CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2007-5537

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.

    Published: 18 Oct 2007
    10
    Critical

    CVE-2007-5538

    Last Modified: 23 Apr 2026

    Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames, aka CSCsh47712.

    Published: 18 Oct 2007
    4.3
    Medium

    CVE-2007-5339

    Last Modified: 23 Apr 2026

    Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.

    Published: 18 Oct 2007
    7.5
    High

    CVE-2007-5532

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the People Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.17, 8.47.14, 8.48.13, 8.49.05 has unknown impact and remote attack vectors, aka PSE01.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5524

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS09 or AS9.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5520

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8 and 9.2.0.8DV, and Oracle Application Server 9.0.4.3, 10.1.3.0.0 up to 10.1.3.3.0, and 10.1.2.0.1 up to 10.1.2.2.0, has unknown impact and remote attack vectors, aka AS05.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5517

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2 and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS02.

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5515

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.2, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB27.

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5509

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Spatial component in Oracle Database 9.2.0.8 and 9.2.0.8DV has unknown impact and remote attack vectors, aka DB06.

    Published: 17 Oct 2007
    6.4
    Medium

    CVE-2007-5507

    Last Modified: 23 Apr 2026

    The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (crash) or read potentially sensitive memory via a connect GIOP packet with an invalid data size, which triggers a buffer over-read, aka DB22.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5488

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in cdr_addon_mysql in Asterisk-Addons before 1.2.8, and 1.4.x before 1.4.4, allow remote attackers to execute arbitrary SQL commands via the (1) source and (2) destination numbers, and probably (3) SIP URI, when inserting a record.

    Published: 17 Oct 2007
    9
    Critical

    CVE-2007-5534

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HCM component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 Bundle 13 9.0 Bundle 3 has unknown impact and remote attack vectors, aka PSE_HCM01.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5527

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and remote attack vectors, related to (1) Application Object Library component (APP01), (2) Contracts Integration (APP02), (3) Applications Manager (APP04), (4) Marketing component (APP05), and (5) Exchange component (APP07).

    Published: 17 Oct 2007
    10
    Critical

    CVE-2007-5526

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2, 10.1.2.2, and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS11.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5521

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.3.3, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS06.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5518

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 10.1.3.2 has unknown impact and remote attack vectors, aka AS03.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5516

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Process Mgmt & Notification component in Oracle Application Server 10.1.3.3 has unknown impact and remote attack vectors, aka AS01.

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5533

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the People Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.14, 8.48.13, 8.49.05 has unknown impact and remote attack vectors, aka PSE02.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5525

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0.1; Collaboration Suite 10.1.2; and Enterprise Manager 10.1.2 has unknown impact and remote attack vectors, aka AS10.

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5510

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Workspace Manager component in Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 have unknown impact and remote attack vectors, aka (1) DB08, (2) DB09, (3) DB10, (4) DB11, (5) DB12, (6) DB13, (7) DB14, (8) DB15, (9) DB16, (10) DB17, and (11) DB18. NOTE: one of these issues is probably CVE-2007-5511, but there are insufficient details to be certain.

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5511

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.0.8.0 allows attackers to execute arbitrary SQL commands via the FINDRICSET procedure in the LT package. NOTE: this is probably covered by CVE-2007-5510, but there are insufficient details to be certain.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5512

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV and 10.2.0.3 has unknown impact and remote attack vectors, aka DB21.

    Published: 17 Oct 2007
    5
    Medium

    CVE-2007-5513

    Last Modified: 23 Apr 2026

    The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect audit entries in the USERID column in which (1) long usernames are trimmed to 5 characters, or (2) short entries contain any extra characters from usernames in previous entries, aka DB23.

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5514

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and attack vectors related to (1) Database Vault component (DB24) and (2) SQL Execution component (DB26).

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5508

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5519

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS04.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5522

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.4.1 has unknown impact and remote attack vectors, aka AS07.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5523

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS08.

    Published: 17 Oct 2007
    10
    Critical

    CVE-2007-5528

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.2 have unknown impact and attack vectors related to (1) Public Sector Human Resources (APP03) and (2) Quoting component (APP06).

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5529

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Self-Service Web Applications component in client-only installations of Oracle E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka APP08.

    Published: 17 Oct 2007
    10
    Critical

    CVE-2007-5530

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Database Control component in Oracle Database 10.1.0.5 and 10.2.0.3, and Enterprise Manager, has unknown impact and remote attack vectors, aka EM01.

    Published: 17 Oct 2007
    10
    Critical

    CVE-2007-5531

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02.

    Published: 17 Oct 2007
    7.8
    High

    CVE-2007-5506

    Last Modified: 23 Apr 2026

    The Core RDBMS component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote attackers to cause a denial of service (CPU consumption) via a crafted type 6 Data packet, aka DB20.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5505

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to (1) the Export component (DB02), (2) Oracle Text (DB04), (3) Oracle Text (DB05), (4) Spatial component (DB07), and (5) Advanced Security Option (DB19).

    Published: 17 Oct 2007
    6.5
    Medium

    CVE-2007-5504

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+ and 10.1.0.5 unknown impact and remote attack vectors, related to (1) Import (DB01) and (2) Advanced Queuing (DB25). NOTE: as of 20071108, Oracle has not disputed reliable researcher claims that DB25 is for a buffer overflow in the DBLINK_INFO procedure in the DBMS_AQADM_SYS package.

    Published: 17 Oct 2007
    9
    Critical

    CVE-2007-5491

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to chmod arbitrary files to 0777 via ".." sequences in the lang parameter.

    Published: 17 Oct 2007
    4.6
    Medium

    CVE-2007-5492

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to execute arbitrary PHP code via the value parameter.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5490

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Okul Otomasyon Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Oct 2007
    7.5
    High

    CVE-2007-5489

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 17 Oct 2007
    6.8
    Medium

    CVE-2007-5935

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag.

    Published: 17 Oct 2007
    5
    Medium

    CVE-2007-5623

    Last Modified: 23 Apr 2026

    Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via crafted snmpget replies.

    Published: 17 Oct 2007
    6.4
    Medium

    CVE-2007-5482

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the FTP service in Sun StorEdge/StorageTek 3510 FC Array with firmware before 4.21 allows remote attackers, with access to the Ethernet management interface, to cause a denial of service (I/O request timeout and device hang) via unspecified vectors.

    Published: 16 Oct 2007
    4.3
    Medium

    CVE-2007-5477

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.

    Published: 16 Oct 2007
    9.3
    Critical

    CVE-2007-5487

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an EXTM3U section of a .m3u file.

    Published: 16 Oct 2007
    6.4
    Medium

    CVE-2007-5486

    Last Modified: 23 Apr 2026

    dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information.

    Published: 16 Oct 2007
    5.1
    Medium

    CVE-2007-4343

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IrfanView 3.99 and 4.00 allows user-assisted remote attackers to execute arbitrary code via a crafted palette (.pal) file.

    Published: 16 Oct 2007
    4.3
    Medium

    CVE-2007-5478

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in projects in Nabh Stringbeans Portal (sbportal) 3.2 allows remote attackers to inject arbitrary web script or HTML via the project_name parameter.

    Published: 16 Oct 2007
    4.3
    Medium

    CVE-2007-5479

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Search.asp in Xcomputer allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter.

    Published: 16 Oct 2007
    4.3
    Medium

    CVE-2007-5480

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in InnovaAge InnovaShop allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to msg.jsp, and the (2) contentid parameter to tc/contents/home001.jsp.

    Published: 16 Oct 2007
    5
    Medium

    CVE-2007-5481

    Last Modified: 23 Apr 2026

    Distributed Checksum Clearinghouse (DCC) 1.3.65 allows remote attackers to cause a denial of service (crash) via a "SOCKS flood."

    Published: 16 Oct 2007