CVE Feed

    Dashboard / CVE

    6.2
    Medium

    CVE-2007-3920

    Last Modified: 23 Apr 2026

    GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.

    Published: 19 Oct 2007
    7.5
    High

    CVE-2007-5579

    Last Modified: 23 Apr 2026

    login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5578

    Last Modified: 23 Apr 2026

    Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication via (1) base_main.php, (2) base_qry_alert.php, and possibly other vectors.

    Published: 18 Oct 2007
    7.8
    High

    CVE-2007-5570

    Last Modified: 23 Apr 2026

    Cisco Firewall Services Module (FWSM) 3.2(1), and 3.1(5) and earlier, allows remote attackers to cause a denial of service (device reload) via a crafted HTTPS request, aka CSCsi77844.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5575

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in 1024 CMS 1.2.5 allows remote attackers to perform some actions as administrators, as demonstrated by (1) an unspecified action that creates a file containing PHP code and (2) unspecified use of the forum component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Oct 2007
    6.8
    Medium

    CVE-2007-5571

    Last Modified: 23 Apr 2026

    Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to bypass intended restrictions on network traffic, aka CSCsj52536.

    Published: 18 Oct 2007
    9.8
    Critical

    CVE-2007-5565

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in phpSCMS 0.0.1-Alpha1 allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this issue is disputed by CVE because the identified code is in a function that is not accessible via direct request

    Published: 18 Oct 2007
    6.8
    Medium

    CVE-2007-5573

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.

    Published: 18 Oct 2007
    6.8
    Medium

    CVE-2007-5574

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in djpage.php in PHPDJ 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 18 Oct 2007
    6.8
    Medium

    CVE-2007-5576

    Last Modified: 23 Apr 2026

    BEA Tuxedo 8.0 before RP392 and 8.1 before RP293, and WebLogic Enterprise 5.1 before RP174, echo the password in cleartext, which allows physically proximate attackers to obtain sensitive information via the (1) cnsbind, (2) cnsunbind, or (3) cnsls commands.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5577

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.13 (aka Sunglow) allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Section Name form fields in the Section Manager component, or (3) multiple unspecified fields in New Menu Item.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5572

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Blog (SPHPBlog) 0.4.9 allow remote attackers to perform delete actions as administrators via (1) the block_id parameter to add_block.php or (2) the link_id parameter to add_link.php.

    Published: 18 Oct 2007
    7.1
    High

    CVE-2007-5569

    Last Modified: 23 Apr 2026

    Cisco PIX and ASA appliances with 7.1 and 7.2 software, when configured for TLS sessions to the device, allow remote attackers to cause a denial of service (device reload) via a crafted TLS packet, aka CSCsg43276 and CSCsh97120.

    Published: 18 Oct 2007
    7.1
    High

    CVE-2007-5568

    Last Modified: 23 Apr 2026

    Cisco PIX and ASA appliances with 7.0 through 8.0 software, and Cisco Firewall Services Module (FWSM) 3.1(5) and earlier, allow remote attackers to cause a denial of service (device reload) via a crafted MGCP packet, aka CSCsi90468 (appliance) and CSCsi00694 (FWSM).

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5567

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _lib/fckeditor/upload_config.php in Galmeta Post 0.11 allows remote attackers to execute arbitrary PHP code via a URL in the DDS parameter.

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5566

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPBlog 0.1 Alpha allow remote attackers to execute arbitrary PHP code via a URL in the blog_localpath parameter to (1) includes/functions.php or (2) includes/email.php. NOTE: this issue is disputed by CVE because the identified code is in functions that are not accessible via direct request

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5562

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/welcome (aka the login page) in Netgear SSL312 PROSAFE SSL VPN-Concentrator 25 allows remote attackers to inject arbitrary web script or HTML via the err parameter in the context of an error page.

    Published: 18 Oct 2007
    10
    Critical

    CVE-2007-5559

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the IBM ThinkVantage TPM Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    7.8
    High

    CVE-2007-5557

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NEC mobile handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-3102

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the linux_audit_record_event function in OpenSSH 4.3p2, as used on Fedora Core 6 and possibly other systems, allows remote attackers to write arbitrary characters to an audit log via a crafted username. NOTE: some of these details are obtained from third party information.

    Published: 18 Oct 2007
    2.6
    Low

    CVE-2007-5564

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile.

    Published: 18 Oct 2007
    7.8
    High

    CVE-2007-5558

    Last Modified: 23 Apr 2026

    Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    6.9
    Medium

    CVE-2007-5555

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solution." NOTE: this description is based on a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    5
    Medium

    CVE-2007-5550

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS allows remote attackers to obtain the IOS version via unspecified vectors involving a "common network service", aka PSIRT-1255024833. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    2.1
    Low

    CVE-2007-5549

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS command" involving "two different methods", aka CSCsk16129. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    9.3
    Critical

    CVE-2007-5546

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in TIBCO SmartPGM FX allow remote attackers to execute arbitrary code or cause a denial of service (service stop and file-transfer outage) via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5563

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in VirtueMart before 1.0.13 allows remote attackers to execute arbitrary PHP code via unspecified vectors.

    Published: 18 Oct 2007
    10
    Critical

    CVE-2007-5560

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Juniper HTTP Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    4.6
    Medium

    CVE-2007-4600

    Last Modified: 23 Apr 2026

    The "Protect Worksheet" functionality in Mathsoft Mathcad 12 through 13.1, and PTC Mathcad 14, implements file access restrictions via a protection element in a gzipped XML file, which allows attackers to bypass these restrictions by removing this element.

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5545

    Last Modified: 23 Apr 2026

    Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5547

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Cisco IOS allows remote attackers to inject arbitrary web script or HTML, and execute IOS commands, via unspecified vectors, aka PSIRT-2022590358. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    7.1
    High

    CVE-2007-5551

    Last Modified: 23 Apr 2026

    Off-by-one error in Cisco IOS allows remote attackers to execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    9.3
    Critical

    CVE-2007-5552

    Last Modified: 23 Apr 2026

    Integer overflow in Cisco IOS allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    7.1
    High

    CVE-2007-5554

    Last Modified: 23 Apr 2026

    Oracle allows remote attackers to obtain server memory contents via crafted packets, aka Oracle reference number 7892711. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    Unknown

    CVE-2007-5553

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4158. Reason: This candidate is a duplicate of CVE-2007-4158. It was based on a vague pre-advisory, so the duplicate was not detected until more details were provided. Notes: All CVE users should reference CVE-2007-4158 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Oct 2007
    10
    Critical

    CVE-2007-5561

    Last Modified: 23 Apr 2026

    Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, allows remote attackers to execute arbitrary code via format string specifiers in the URI in an HTTP request to port 6003, aka Oracle reference number 6296175. NOTE: this might be the same issue as CVE-2007-0282 or CVE-2007-0280, but there are insufficient details to be sure.

    Published: 18 Oct 2007
    6.9
    Medium

    CVE-2007-5548

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Command EXEC in Cisco IOS allow local users to gain privileges via unspecified vectors, aka (1) PSIRT-0474975756 and (2) PSIRT-0388256465. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    7.8
    High

    CVE-2007-5556

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 18 Oct 2007
    5
    Medium

    CVE-2007-5473

    Last Modified: 23 Apr 2026

    StaticFileHandler.cs in System.Web in Mono before 1.2.5.2, when running on Windows, allows remote attackers to obtain source code of sensitive files via a request containing a trailing (1) space or (2) dot, which is not properly handled by XSP.

    Published: 18 Oct 2007
    9.3
    Critical

    CVE-2007-5338

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5540

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.24 allows remote attackers to overwrite functions on pages from other domains and bypass the same-origin policy via unknown vectors.

    Published: 18 Oct 2007
    9
    Critical

    CVE-2007-5539

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Unified Intelligent Contact Management Enterprise (ICME), Unified ICM Hosted (ICMH), Unified Contact Center Enterprise (UCCE), Unified Contact Center Hosted (UCCH), and System Unified Contact Center Enterprise (SUCCE) 7.1(5) allows remote authenticated users to gain privileges, and read reports or change the SUCCE configuration, via certain web interfaces, aka CSCsj55686.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5493

    Last Modified: 23 Apr 2026

    The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5340

    Last Modified: 23 Apr 2026

    Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5334

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.

    Published: 18 Oct 2007
    9.3
    Critical

    CVE-2007-5541

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.24, when using an "external" newsgroup or e-mail client, allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5337

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

    Published: 18 Oct 2007
    10
    Critical

    CVE-2007-5476

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Player 9.0.47.0 and earlier, when running on Opera before 9.24 on Mac OS X, has unknown "Highly Severe" impact and unknown attack vectors.

    Published: 18 Oct 2007
    10
    Critical

    CVE-2007-5535

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in newbb_plus in RunCms 1.5.2 has unknown impact and attack vectors.

    Published: 18 Oct 2007
    4.9
    Medium

    CVE-2007-5536

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OpenSSL before A.00.09.07l on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to cause a denial of service via unspecified vectors.

    Published: 18 Oct 2007