CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2007-4132

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Red Hat Network Satellite Server 5.0.0 allows remote authenticated users to execute arbitrary code via unknown vectors in a "back-end XMLRPC handler."

    Published: 29 Aug 2007
    6.5
    Medium

    CVE-2007-4639

    Last Modified: 23 Apr 2026

    EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as demonstrated by (1) pldbg_get_stack and (2) pldbg_abort_target, which triggers use of an uninitialized pointer.

    Published: 29 Aug 2007
    7.2
    High

    CVE-2007-4580

    Last Modified: 23 Apr 2026

    Buffer underflow in redlight.sys in BufferZone 2.1 and 2.5 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by sending a small buffer size value to the FsSetVolumeInformation IOCTL handler code with a FsSetDirectoryInformation subcode containing a large buffer.

    Published: 28 Aug 2007
    Unknown

    CVE-2007-4579

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2931. Reason: This candidate is a reservation duplicate of CVE-2007-2931. Notes: All CVE users should reference CVE-2007-2931 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Aug 2007
    7.8
    High

    CVE-2007-4577

    Last Modified: 23 Apr 2026

    Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").

    Published: 28 Aug 2007
    6
    Medium

    CVE-2007-3846

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.

    Published: 28 Aug 2007
    6.8
    Medium

    CVE-2007-4578

    Last Modified: 23 Apr 2026

    Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.

    Published: 28 Aug 2007
    5
    Medium

    CVE-2007-4521

    Last Modified: 23 Apr 2026

    Asterisk Open Source 1.4.5 through 1.4.11, when configured to use an IMAP voicemail storage backend, allows remote attackers to cause a denial of service via an e-mail with an "invalid/corrupted" MIME body, which triggers a crash when the recipient listens to voicemail.

    Published: 28 Aug 2007
    4.3
    Medium

    CVE-2007-4557

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the webacc servlet in Novell GroupWise 6.5 WebAccess allows remote attackers to inject arbitrary web script or HTML via the User.Id parameter, as demonstrated by a URL within a url field in a STYLE element, possibly due to an incomplete fix for CVE-2004-2103.2.

    Published: 28 Aug 2007
    Unknown

    CVE-2007-4558

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4134. Reason: This candidate is a duplicate of CVE-2007-4134. Notes: All CVE users should reference CVE-2007-4134 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Aug 2007
    4.6
    Medium

    CVE-2007-4564

    Last Modified: 23 Apr 2026

    Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges.

    Published: 28 Aug 2007
    6.8
    Medium

    CVE-2006-7222

    Last Modified: 23 Apr 2026

    Buffer overflow in the CFLICStream::_deltachunk function in FLICSource.cpp in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to execute arbitrary code via a crafted FLI file.

    Published: 28 Aug 2007
    6.8
    Medium

    CVE-2007-4556

    Last Modified: 23 Apr 2026

    Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

    Published: 28 Aug 2007
    10
    Critical

    CVE-2007-4561

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the RTSP service in Helix DNA Server before 11.1.4 allows remote attackers to execute arbitrary code via an RSTP command containing multiple Require headers.

    Published: 28 Aug 2007
    4.3
    Medium

    CVE-2007-4562

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi DABroker before 03-02-/D and Cosminexus DABroker before 02-04-/C and 03-05-/E allows remote attackers to cause a denial of service (connection prevention) by sending "data unexpectedly through a port."

    Published: 28 Aug 2007
    4.4
    Medium

    CVE-2007-4563

    Last Modified: 23 Apr 2026

    Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges.

    Published: 28 Aug 2007
    7.6
    High

    CVE-2007-4560

    Last Modified: 23 Apr 2026

    clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."

    Published: 28 Aug 2007
    10
    Critical

    CVE-2007-4566

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.

    Published: 28 Aug 2007
    6.8
    Medium

    CVE-2007-4549

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrary code via an ALPass DB (APW) file containing (1) a long file-key or (2) a "Site Information and Folder entry" with a ciphertext_length value much larger than the plaintext_length value.

    Published: 28 Aug 2007
    7.5
    High

    CVE-2007-4551

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter.

    Published: 28 Aug 2007
    4.3
    Medium

    CVE-2007-4555

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin account.

    Published: 28 Aug 2007
    5
    Medium

    CVE-2007-4565

    Last Modified: 23 Apr 2026

    sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and application crash) by refusing certain warning messages that are sent over SMTP.

    Published: 28 Aug 2007
    5
    Medium

    CVE-2007-4553

    Last Modified: 23 Apr 2026

    The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.

    Published: 28 Aug 2007
    5.1
    Medium

    CVE-2007-4550

    Last Modified: 23 Apr 2026

    Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an fnm field in a folder-name record in an ALPASS DB (APW) file.

    Published: 28 Aug 2007
    4.3
    Medium

    CVE-2007-4554

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7.

    Published: 28 Aug 2007
    7.5
    High

    CVE-2007-4552

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.

    Published: 28 Aug 2007
    6.8
    Medium

    CVE-2007-4545

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) ZIP or (2) RAR archive.

    Published: 27 Aug 2007
    4.3
    Medium

    CVE-2007-4547

    Last Modified: 23 Apr 2026

    Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive with malformed size information in a file header, which might allow user-assisted attackers to obtain sensitive information (memory contents) by reading the extracted files. NOTE: this issue is only a vulnerability if Unreal is run with privileges, or if the extracted files are made accessible to other users.

    Published: 27 Aug 2007
    4.3
    Medium

    CVE-2007-4544

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the weblog_id parameter (Username field).

    Published: 27 Aug 2007
    5.8
    Medium

    CVE-2007-4546

    Last Modified: 23 Apr 2026

    Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to local filenames corresponding to names in Local File Header fields in this archive, which might allow remote attackers to trick a user into performing a dangerous file overwrite or creation.

    Published: 27 Aug 2007
    10
    Critical

    CVE-2007-4548

    Last Modified: 23 Apr 2026

    The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote attackers to bypass authentication requirements, deploy arbitrary modules, and gain administrative access by sending a blank username and password with the command line deployer in the deployment module.

    Published: 27 Aug 2007
    6.8
    Medium

    CVE-2007-4537

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet.

    Published: 27 Aug 2007
    5
    Medium

    CVE-2007-4538

    Last Modified: 23 Apr 2026

    email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Send::Sendmail function, probably involving shell metacharacters.

    Published: 27 Aug 2007
    5
    Medium

    CVE-2007-4539

    Last Modified: 23 Apr 2026

    The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.

    Published: 27 Aug 2007
    4.3
    Medium

    CVE-2007-4542

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in mapserv.c in the mapserv CGI program.

    Published: 27 Aug 2007
    4.3
    Medium

    CVE-2007-4541

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the PHP_SELF variable in modules/core/uim.php and (2) [url] tags in a comment in modules/core/fldm.php.

    Published: 27 Aug 2007
    7.5
    High

    CVE-2007-4540

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute arbitrary SQL commands via the (1) HTTP_REFERER or (2) HTTP_USER_AGENT HTTP header.

    Published: 27 Aug 2007
    4.3
    Medium

    CVE-2007-4543

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form."

    Published: 27 Aug 2007
    7.5
    High

    CVE-2007-4527

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Aug 2007
    4.3
    Medium

    CVE-2007-4528

    Last Modified: 23 Apr 2026

    The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code by loading an arbitrary DLL and calling a function, as demonstrated by kernel32.dll and the WinExec function. NOTE: this issue does not cross privilege boundaries in most contexts, so perhaps it should not be included in CVE.

    Published: 25 Aug 2007
    6.8
    Medium

    CVE-2007-4533

    Last Modified: 23 Apr 2026

    Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a chat message, related to a call to the BroadcastPrintf function.

    Published: 25 Aug 2007
    4.6
    Medium

    CVE-2007-4536

    Last Modified: 23 Apr 2026

    TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to execute arbitrary PHP code by modifying (1) disclaimer.txt, (2) sponsors.txt, and (3) banners.txt, which are used in an include call. NOTE: there might be local attack vectors that extend to other files.

    Published: 25 Aug 2007
    7.5
    High

    CVE-2007-4524

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

    Published: 25 Aug 2007
    8.5
    High

    CVE-2007-4529

    Last Modified: 23 Apr 2026

    The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3) AdminStartServer, and (4) AdminStopServer privileges; and administration of arbitrary virtual servers via a request to a .tscmd URI with a modified serverid parameter, as demonstrated by (a) add_server.tscmd, (b) ask_delete_server.tscmd, (c) start_server.tscmd, and (d) stop_server.tscmd.

    Published: 25 Aug 2007
    5
    Medium

    CVE-2007-4531

    Last Modified: 23 Apr 2026

    Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many 0x07 or other control characters to the file transfer port.

    Published: 25 Aug 2007
    6
    Medium

    CVE-2007-4522

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php. NOTE: some vectors might be reachable through the url and name parameters to (g) admin/navigation/new_nav_item.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

    Published: 25 Aug 2007
    3.5
    Low

    CVE-2007-4523

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php, probably involving the Title or textarea field as reachable through admin/pages/new_page.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

    Published: 25 Aug 2007
    7.5
    High

    CVE-2007-4525

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function

    Published: 25 Aug 2007
    2.1
    Low

    CVE-2007-4526

    Last Modified: 23 Apr 2026

    The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a local file, which allows local users to obtain sensitive information by reading this file.

    Published: 25 Aug 2007
    4.3
    Medium

    CVE-2007-4530

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.

    Published: 25 Aug 2007