CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-5241

    Last Modified: 23 Apr 2026

    Buffer overflow in NET$CSMACD.EXE in HP OpenVMS 8.3 and earlier allows local users to cause a denial of service (machine crash) via the "MCR MCL SHOW CSMA-CD Port * All" command, which overwrites a Non-Paged Pool Packet.

    Published: 6 Oct 2007
    4.3
    Medium

    CVE-2007-5242

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in (1) SYS$EI1000.EXE and (2) SYS$EI1000_MON.EXE in HP OpenVMS 8.3 and earlier allows remote attackers to cause a denial of service (machine crash) via an "oversize" packet, which is not properly discarded if "the device has no remaining buffers after receipt of the first buffer segment."

    Published: 6 Oct 2007
    5.4
    Medium

    CVE-2007-5236

    Last Modified: 23 Apr 2026

    Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.

    Published: 6 Oct 2007
    6.9
    Medium

    CVE-2007-5377

    Last Modified: 23 Apr 2026

    The (1) tramp-make-temp-file and (2) tramp-make-tramp-temp-file functions in Tramp 2.1.10 extension for Emacs, and possibly earlier 2.1.x versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 6 Oct 2007
    4.3
    Medium

    CVE-2007-5235

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject arbitrary web script or HTML via the f_email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Oct 2007
    7.5
    High

    CVE-2007-5230

    Last Modified: 23 Apr 2026

    admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.

    Published: 5 Oct 2007
    4.6
    Medium

    CVE-2007-5231

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.

    Published: 5 Oct 2007
    7.5
    High

    CVE-2007-5233

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.

    Published: 5 Oct 2007
    7.5
    High

    CVE-2007-5234

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers to execute arbitrary PHP code via a URL in the level parameter.

    Published: 5 Oct 2007
    6.4
    Medium

    CVE-2007-5229

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url and (2) feedburner_comments_url parameters.

    Published: 5 Oct 2007
    3.5
    Low

    CVE-2007-5228

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the subscription functionality in the Project issue tracking module before 4.7.x-1.5, 4.7.x-2.x before 4.7.x-2.5, and 5.x-1.x before 5.x-1.1 for Drupal allows remote authenticated users with project create or edit permissions to inject arbitrary web script or HTML via unspecified vectors involving a (1) individual or (2) overview form.

    Published: 5 Oct 2007
    4.3
    Medium

    CVE-2007-5227

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing a client-side security mechanism that attempts to block XSS sequences.

    Published: 5 Oct 2007
    4.3
    Medium

    CVE-2007-3918

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.

    Published: 5 Oct 2007
    Unknown

    CVE-2007-4989

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4568. Reason: This candidate is a reservation duplicate of CVE-2007-4568. Notes: All CVE users should reference CVE-2007-4568 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Oct 2007
    5
    Medium

    CVE-2007-5226

    Last Modified: 23 Apr 2026

    irc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a NULL pointer dereference, as demonstrated using a blank /me message from irssi.

    Published: 5 Oct 2007
    9.3
    Critical

    CVE-2007-0447

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.

    Published: 5 Oct 2007
    9.3
    Critical

    CVE-2007-3699

    Last Modified: 23 Apr 2026

    The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.

    Published: 5 Oct 2007
    6.4
    Medium

    CVE-2007-5219

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method.

    Published: 5 Oct 2007
    6.8
    Medium

    CVE-2007-5217

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Oct 2007
    4.3
    Medium

    CVE-2007-5218

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 5 Oct 2007
    7.5
    High

    CVE-2007-5222

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQL commands via a "Firefox ID=" substring in a Referer HTTP header.

    Published: 5 Oct 2007
    6.8
    Medium

    CVE-2007-5224

    Last Modified: 23 Apr 2026

    inc/exif.inc.php in Original Photo Gallery 0.11.2 and earlier allows remote attackers to execute arbitrary programs via the exif_prog parameter, which is specified in an exec function call.

    Published: 5 Oct 2007
    4.9
    Medium

    CVE-2007-5225

    Last Modified: 23 Apr 2026

    Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl.

    Published: 5 Oct 2007
    7.5
    High

    CVE-2007-5220

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters.

    Published: 5 Oct 2007
    6.8
    Medium

    CVE-2007-5223

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified impact, related to incorrect input validation or other defects involving (1) admin/backupstart.php, (2) a .sql filename under admin/admin/dump/, (3) a .sql filename in the fl parameter to admin/downloadbackup.php, and (4) a .. (dot dot) in the fl parameter to admin/downloadbackup.php.

    Published: 5 Oct 2007
    4.3
    Medium

    CVE-2007-5078

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager allow remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied input" to (1) center.exe or (2) Index.exe.

    Published: 5 Oct 2007
    6.8
    Medium

    CVE-2007-5221

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the form parameter.

    Published: 5 Oct 2007
    5
    Medium

    CVE-2008-2829

    Last Modified: 23 Apr 2026

    php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c legacy routine buffer overflow" error message, related to the rfc822_write_address function.

    Published: 5 Oct 2007
    9.3
    Critical

    CVE-2007-5209

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DriveLock.exe in CenterTools DriveLock 5.0 allows remote attackers to execute arbitrary code via a long HTTP request to TCP port 6061. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Oct 2007
    6
    Medium

    CVE-2007-5210

    Last Modified: 23 Apr 2026

    Arbor Networks Peakflow SP before 3.5.1 patch 14, and 3.6.x before 3.6.1 patch 5, allows remote authenticated users to bypass access restrictions and read or write unspecified data via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Oct 2007
    6.8
    Medium

    CVE-2007-5216

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in eArk (e-Ark) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in (1) the cfg_vcard_path parameter to src/vcard_inc.php or (2) the cfg_phpmailer_path parameter to src/email_inc.php. NOTE: the ark_inc.php vector is already covered by CVE-2006-6086.

    Published: 4 Oct 2007
    6.8
    Medium

    CVE-2007-5215

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Jacob Hinkle GodSend 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the SCRIPT_DIR parameter to (1) gtk/main.inc.php or (2) cmdline.inc.php. NOTE: vector 2 is disputed by CVE because it is contained in unaccessible code, requiring that two undefined constants be equal.

    Published: 4 Oct 2007
    4.3
    Medium

    CVE-2007-5211

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Arbor Networks Peakflow SP 3.5.1 before patch 14, and 3.6.1 before patch 5, when scope accounts are enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving GET or POST requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Oct 2007
    9.3
    Critical

    CVE-2007-5213

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_MailServer1 parameter to ServerManager.srv and (2) a hostname change through the conf_Network_HostName parameter on the Network page.

    Published: 4 Oct 2007
    4.3
    Medium

    CVE-2007-5214

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to the default URI associated with a directory, as demonstrated by (a) the root directory and (b) the view/ directory; (2) parameters associated with saved settings, as demonstrated by (c) the conf_Network_HostName parameter on the Network page and (d) the conf_Layout_OwnTitle parameter to ServerManager.srv; and (3) the query string to ServerManager.srv, which is displayed on the logs page. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings.

    Published: 4 Oct 2007
    9.3
    Critical

    CVE-2007-4673

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045.

    Published: 4 Oct 2007
    4.3
    Medium

    CVE-2007-5212

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware before 2.43 allow remote attackers to inject arbitrary web script or HTML via (1) parameters associated with saved settings, as demonstrated by the conf_SMTP_MailServer1 parameter to ServerManager.srv; or (2) the subpage parameter to wizard/first/wizard_main_first.shtml. NOTE: an attacker can leverage a CSRF vulnerability to modify saved settings.

    Published: 4 Oct 2007
    3.3
    Low

    CVE-2007-5207

    Last Modified: 23 Apr 2026

    guilt 0.27 allows local users to overwrite arbitrary files via a symlink attack on a guilt.log.[PID] temporary file.

    Published: 4 Oct 2007
    6.9
    Medium

    CVE-2007-5194

    Last Modified: 23 Apr 2026

    The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain root privileges.

    Published: 4 Oct 2007
    4.6
    Medium

    CVE-2007-5201

    Last Modified: 23 Apr 2026

    The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its arguments.

    Published: 4 Oct 2007
    5
    Medium

    CVE-2007-5193

    Last Modified: 23 Apr 2026

    The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{RCS}{WorkAreaDir}) under the web document root, which might allow remote attackers to obtain sensitive information when .htaccess restrictions are not applied.

    Published: 4 Oct 2007
    2.6
    Low

    CVE-2007-5274

    Last Modified: 23 Apr 2026

    Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.

    Published: 4 Oct 2007
    6.8
    Medium

    CVE-2007-5173

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter.

    Published: 3 Oct 2007
    7.5
    High

    CVE-2007-5174

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the do parameter.

    Published: 3 Oct 2007
    6.8
    Medium

    CVE-2007-5175

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary PHP code via a URL in the BaseCfg[BaseDir] parameter.

    Published: 3 Oct 2007
    4.3
    Medium

    CVE-2007-5179

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in iletisim.asp in Y&K Iletisim Formu allow remote attackers to inject arbitrary web script or HTML via the (1) ad, (2) sehir, (3) yas, (4) cins, (5) tel, (6) mail, and (7) mesaj parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Oct 2007
    7.5
    High

    CVE-2007-5181

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detay.asp in Netkamp Emlak Scripti allows remote attackers to execute arbitrary SQL commands via the ilan_id parameter.

    Published: 3 Oct 2007
    4.3
    Medium

    CVE-2007-5182

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mail.asp in Netkamp Emlak Scripti allows remote attackers to inject arbitrary web script or HTML via the (1) Email parameter, and possibly the (2) Ad, (3) Soyad, (4) Konu, and (5) Mesaj parameters to iletisim.asp.

    Published: 3 Oct 2007
    4.3
    Medium

    CVE-2007-5183

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mailbox.mws in OdysseySuite, possibly 4.0.729, allows remote attackers to inject arbitrary web script or HTML via the idkey parameter.

    Published: 3 Oct 2007
    7.5
    High

    CVE-2007-5180

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ohesa Emlak Portali allow remote attackers to execute arbitrary SQL commands via the (1) Kategori parameter in satilik.asp and the (2) Emlak parameter in detay.asp.

    Published: 3 Oct 2007