CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-5753

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Light FMan PHP (lfman or lightfman) before 2.0rc1 has unknown impact and attack vectors related to "actions."

    Published: 31 Oct 2007
    7.5
    High

    CVE-2007-5740

    Last Modified: 23 Apr 2026

    The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.

    Published: 31 Oct 2007
    10
    Critical

    CVE-2007-4351

    Last Modified: 23 Apr 2026

    Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.

    Published: 31 Oct 2007
    5
    Medium

    CVE-2007-4136

    Last Modified: 23 Apr 2026

    The ricci daemon in Red Hat Conga 0.10.0 allows remote attackers to cause a denial of service (loss of new connections) by repeatedly sending data or attempting connections.

    Published: 31 Oct 2007
    4.7
    Medium

    CVE-2007-5906

    Last Modified: 23 Apr 2026

    Xen 3.1.1 allows virtual guest system users to cause a denial of service (hypervisor crash) by using a debug register (DR7) to set certain breakpoints.

    Published: 31 Oct 2007
    3.5
    Low

    CVE-2007-5731

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag, a related issue to CVE-2007-5461.

    Published: 30 Oct 2007
    7.5
    High

    CVE-2007-5733

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload/upload.php in Japanese PHP Gallery Hosting, when Open directory mode is enabled, allows remote attackers to upload and execute arbitrary PHP code via a ServerPath parameter specifying a filename with a double extension. NOTE: some of these details are obtained from third party information.

    Published: 30 Oct 2007
    5
    Medium

    CVE-2007-5739

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Published: 30 Oct 2007
    5
    Medium

    CVE-2007-5735

    Last Modified: 23 Apr 2026

    eFileMan 7.1.0.87-88 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain unspecified user information via a direct request for cgi-bin/efileman/efileman_config.pm.

    Published: 30 Oct 2007
    6.8
    Medium

    CVE-2007-5738

    Last Modified: 23 Apr 2026

    The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a modified copy of component/flashupload/upload.html.

    Published: 30 Oct 2007
    5
    Medium

    CVE-2007-5732

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in downloadfile.php in eLouai's Force Download of media files script, as available on 20071030 and earlier, allows remote attackers to read arbitrary files via the file parameter. NOTE: this issue only occurs in environments where the system administrator has not followed the vendor recommendations that this product should only be used internally.

    Published: 30 Oct 2007
    6.4
    Medium

    CVE-2007-5734

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in eFileMan 7.1.0.87-88 allows remote attackers to upload arbitrary files, with "uploads/upload_file." destination filenames, via unspecified vectors to upload.cgi, accessed from upload.html.

    Published: 30 Oct 2007
    7.5
    High

    CVE-2007-5737

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified vectors, probably involving a direct request.

    Published: 30 Oct 2007
    6.4
    Medium

    CVE-2007-5736

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in SeeBlick 1.0 Beta allows remote attackers to upload arbitrary files via unspecified vectors. NOTE: these files are stored with .html extensions, so the scope of the attack might be limited to resource consumption and possibly XSS.

    Published: 30 Oct 2007
    6.6
    Medium

    CVE-2007-4277

    Last Modified: 23 Apr 2026

    The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \\.\Tmfilter device, which allows local users to send arbitrary content to the device via the IOCTL functionality. NOTE: this can be leveraged for privilege escalation by exploiting a buffer overflow in the handler for IOCTL 0xa0284403.

    Published: 30 Oct 2007
    7.2
    High

    CVE-2007-5729

    Last Modified: 23 Apr 2026

    The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-4862

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/menu.php in SAXON 5.4 allows remote attackers to inject arbitrary web script or HTML via the config[news_url] parameter.

    Published: 30 Oct 2007
    6.8
    Medium

    CVE-2007-4863

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.

    Published: 30 Oct 2007
    7.8
    High

    CVE-2007-5716

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.

    Published: 30 Oct 2007
    10
    Critical

    CVE-2007-5717

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) on x86 before firmware 2.70 allows remote attackers to execute arbitrary commands as root on the Service Processor (SP) via unspecified vectors, a different vulnerability than CVE-2007-5170.

    Published: 30 Oct 2007
    4.9
    Medium

    CVE-2007-5718

    Last Modified: 23 Apr 2026

    vobcopy 0.5.14 allows local users to append data to an arbitrary file, or create an arbitrary new file, via a symlink attack on the (1) /tmp/vobcopy.bla or (2) /tmp/vobcopy_0.5.14.log temporary file.

    Published: 30 Oct 2007
    5
    Medium

    CVE-2007-5723

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the samp_send function in nuauth/sasl.c in NuFW before 2.2.7 allows remote attackers to cause a denial of service via unspecified input on which base64 encoding is performed. NOTE: some of these details are obtained from third party information.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-5724

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web script or HTML via (1) the category_id parameter to users/kb.php, and possibly (3) the Email Box field in profile.php.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-5725

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Smart-Shop allow remote attackers to inject arbitrary web script or HTML via (1) the email parameter to index.php; or the command parameter to index.php in (2) the default action for the home page, (3) a currencies action, or (4) a basket action.

    Published: 30 Oct 2007
    6.8
    Medium

    CVE-2007-5726

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Stream Control Transmission Protocol (sctp) functionality in Sun Solaris 10, when at least one SCTP socket is in the LISTEN state, allows remote attackers to cause a denial of service (panic) via unspecified vectors related to "INIT processing."

    Published: 30 Oct 2007
    5
    Medium

    CVE-2007-4861

    Last Modified: 23 Apr 2026

    SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.

    Published: 30 Oct 2007
    6.8
    Medium

    CVE-2007-5720

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-5728

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpPgAdmin 3.5 to 4.1.1, and possibly 4.1.2, allows remote attackers to inject arbitrary web script or HTML via certain input available in PHP_SELF in (1) redirect.php, possibly related to (2) login.php, different vectors than CVE-2007-2865.

    Published: 30 Oct 2007
    6.8
    Medium

    CVE-2007-5721

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the rootBase parameter.

    Published: 30 Oct 2007
    7.5
    High

    CVE-2007-5722

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in a certain ActiveX control in GLChat.ocx 2.5.1.32 in GlobalLink 2.7.0.8, as used in Ourgame GLWorld and possibly other products, allows remote attackers to execute arbitrary code via a long first argument to the ConnectAndEnterRoom method, possibly involving the GLCHAT.GLChatCtrl.1 control, as originally exploited in the wild in October 2007. NOTE: some of these details are obtained from third party information. NOTE: this was originally reported as a heap-based issue by some sources.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-5727

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.

    Published: 30 Oct 2007
    Unknown

    CVE-2007-1323

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2893. Reason: this candidate was intended for one issue, but some sources used this identifier for a separate issue, and a duplicate identifier had also been created by the time dual use was detected. Notes: All CVE users should consult CVE-2007-2893 to determine if it is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Oct 2007
    7.5
    High

    CVE-2007-5719

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL commands via the table parameter to index.php.

    Published: 30 Oct 2007
    9.3
    Critical

    CVE-2007-5709

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file.

    Published: 30 Oct 2007
    2.6
    Low

    CVE-2007-5710

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.

    Published: 30 Oct 2007
    6.8
    Medium

    CVE-2007-5714

    Last Modified: 23 Apr 2026

    The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-5715

    Last Modified: 23 Apr 2026

    DenyHosts 2.6 processes OpenSSH sshd "not listed in AllowUsers" log messages with an incorrect regular expression that does not match an IP address, which might allow remote attackers to avoid detection and blocking when making invalid login attempts with a username not present in AllowUsers, as demonstrated by the root username, a different vulnerability than CVE-2007-4323.

    Published: 30 Oct 2007
    5
    Medium

    CVE-2007-5711

    Last Modified: 23 Apr 2026

    Massive Entertainment World in Conflict 1.001 and earlier allows remote attackers to cause a denial of service (failed assertion and daemon crash) via a large packet to TCP or UDP port 48000.

    Published: 30 Oct 2007
    2.6
    Low

    CVE-2007-5712

    Last Modified: 23 Apr 2026

    The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory consumption) via many HTTP requests with large Accept-Language headers.

    Published: 30 Oct 2007
    7.5
    High

    CVE-2007-5713

    Last Modified: 23 Apr 2026

    Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified input related to geolocation, which triggers an error message from the (1) geoip_code2 or (2) geoip_code3 function, leading to a buffer overflow.

    Published: 30 Oct 2007
    4.3
    Medium

    CVE-2007-4348

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the CAD service in IBM Tivoli Storage Manager (TSM) Client 5.3.5.3 and 5.4.1.2 for Windows allows remote attackers to inject arbitrary web script or HTML via HTTP requests to port 1581, which generate log entries in a dsmerror.log file that is accessible through a certain web interface.

    Published: 30 Oct 2007
    9.3
    Critical

    CVE-2007-4222

    Last Modified: 23 Apr 2026

    Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.

    Published: 29 Oct 2007
    4.3
    Medium

    CVE-2007-4999

    Last Modified: 23 Apr 2026

    libpurple in Pidgin 2.1.0 through 2.2.1, when using HTML logging, allows remote attackers to cause a denial of service (NULL dereference and application crash) via a message that contains invalid HTML data, a different vector than CVE-2007-4996.

    Published: 29 Oct 2007
    7.8
    High

    CVE-2007-5413

    Last Modified: 23 Apr 2026

    httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Configuration Manager (CCM) 2.0 allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories, as demonstrated by ~root.

    Published: 29 Oct 2007
    4.3
    Medium

    CVE-2007-5702

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in swamp/action/LoginActions (aka the login box) in the Novell OpenSUSE SWAMP Workflow Administration and Management Platform 1.x allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 29 Oct 2007
    4.3
    Medium

    CVE-2007-5703

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) Request-spk.xuda and (2) Add-msie-request.xuda in RSA KEON Registration Authority Web Interface 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Oct 2007
    6
    Medium

    CVE-2007-5705

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Settings component in the administration system in Jeebles Directory 2.9.60 allows remote authenticated administrators to execute arbitrary PHP code via unspecified vectors related to settings.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Oct 2007
    9.3
    Critical

    CVE-2007-5706

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in download.php in Jeebles Directory 2.9.60 allows remote attackers to read arbitrary files via a full pathname in the query string. NOTE: some of these details are obtained from third party information.

    Published: 29 Oct 2007
    7.5
    High

    CVE-2007-5704

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp.

    Published: 29 Oct 2007
    5
    Medium

    CVE-2007-5622

    Last Modified: 23 Apr 2026

    Double free vulnerability in the ftpprchild function in ftppr in 3proxy 0.5 through 0.5.3i allows remote attackers to cause a denial of service (daemon crash) via multiple OPEN commands to the FTP proxy.

    Published: 29 Oct 2007