CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-5048

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Lhaplus before 1.55 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive.

    Published: 24 Sept 2007
    4.3
    Medium

    CVE-2007-5051

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PhpGedView 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) box_width, (2) PEDIGREE_GENERATIONS, and (3) rootid parameters in ancestry.php, and the (4) newpid parameter in timeline.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Sept 2007
    4.6
    Medium

    CVE-2007-5042

    Last Modified: 23 Apr 2026

    Outpost Firewall Pro 4.0.1025.7828 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteFile, (3) NtLoadDriver, (4) NtOpenProcess, (5) NtOpenSection, (6) NtOpenThread, and (7) NtUnloadDriver kernel SSDT hooks, a partial regression of CVE-2006-7160.

    Published: 24 Sept 2007
    Unknown

    CVE-2007-5049

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-3387. Reason: This candidate is a duplicate of CVE-2007-3387. Notes: All CVE users should reference CVE-2007-3387 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Sept 2007
    6.9
    Medium

    CVE-2007-4993

    Last Modified: 23 Apr 2026

    pygrub (tools/pygrub/src/GrubConf.py) in Xen 3.0.3, when booting a guest domain, allows local users with elevated privileges in the guest domain to execute arbitrary commands in domain 0 via a crafted grub.conf file whose contents are used in exec statements.

    Published: 22 Sept 2007
    5
    Medium

    CVE-2007-4991

    Last Modified: 23 Apr 2026

    The SOCKS4 Proxy in Microsoft Internet Security and Acceleration (ISA) Server 2004 SP1 and SP2 allows remote attackers to obtain potentially sensitive information (the destination IP address of another user's session) via an empty packet.

    Published: 21 Sept 2007
    2.1
    Low

    CVE-2007-5024

    Last Modified: 23 Apr 2026

    EMC VMware Server before 1.0.4 Build 56528 writes passwords in cleartext to unspecified log files, which allows local users to obtain sensitive information by reading these files, a different vulnerability than CVE-2005-3620.

    Published: 21 Sept 2007
    9.3
    Critical

    CVE-2007-5025

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in EMC VMware ACE before 1.0.3 Build 54075 allows attackers to have an unknown impact via an unspecified manipulation of "images stored in virtual machines downloaded by the user."

    Published: 21 Sept 2007
    5
    Medium

    CVE-2007-5030

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Dibbler 0.6.0 allow remote attackers to cause a denial of service (daemon crash) via packets containing options with large lengths, which trigger attempts at excessive memory allocation, as demonstrated by (1) the TSrvMsg constructor in SrvMessages/SrvMsg.cpp; the (2) TClntMsg, (3) TClntOptIAAddress, (4) TClntOptIAPrefix, (5) TOptVendorSpecInfo, and (6) TOptOptionRequest constructors; and the (7) TRelIfaceMgr::decodeRelayRepl, (8) TRelMsg::decodeOpts, and (9) TSrvIfaceMgr::decodeRelayForw methods.

    Published: 21 Sept 2007
    5
    Medium

    CVE-2007-5031

    Last Modified: 23 Apr 2026

    The TSrvOptIA_NA::rebind method in SrvOptions/SrvOptIA_NA.cpp in Dibbler 0.6.0 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via an invalid IA_NA option in a REBIND message.

    Published: 21 Sept 2007
    5.1
    Medium

    CVE-2007-5032

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_radminsuper parameters.

    Published: 21 Sept 2007
    4.3
    Medium

    CVE-2007-5033

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows remote attackers to inject arbitrary web script or HTML via the selfdes parameter in a profile_info editprofile action.

    Published: 21 Sept 2007
    5.5
    Medium

    CVE-2007-4497

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows users with login access to a guest operating system to cause a denial of service (guest outage and host process crash or hang) via unspecified vectors.

    Published: 21 Sept 2007
    4.3
    Medium

    CVE-2007-5027

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.

    Published: 21 Sept 2007
    10
    Critical

    CVE-2007-0063

    Last Modified: 23 Apr 2026

    Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.

    Published: 21 Sept 2007
    6.5
    Medium

    CVE-2007-4496

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows authenticated users with administrative privileges on a guest operating system to corrupt memory and possibly execute arbitrary code on the host operating system via unspecified vectors.

    Published: 21 Sept 2007
    6.9
    Medium

    CVE-2007-5023

    Last Modified: 23 Apr 2026

    Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075, and Server before 1.0.4 Build 56528 allows local users to gain privileges via unspecified vectors, possibly involving a malicious "program.exe" file in the C: folder.

    Published: 21 Sept 2007
    7.5
    High

    CVE-2007-5028

    Last Modified: 23 Apr 2026

    Dibbler 0.6.0 on Linux uses weak world-writable permissions for unspecified files in /var/lib/dibbler, which has unknown impact and local attack vectors.

    Published: 21 Sept 2007
    5
    Medium

    CVE-2007-5029

    Last Modified: 23 Apr 2026

    Dibbler 0.6.0 does not verify that certain length parameters are appropriate for buffer sizes, which allows remote attackers to trigger a buffer over-read and cause a denial of service (daemon crash), as demonstrated by incorrect behavior of the TSrvMsg constructor in SrvMessages/SrvMsg.cpp when (1) reading the option code and option length and (2) parsing options.

    Published: 21 Sept 2007
    10
    Critical

    CVE-2007-0061

    Last Modified: 23 Apr 2026

    The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."

    Published: 21 Sept 2007
    5
    Medium

    CVE-2007-5026

    Last Modified: 23 Apr 2026

    dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb.

    Published: 21 Sept 2007
    5
    Medium

    CVE-2007-5022

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2, when using "server-initiated prompted scheduling," allows remote attackers to read a client's data, aka IC53616.

    Published: 21 Sept 2007
    Unknown

    CVE-2007-5021

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4880. Reason: This candidate is a duplicate of CVE-2007-4880. Notes: All CVE users should reference CVE-2007-4880 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Sept 2007
    9.3
    Critical

    CVE-2007-5020

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.

    Published: 21 Sept 2007
    7.2
    High

    CVE-2007-4573

    Last Modified: 23 Apr 2026

    The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.

    Published: 21 Sept 2007
    9
    Critical

    CVE-2007-5008

    Last Modified: 23 Apr 2026

    The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.

    Published: 20 Sept 2007
    6.8
    Medium

    CVE-2007-5009

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before 20070922, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 20 Sept 2007
    4.3
    Medium

    CVE-2007-5010

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebBatch allows remote attackers to inject arbitrary web script or HTML via the URL to webbatch.exe.

    Published: 20 Sept 2007
    6.8
    Medium

    CVE-2007-5015

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to execute arbitrary PHP code via a URL in the sl_theme_unix_path parameter to (1) admin_footer.php, (2) info_footer.php, (3) theme_footer.php, (4) browse_footer.php, (5) account_footer.php, or (6) search_footer.php in core/theme/includes/. NOTE: the vulnerability is present only when the administrator does not follow installation instructions about the requirement for .htaccess Limit support.

    Published: 20 Sept 2007
    7.5
    High

    CVE-2007-5016

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter.

    Published: 20 Sept 2007
    5
    Medium

    CVE-2007-5017

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method.

    Published: 20 Sept 2007
    4.3
    Medium

    CVE-2007-5013

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Phormer 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) u, (2) p, (3) c, and (4) s parameters, and other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Sept 2007
    4.3
    Medium

    CVE-2007-5012

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to inject arbitrary web script or HTML via the author parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Sept 2007
    10
    Critical

    CVE-2007-5019

    Last Modified: 23 Apr 2026

    Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attackers to have an unknown impact via a long argument to the dnsResolve (isInstalled.dnsResolve) method.

    Published: 20 Sept 2007
    7.5
    High

    CVE-2007-5014

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in pSlash 0.70 allow remote attackers to execute arbitrary PHP code via a URL in (1) the lvc_admin_dir parameter to modules/visitors2/admin/view-archiver.inc.php or (2) the lvc_include_dir parameter to modules/visitors2/include/menus.inc.php. NOTE: the modules/visitors2/include/config.inc.php vector is already covered by CVE-2006-4373. NOTE: vector 1 is disputed by CVE because PHP encounters a fatal instantiation error on a direct request for the file, before reaching the include statement.

    Published: 20 Sept 2007
    6
    Medium

    CVE-2007-5018

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211.

    Published: 20 Sept 2007
    5
    Medium

    CVE-2007-5011

    Last Modified: 23 Apr 2026

    webbatch.exe in WebBatch allows remote attackers to obtain sensitive information via the dumpinputdata parameter.

    Published: 20 Sept 2007
    7.2
    High

    CVE-2007-5191

    Last Modified: 23 Apr 2026

    mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

    Published: 20 Sept 2007
    7.5
    High

    CVE-2007-4984

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Ktauber.com StylesDemo mod for phpBB 2.0.xx allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Published: 19 Sept 2007
    10
    Critical

    CVE-2007-4983

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call.

    Published: 19 Sept 2007
    6.8
    Medium

    CVE-2007-3286

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 19 Sept 2007
    7.5
    High

    CVE-2007-4827

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502.

    Published: 19 Sept 2007
    4.3
    Medium

    CVE-2007-4975

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter.

    Published: 19 Sept 2007
    4.3
    Medium

    CVE-2007-4981

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the save function in Obedit 3.03 allows user-assisted remote attackers to inject arbitrary web script or HTML via unknown vectors, as demonstrated by a SCRIPT element in an unspecified context when saving a document. NOTE: because the details of the attack are uncertain, it is unclear whether this crosses privilege boundaries.

    Published: 19 Sept 2007
    10
    Critical

    CVE-2007-4982

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information.

    Published: 19 Sept 2007
    3.5
    Low

    CVE-2007-4977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.

    Published: 19 Sept 2007
    4.3
    Medium

    CVE-2007-4980

    Last Modified: 23 Apr 2026

    The readRequest method in org/gcaldaemon/core/http/HTTPListener.java in GCALDaemon 1.0-beta13 allows remote attackers to cause a denial of service via a large integer value in the Content-Length HTTP header, which triggers a fatal Java OutOfMemoryError.

    Published: 19 Sept 2007
    7.5
    High

    CVE-2007-4979

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a different module than CVE-2007-4956.2.

    Published: 19 Sept 2007
    6.5
    Medium

    CVE-2007-4976

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.

    Published: 19 Sept 2007
    7.5
    High

    CVE-2007-4978

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) Decoder.php and (2) Encoder.php in WBXML/.

    Published: 19 Sept 2007