CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-4713

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd parameters.

    Published: 5 Sept 2007
    10
    Critical

    CVE-2007-4743

    Last Modified: 23 Apr 2026

    The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack.

    Published: 5 Sept 2007
    5
    Medium

    CVE-2007-4665

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to cause a denial of service (daemon crash) via an XNET session that makes multiple simultaneous requests to register events, aka CORE-1403.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4666

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the server in Firebird before 2.0.2, when a Superserver/TCP/IP environment is configured, allows remote attackers to cause a denial of service (CPU and memory consumption) via "large network packets with garbage", aka CORE-1397.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4668

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly obtain other "file access," via unknown vectors, aka CORE-1312.

    Published: 4 Sept 2007
    4
    Medium

    CVE-2007-4669

    Last Modified: 23 Apr 2026

    The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4654

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SSHield 1.6.1 with OpenSSH 3.0.2p1 on Cisco WebNS 8.20.0.1 on Cisco Content Services Switch (CSS) series 11000 devices allows remote attackers to cause a denial of service (connection slot exhaustion and device crash) via a series of large packets designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144), possibly a related issue to CVE-2002-1024.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4655

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4663

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in PHP before 5.2.4 allows attackers to bypass open_basedir restrictions via unspecified vectors involving the glob function.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter in a search action.

    Published: 4 Sept 2007
    2.1
    Low

    CVE-2007-4656

    Last Modified: 23 Apr 2026

    backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4657

    Last Modified: 23 Apr 2026

    Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4664

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the (1) attach database and (2) create database functionality in Firebird before 2.0.2, when a filename exceeds MAX_PATH_LEN, has unknown impact and attack vectors, aka CORE-1405.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4662

    Last Modified: 23 Apr 2026

    Buffer overflow in the php_openssl_make_REQ function in PHP before 5.2.4 has unknown impact and attack vectors.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4667

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Services API in Firebird before 2.0.2 allows remote attackers to cause a denial of service, aka CORE-1149.

    Published: 4 Sept 2007
    10
    Critical

    CVE-2007-3999

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.

    Published: 4 Sept 2007
    8.5
    High

    CVE-2007-4000

    Last Modified: 23 Apr 2026

    The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.

    Published: 4 Sept 2007
    4.4
    Medium

    CVE-2007-4652

    Last Modified: 23 Apr 2026

    The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-3997

    Last Modified: 23 Apr 2026

    The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass safe_mode and open_basedir restrictions via MySQL LOCAL INFILE operations, as demonstrated by a query with LOAD DATA LOCAL INFILE.

    Published: 4 Sept 2007
    6.4
    Medium

    CVE-2007-4650

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4784

    Last Modified: 23 Apr 2026

    The setlocale function in PHP before 5.2.4 allows context-dependent attackers to cause a denial of service (application crash) via a long string in the locale parameter. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless this issue can be demonstrated for code execution.

    Published: 4 Sept 2007
    5
    Medium

    CVE-2007-4782

    Last Modified: 23 Apr 2026

    PHP before 5.2.3 allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the pattern parameter to the glob function; or (2) a long string in the string parameter to the fnmatch function, accompanied by a pattern parameter value with undefined characteristics, as demonstrated by a "*[1]e" value. NOTE: this might not be a vulnerability in most web server environments that support multiple threads, unless these issues can be demonstrated for code execution.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4752

    Last Modified: 23 Apr 2026

    ssh in OpenSSH before 4.7 does not properly handle when an untrusted cookie cannot be created and uses a trusted X11 cookie instead, which allows attackers to violate intended policy and gain privileges by causing an X client to be treated as trusted.

    Published: 4 Sept 2007
    Unknown

    CVE-2007-4721

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6113. Reason: This candidate is a duplicate of CVE-2007-6113. Notes: All CVE users should reference CVE-2007-6113 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 4 Sept 2007
    1.9
    Low

    CVE-2007-3849

    Last Modified: 23 Apr 2026

    Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent attackers to bypass file integrity checks and modify certain files.

    Published: 4 Sept 2007
    7.5
    High

    CVE-2007-4137

    Last Modified: 23 Apr 2026

    Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that triggers a heap-based buffer overflow. NOTE: Qt 4 has the same error in the QUtf8Codec::convertToUnicode function, but it is not exploitable.

    Published: 3 Sept 2007
    7.2
    High

    CVE-2007-4648

    Last Modified: 23 Apr 2026

    The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.

    Published: 31 Aug 2007
    5
    Medium

    CVE-2007-4647

    Last Modified: 23 Apr 2026

    newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.cgi.

    Published: 31 Aug 2007
    4.3
    Medium

    CVE-2007-4633

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.

    Published: 31 Aug 2007
    7.2
    High

    CVE-2007-4649

    Last Modified: 23 Apr 2026

    MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.

    Published: 31 Aug 2007
    6.4
    Medium

    CVE-2007-4645

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2006-1108.

    Published: 31 Aug 2007
    4.3
    Medium

    CVE-2007-4632

    Last Modified: 23 Apr 2026

    Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.

    Published: 31 Aug 2007
    7.5
    High

    CVE-2007-4644

    Last Modified: 23 Apr 2026

    Format string vulnerability in the Cl_GetPackets function in cl_main.c in the client in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote Doomsday servers to execute arbitrary code via format string specifiers in a PSV_CONSOLE_TEXT message.

    Published: 31 Aug 2007
    6.4
    Medium

    CVE-2007-4641

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.

    Published: 31 Aug 2007
    6.4
    Medium

    CVE-2007-4640

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.

    Published: 31 Aug 2007
    9.3
    Critical

    CVE-2007-4634

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.

    Published: 31 Aug 2007
    5
    Medium

    CVE-2007-4643

    Last Modified: 23 Apr 2026

    Integer underflow in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a PKT_CHAT packet with a data length less than 3, which triggers an erroneous malloc, possibly related to the Sv_HandlePacket function in sv_main.c.

    Published: 31 Aug 2007
    10
    Critical

    CVE-2007-4646

    Last Modified: 23 Apr 2026

    Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.

    Published: 31 Aug 2007
    10
    Critical

    CVE-2007-4642

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2) Msg_Write function in net_msg.c, or (3) many commands that are not properly handled by the NetSv_ReadCommands function in d_netsv.c; or (4) cause a denial of service (daemon crash) via a chat (PKT_CHAT) message without a final '\0' character.

    Published: 31 Aug 2007
    4.3
    Medium

    CVE-2007-4638

    Last Modified: 23 Apr 2026

    Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview.

    Published: 31 Aug 2007
    6.4
    Medium

    CVE-2007-4637

    Last Modified: 23 Apr 2026

    xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.

    Published: 31 Aug 2007
    7.5
    High

    CVE-2007-4636

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.

    Published: 31 Aug 2007
    5
    Medium

    CVE-2007-4635

    Last Modified: 23 Apr 2026

    Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Aug 2007
    9.3
    Critical

    CVE-2007-4515

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.

    Published: 31 Aug 2007
    9.3
    Critical

    CVE-2007-2931

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.

    Published: 31 Aug 2007
    10
    Critical

    CVE-2007-2954

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.

    Published: 31 Aug 2007
    6.9
    Medium

    CVE-2007-4631

    Last Modified: 23 Apr 2026

    The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.

    Published: 31 Aug 2007
    4.3
    Medium

    CVE-2007-4630

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 31 Aug 2007
    7.5
    High

    CVE-2007-4629

    Last Modified: 23 Apr 2026

    Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.

    Published: 31 Aug 2007
    7.5
    High

    CVE-2007-4628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Aug 2007