CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-5326

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in (1) RPC and (2) rpcx.dll in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Oct 2007
    10
    Critical

    CVE-2007-5329

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in dbasvr in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, has unknown impact and attack vectors related to memory corruption.

    Published: 13 Oct 2007
    10
    Critical

    CVE-2007-5331

    Last Modified: 23 Apr 2026

    Queue.dll for the message queuing service (LQserver.exe) in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows remote attackers to execute arbitrary code via a malformed ONRPC protocol request for operation 0x76, which causes ARCserve Backup to dereference arbitrary pointers.

    Published: 13 Oct 2007
    7.5
    High

    CVE-2007-5423

    Last Modified: 23 Apr 2026

    tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function.

    Published: 12 Oct 2007
    7.5
    High

    CVE-2007-5424

    Last Modified: 23 Apr 2026

    The disable_functions feature in PHP 4 and 5 allows attackers to bypass intended restrictions by using an alias, as demonstrated by using ini_alter when ini_set is disabled.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5427

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the com_search component in Joomla! 1.0.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. NOTE: this might be related to CVE-2007-4189.1.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5428

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in UMI CMS allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to the default URI in search_do/.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5429

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Nucleus 3.01 allows remote attackers to inject arbitrary web script or HTML via the archive parameter.

    Published: 12 Oct 2007
    7.5
    High

    CVE-2007-5430

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem.

    Published: 12 Oct 2007
    7.8
    High

    CVE-2007-5431

    Last Modified: 23 Apr 2026

    include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow remote attackers to gain unauthorized access to the FTP server being used by the module by viewing the source code.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5358

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the voicemail functionality in Asterisk 1.4.x before 1.4.13, when using IMAP storage, might allow (1) remote attackers to execute arbitrary code via a long combination of Content-type and Content-description headers, or (2) local users to execute arbitrary code via a long combination of astspooldir, voicemail context, and voicemail mailbox fields. NOTE: vector 2 requires write access to Asterisk configuration files.

    Published: 12 Oct 2007
    6.4
    Medium

    CVE-2007-5425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the questId parameter in a hideQuestion ToDo action. NOTE: the catId vector is already covered by CVE-2007-5131.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5434

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PRO-search 0.17.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter to the default URI.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5426

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page parameter to the default URI for some directories, as demonstrated by (1) ActiveKB/ and (2) default/categories/ActiveKB/.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5433

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Site-Up 2.64 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) search mask field.

    Published: 12 Oct 2007
    7.5
    High

    CVE-2007-5432

    Last Modified: 23 Apr 2026

    Stride 1.0 has a default administrator username of "scott" with the password "running", which allows remote attackers to obtain administrative access through login.php.

    Published: 12 Oct 2007
    2.6
    Low

    CVE-2007-5414

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5415

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.

    Published: 12 Oct 2007
    2.6
    Low

    CVE-2007-5420

    Last Modified: 23 Apr 2026

    The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might allow remote attackers to obtain information about the router's existence and product details.

    Published: 12 Oct 2007
    4.9
    Medium

    CVE-2007-5422

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in "Solaris Auditing" in the Basic Security Module (BSM) in Sun Solaris 10, when configured for auditing of networking (nt) events, allows local users to cause a denial of service (panic) via unspecified vectors.

    Published: 12 Oct 2007
    Unknown

    CVE-2007-5421

    Last Modified: 7 Nov 2023

    Multiple stack-based buffer overflows in Cisco IOS 12.x and IOS XR allow attackers to execute arbitrary code, as demonstrated via the "Bind Shell", "Reverse Shell", and "Two byte rootshell (Tiny Shell)" attacks. NOTE: the vendor and researcher agree that this issue does not cross privilege boundaries, saying they do not "represent a vulnerability." The disclosure was intended to demonstrate techniques for exploitation, which is not covered by CVE

    Published: 12 Oct 2007
    7.5
    High

    CVE-2007-5418

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CARE2X 2G 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) en_copyrite.php, (2) vi_copyrite.php, and (3) ar_copyrite.php in language/ directories; (4) class_access.php, (5) class_department.php, (6) class_config.php, (7) class_image.php, (8) class_ward.php, and (9) class_product.php in include/care_api_classes/; (10) gui/smarty_template/smarty_care.class.php; and possibly other components, different vectors than CVE-2007-1458.

    Published: 12 Oct 2007
    5
    Medium

    CVE-2007-5417

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5416

    Last Modified: 23 Apr 2026

    Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by invoking the drupal_eval function through a callback parameter to the default URI, as demonstrated by the _menu[callbacks][1][callback] parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Drupal.

    Published: 12 Oct 2007
    10
    Critical

    CVE-2007-5419

    Last Modified: 23 Apr 2026

    The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source IP addresses on the external (Internet) interface unless the user selects other options, which might expose the router to unintended incoming traffic from remote attackers, as demonstrated by setting up a virtual server on port 80, which allows remote attackers to access the web management interface.

    Published: 12 Oct 2007
    9.3
    Critical

    CVE-2007-3675

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5407

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2) add.php, (3) history.php, and (4) register.php, in view/; and (5) list.sub.html.php, (6) list.user.sub.html.php, and (7) reports.html.php in views/.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5408

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5412

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter to (1) allopass.php and (2) allopass-error.php.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5410

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.wmtrssreader.php in the webmaster-tips.net Flash RSS Reader (com_wmtrssreader) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5411

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5409

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the nuseo_dir parameter.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5386

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in scripts/setup.php in phpMyAdmin 2.11.1, when accessed by a browser that does not URL-encode requests, allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 12 Oct 2007
    10
    Critical

    CVE-2007-5391

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access via unknown vectors.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5389

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in preview.php in the swMenuFree (com_swmenufree) 4.6 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: a reliable third party disputes this issue because preview.php tests a certain constant to prevent direct requests

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5390

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5387

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the c[components] parameter.

    Published: 12 Oct 2007
    6.8
    Medium

    CVE-2007-5388

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5384

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to perform actions as administrators via unspecified POST requests, as demonstrated by enabling an inbound remote-assistance HTTPS session on TCP port 51003. NOTE: an authentication bypass can be leveraged to exploit this in the absence of an existing administrative session. NOTE: SpeedTouch 780 might also be affected by some of these issues.

    Published: 12 Oct 2007
    4.3
    Medium

    CVE-2007-5385

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 12 Oct 2007
    9.3
    Critical

    CVE-2007-5381

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.

    Published: 12 Oct 2007
    10
    Critical

    CVE-2007-5383

    Last Modified: 23 Apr 2026

    The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentication and gain administrative access via vectors including a '/' (slash) character at the end of the PATH_INFO to cgi/b, aka "double-slash auth bypass." NOTE: remote attackers outside the intranet can exploit this by leveraging a separate CSRF vulnerability. NOTE: SpeedTouch 780 might also be affected by some of these issues.

    Published: 12 Oct 2007
    10
    Critical

    CVE-2007-5382

    Last Modified: 23 Apr 2026

    The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) creates administrator accounts with default usernames and passwords, which allows remote attackers to gain privileges.

    Published: 12 Oct 2007
    9.3
    Critical

    CVE-2007-4995

    Last Modified: 23 Apr 2026

    Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 12 Oct 2007
    9.3
    Critical

    CVE-2007-5169

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in MAIPM6.dll in Adobe PageMaker 7.0.1 and 7.0.2 on Windows allows user-assisted remote attackers to execute arbitrary code via a long font name in a .PMD file.

    Published: 11 Oct 2007
    4.9
    Medium

    CVE-2007-5367

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors.

    Published: 11 Oct 2007
    4.9
    Medium

    CVE-2007-5368

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local users to cause a denial of service (multiple application hang) via unspecified vectors.

    Published: 11 Oct 2007
    5
    Medium

    CVE-2007-5369

    Last Modified: 23 Apr 2026

    The GetMagicNumberString function in Massive Entertainment World in Conflict 1.000 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a string to the VoIP port (52999/tcp) with an invalid value in the third byte.

    Published: 11 Oct 2007
    5
    Medium

    CVE-2007-5366

    Last Modified: 23 Apr 2026

    The Tomcat 4.1-based Servlet Service in Fujitsu Interstage Application Server 7.0 through 9.0.0 and Interstage Apworks/Studio 7.0 through 9.0.0 allows remote attackers to obtain sensitive information (web root path) via unspecified vectors that trigger an error message, probably related to enabling the useCanonCaches Java Virtual Machine (JVM) option.

    Published: 11 Oct 2007
    6.5
    Medium

    CVE-2007-5374

    Last Modified: 23 Apr 2026

    cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticated users to increase the privileges of any account.

    Published: 11 Oct 2007