackets and parentheses, which allows context-dependent attackers to cause a denial of service (crash), possibly involving forward references.

    Published: 5 Nov 2007
    7.5
    High

    CVE-2007-4766

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 7.3 allow context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via unspecified escape (backslash) sequences.

    Published: 5 Nov 2007
    5
    Medium

    CVE-2007-4767

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \p sequence, (2) a \P sequence, or (3) a \P{x} sequence, which allows context-dependent attackers to cause a denial of service (infinite loop or crash) or execute arbitrary code.

    Published: 5 Nov 2007
    4
    Medium

    CVE-2007-5925

    Last Modified: 23 Apr 2026

    The convert_search_mode_to_innobase function in ha_innodb.cc in the InnoDB engine in MySQL 5.1.23-BK and earlier allows remote authenticated users to cause a denial of service (database crash) via a certain CONTAINS operation on an indexed column, which triggers an assertion error.

    Published: 5 Nov 2007
    6.8
    Medium

    CVE-2007-1659

    Last Modified: 23 Apr 2026

    Perl-Compatible Regular Expression (PCRE) library before 7.3 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via regex patterns containing unmatched "\Q\E" sequences with orphan "\E" codes.

    Published: 5 Nov 2007
    7.5
    High

    CVE-2007-5797

    Last Modified: 23 Apr 2026

    SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass authentication via a login attempt with any username not contained in the database.

    Published: 3 Nov 2007
    4.3
    Medium

    CVE-2007-5798

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.

    Published: 3 Nov 2007
    4.3
    Medium

    CVE-2007-5799

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to perform some actions as WAS UDDI users via the (1) keyField, (2) nameField, (3) valueField, and (4) frameReturn parameters.

    Published: 3 Nov 2007
    4.3
    Medium

    CVE-2007-5796

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revocation Lists.

    Published: 3 Nov 2007
    6.8
    Medium

    CVE-2007-5800

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow remote attackers to execute arbitrary PHP code via a URL in the bkpwp_plugin_path parameter to (1) plugins/BackUp/Archive.php; and (2) Predicate.php, (3) Writer.php, (4) Reader.php, and other unspecified scripts under plugins/BackUp/Archive/.

    Published: 3 Nov 2007
    7.5
    High

    CVE-2007-5801

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in WORK system e-commerce before 4.0.2 has unknown impact and attack vectors related to "Ajax pages."

    Published: 3 Nov 2007
    7.5
    High

    CVE-2007-5802

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Firewolf Technologies Synergiser 1.2 RC1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: this can be leveraged to obtain the path by including a local PHP script with a duplicate function declaration.

    Published: 3 Nov 2007
    10
    Critical

    CVE-2007-5767

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree name is not properly delimited with a wide-character backslash or NULL character.

    Published: 2 Nov 2007
    7.5
    High

    CVE-2007-5197

    Last Modified: 23 Apr 2026

    Buffer overflow in the Mono.Math.BigInteger class in Mono 1.2.5.1 and earlier allows context-dependent attackers to execute arbitrary code via unspecified vectors related to Reduce in Montgomery-based Pow methods.

    Published: 2 Nov 2007
    9.3
    Critical

    CVE-2007-5660

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.

    Published: 2 Nov 2007
    6.3
    Medium

    CVE-2007-5795

    Last Modified: 23 Apr 2026

    The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.

    Published: 2 Nov 2007
    7.1
    High

    CVE-2007-5793

    Last Modified: 23 Apr 2026

    Stonesoft StoneGate IPS before 4.0 does not properly decode Fullwidth/Halfwidth Unicode encoded data, which makes it easier for remote attackers to scan or penetrate systems and avoid detection.

    Published: 1 Nov 2007
    4.3
    Medium

    CVE-2007-5773

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the ffile parameter.

    Published: 1 Nov 2007
    5
    Medium

    CVE-2007-5774

    Last Modified: 23 Apr 2026

    index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message.

    Published: 1 Nov 2007
    5
    Medium

    CVE-2007-5776

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence.

    Published: 1 Nov 2007
    5
    Medium

    CVE-2007-5777

    Last Modified: 23 Apr 2026

    Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb.

    Published: 1 Nov 2007
    6
    Medium

    CVE-2007-5772

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit this by leveraging a cookie manipulation issue.

    Published: 1 Nov 2007
    6.8
    Medium

    CVE-2007-5781

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the SYS_PATH parameter.

    Published: 1 Nov 2007
    7.5
    High

    CVE-2007-5783

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands via the pageId parameter.

    Published: 1 Nov 2007
    6.8
    Medium

    CVE-2007-5784

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

    Published: 1 Nov 2007
    7.5
    High

    CVE-2007-5785

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2007
    5
    Medium

    CVE-2007-5787

    Last Modified: 23 Apr 2026

    Micro Login System 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a password via a direct request for userpwd.txt.

    Published: 1 Nov 2007
    7.5
    High

    CVE-2007-5771

    Last Modified: 23 Apr 2026

    Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.

    Published: 1 Nov 2007
    7.5
    High

    CVE-2007-5779

    Last Modified: 23 Apr 2026

    Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method.

    Published: 1 Nov 2007
    2.1
    Low

    CVE-2007-5790

    Last Modified: 23 Apr 2026

    The Globe7 soft phone client 7.3 uses weak cryptography (reversed sequence of binary values) for the password, which might allow local users to obtain sensitive information.

    Published: 1 Nov 2007
    9.8
    Critical

    CVE-2007-5775

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 1 Nov 2007
    7.5
    High

    CVE-2007-5778

    Last Modified: 23 Apr 2026

    Mobile Spy (1) stores login credentials in cleartext under the RetinaxStudios registry key, and (2) sends login credentials and log data over a cleartext HTTP connection, which allows attackers to obtain sensitive information by reading the registry or sniffing the network.

    Published: 1 Nov 2007
    6.8
    Medium

    CVE-2007-5780

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the basePath parameter.

    Published: 1 Nov 2007
    7.5
    High

    CVE-2007-5786

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) HTML_oben.php, (2) inc_freigabe.php, (3) inc_freigabe1.php, or (4) inc_freigabe3.php in include/; (5) inc_group.php; (6) inc_manager.php; (7) inc_newgroup.php; (8) inc_smb_conf.php; (9) inc_user.php; or (10) main.php.

    Published: 1 Nov 2007
    7.8
    High

    CVE-2007-5789

    Last Modified: 23 Apr 2026

    The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060.

    Published: 1 Nov 2007
    10
    Critical

    CVE-2007-5791

    Last Modified: 23 Apr 2026

    The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows remote attackers to send spoofed INVITE messages, as demonstrated by a flood of messages triggering a denial of service, and by phone calls with malicious content.

    Published: 1 Nov 2007
    7.1
    High

    CVE-2007-5792

    Last Modified: 23 Apr 2026

    The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP session.

    Published: 1 Nov 2007
    7.1
    High

    CVE-2007-5788

    Last Modified: 23 Apr 2026

    Buffer overflow in the SIP parser on the Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP INVITE message.

    Published: 1 Nov 2007
    5
    Medium

    CVE-2007-5782

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dl.php in FireConfig 0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 1 Nov 2007
    5
    Medium

    CVE-2007-5768

    Last Modified: 23 Apr 2026

    The Globe7 soft phone client 7.3 sends username and password information in cleartext, which allows remote attackers to obtain sensitive information by sniffing the HTTP traffic.

    Published: 31 Oct 2007
    9.3
    Critical

    CVE-2007-2957

    Last Modified: 23 Apr 2026

    Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large length value in an authentication packet, which results in a heap-based buffer overflow.

    Published: 31 Oct 2007
    9.3
    Critical

    CVE-2007-5080

    Last Modified: 23 Apr 2026

    Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow.

    Published: 31 Oct 2007
    2.1
    Low

    CVE-2007-5751

    Last Modified: 23 Apr 2026

    Liferea before 1.4.6 uses weak permissions (0644) for the feedlist.opml backup file, which allows local users to obtain credentials.

    Published: 31 Oct 2007
    7.5
    High

    CVE-2007-5752

    Last Modified: 23 Apr 2026

    adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges.

    Published: 31 Oct 2007
    6.8
    Medium

    CVE-2007-5754

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in urlinn_includes/config.php in phpFaber URLInn 2.0.5 allows remote attackers to execute arbitrary PHP code via a URL in the dir_ws parameter.

    Published: 31 Oct 2007
    7.5
    High

    CVE-2007-4345

    Last Modified: 23 Apr 2026

    Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message.

    Published: 31 Oct 2007
    9.3
    Critical

    CVE-2007-4599

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file.

    Published: 31 Oct 2007