CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-5370

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/dnewsweb.exe in NetWin DNewsWeb (DNews News Server) 57e1 allow remote attackers to inject arbitrary web script or HTML via the (1) group or (2) utag parameter.

    Published: 11 Oct 2007
    6.8
    Medium

    CVE-2007-5371

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (1) documentDirty or (2) modVariables parameter.

    Published: 11 Oct 2007
    10
    Critical

    CVE-2007-5372

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through 1.2.7 and (b) DWS Systems SQL-Ledger 2.x allow remote attackers to execute arbitrary SQL commands via (1) the invoice quantity field or (2) the sort field.

    Published: 11 Oct 2007
    2.1
    Low

    CVE-2007-5373

    Last Modified: 23 Apr 2026

    ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepassword function.

    Published: 11 Oct 2007
    7.8
    High

    CVE-2007-3917

    Last Modified: 23 Apr 2026

    The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.

    Published: 11 Oct 2007
    10
    Critical

    CVE-2007-5364

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in payments/ideal_process.php in the iDEAL transaction handler in ViArt Shopping Cart allows remote attackers to have an unknown impact via directory traversal sequences in the filename parameter to the createCertFingerprint function. NOTE: this issue is disputed by CVE because PHP encounters a fatal function-call error on a direct request for payments/ideal_process.php

    Published: 11 Oct 2007
    6.8
    Medium

    CVE-2007-5362

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.

    Published: 11 Oct 2007
    6.8
    Medium

    CVE-2007-5363

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (plugin) 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Oct 2007
    9.3
    Critical

    CVE-2007-3896

    Last Modified: 23 Apr 2026

    The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 installed, allows remote attackers to execute arbitrary programs via invalid "%" sequences in a mailto: or other URI handler, as demonstrated using mIRC, Outlook, Firefox, Adobe Reader, Skype, and other applications. NOTE: this issue might be related to other issues involving URL handlers in Windows systems, such as CVE-2007-3845. There also might be separate but closely related issues in the applications that are invoked by the handlers.

    Published: 11 Oct 2007
    9.3
    Critical

    CVE-2007-4619

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

    Published: 11 Oct 2007
    10
    Critical

    CVE-2007-4992

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the process_packet function in fbserver.exe in Firebird SQL 2.0.2 allows remote attackers to execute arbitrary code via a long request to TCP port 3050.

    Published: 11 Oct 2007
    7.6
    High

    CVE-2007-5208

    Last Modified: 23 Apr 2026

    hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not properly handled when invoking sendmail.

    Published: 11 Oct 2007
    10
    Critical

    CVE-2007-5323

    Last Modified: 23 Apr 2026

    The RepliStor Server Service in EMC Replistor 6.1.3 allows remote attackers to execute arbitrary code via a size value that causes RepliStor to create a smaller buffer than expected, which triggers a buffer overflow when that buffer is used in a recv function call.

    Published: 11 Oct 2007
    9.8
    Critical

    CVE-2007-5341

    Last Modified: 20 Apr 2025

    Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.

    Published: 10 Oct 2007
    2.6
    Low

    CVE-2007-5375

    Last Modified: 23 Apr 2026

    Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local relative URI, which may be associated with different IP addresses by the browser and the JVM.

    Published: 10 Oct 2007
    9.3
    Critical

    CVE-2007-3897

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-3893

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via unspecified vectors involving memory corruption from an unhandled error.

    Published: 9 Oct 2007
    3.5
    Low

    CVE-2007-5319

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors.

    Published: 9 Oct 2007
    7.5
    High

    CVE-2007-5322

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.

    Published: 9 Oct 2007
    7.5
    High

    CVE-2007-3892

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01 through 7 allows remote attackers to spoof the URL address bar and other "trust UI" components via unspecified vectors, a different issue than CVE-2007-1091 and CVE-2007-3826.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-4466

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters.

    Published: 9 Oct 2007
    7.8
    High

    CVE-2007-2228

    Last Modified: 23 Apr 2026

    rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS service stop and system restart) via an RPC request that uses NTLMSSP PACKET authentication with a zero-valued verification trailer signature, which triggers an invalid dereference. NOTE: this also affects Windows 2000 SP4, although the impact is an information leak.

    Published: 9 Oct 2007
    4
    Medium

    CVE-2007-5320

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5321

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.

    Published: 9 Oct 2007
    9.3
    Critical

    CVE-2007-2217

    Last Modified: 23 Apr 2026

    Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote attackers to execute arbitrary code via crafted image files that trigger memory corruption, as demonstrated by a certain .tif (TIFF) file.

    Published: 9 Oct 2007
    9.3
    Critical

    CVE-2007-3899

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word 2000 SP3, Word 2002 SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a malformed string in a Word file, aka "Word Memory Corruption Vulnerability."

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5310

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 9 Oct 2007
    7.5
    High

    CVE-2007-5311

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic Edition 1.07 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5312

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in TorrentTrader Classic 1.07 allows remote attackers to inject arbitrary web script or HTML via the (1) color parameter to pjirc/css.php and the (2) cat parameter to browse.php.

    Published: 9 Oct 2007
    7.5
    High

    CVE-2007-5313

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 9 Oct 2007
    Unknown

    CVE-2007-5317

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-5292. Reason: This candidate is a duplicate of CVE-2007-5292. Notes: All CVE users should reference CVE-2007-5292 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5315

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the livealbum_dir parameter.

    Published: 9 Oct 2007
    5
    Medium

    CVE-2007-5318

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in preview.php in TYPOlight webCMS 2.4.6 allows remote attackers to download arbitrary files via the src parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5309

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Published: 9 Oct 2007
    5
    Medium

    CVE-2007-5316

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browsecats.php in Softbiz Jobs and Recruitment Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5314

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in system/funcs/xkurl.php in xKiosk WEB 3.0.1i, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PEARPATH parameter.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5290

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail Pro ASP before 3.4.64, WebMail Lite ASP before 4.0.11, and WebMail Lite PHP before 4.0.22; allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to login.php and the (2) mode2 parameter to default.asp in an advanced_login mode.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5295

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML via the (1) PageContent and (2) PageName parameters.

    Published: 9 Oct 2007
    6.4
    Medium

    CVE-2007-5298

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CMS Creamotion allow remote attackers to execute arbitrary PHP code via a URL in the cfg[document_uri] parameter to (1) _administration/securite.php and (2) _administration/gestion_configurations/save_config.php.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5301

    Last Modified: 23 Apr 2026

    Buffer overflow in the vorbis_stream_info function in input/vorbis/vorbis_engine.c (aka the vorbis input plugin) in AlsaPlayer before 0.99.80-rc3 allows remote attackers to execute arbitrary code via a .OGG file with long comments.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5303

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5292

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory parameter.

    Published: 9 Oct 2007
    2.6
    Low

    CVE-2007-5293

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to error.php and the (2) content parameter to templates/simple/ia.php.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5302

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5308

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Published: 9 Oct 2007
    6.8
    Medium

    CVE-2007-5294

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in core/aural.php in IDMOS 1.0-beta (aka Phoenix) allows remote attackers to execute arbitrary PHP code via a URL in the site_absolute_path parameter.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5296

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in dblisttest.asp in dbList 8.1 allow remote attackers to inject arbitrary web script or HTML via the (1) db, (2) pagesize, (3) sort, (4) strKeyWords, and (5) table parameters. NOTE: some of these details are obtained from third party information.

    Published: 9 Oct 2007
    5
    Medium

    CVE-2007-5300

    Last Modified: 23 Apr 2026

    Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service (daemon crash) via a long USER command that triggers a stack-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Published: 9 Oct 2007
    4.3
    Medium

    CVE-2007-5304

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) repertimage parameter to utilisateurs/vousetesbannis.php, the (2) elseifvotetxtresultatduvote parameter to utilisateurs/votesresultats.php, and the (3) elseifforumtxtmenugeneraleduforum parameter to moduleajouter/depot/adminforum.php.

    Published: 9 Oct 2007
    7.5
    High

    CVE-2007-5305

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c) espaceperso.php, (d) enregistrement.php, (e) commentaire.php, and (f) coeurusr.php in utilisateurs/, and (g) articles/fonctions.php and (h) depot/fonctions.php in moduleajouter/; the (3) corpsdesign parameter to (i) articles/usrarticles.php and (j) depot/usrdepot.php in moduleajouter/; and possibly other files.

    Published: 9 Oct 2007