CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2007-4532

    Last Modified: 23 Apr 2026

    Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address.

    Published: 25 Aug 2007
    4.3
    Medium

    CVE-2007-4535

    Last Modified: 23 Apr 2026

    The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within a certain UDP packet that triggers an assertion error.

    Published: 25 Aug 2007
    7.5
    High

    CVE-2007-4534

    Last Modified: 23 Apr 2026

    Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a chat message and possibly (2) a long name field.

    Published: 25 Aug 2007
    9.8
    Critical

    CVE-2007-4559

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

    Published: 24 Aug 2007
    6.8
    Medium

    CVE-2007-4829

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.

    Published: 24 Aug 2007
    Unknown

    CVE-2007-1356

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 23 Aug 2007
    7.5
    High

    CVE-2007-4502

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

    Published: 23 Aug 2007
    7.5
    High

    CVE-2007-4503

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid parameter.

    Published: 23 Aug 2007
    5
    Medium

    CVE-2007-4504

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action.

    Published: 23 Aug 2007
    7.5
    High

    CVE-2007-4505

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.

    Published: 23 Aug 2007
    7.5
    High

    CVE-2007-4509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did parameter in a details action.

    Published: 23 Aug 2007
    5
    Medium

    CVE-2007-4511

    Last Modified: 23 Apr 2026

    The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener services to enable all protocols and ciphers after the services are restarted, possibly allowing remote attackers to bypass intended policy.

    Published: 23 Aug 2007
    6.8
    Medium

    CVE-2007-4499

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in output.php in American Financing eMail Image Upload 4.1 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Aug 2007
    6.8
    Medium

    CVE-2007-4507

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrary code via long arguments to the (1) ntuser_getuserlist, (2) ntuser_getuserinfo, (3) ntuser_getusergroups, or (4) ntuser_getdomaincontroller functions.

    Published: 23 Aug 2007
    4.3
    Medium

    CVE-2007-4510

    Last Modified: 23 Apr 2026

    ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI, which triggers a NULL dereference in the cli_html_normalise function in libclamav/htmlnorm.c. NOTE: some of these details are obtained from third party information.

    Published: 23 Aug 2007
    7.8
    High

    CVE-2007-4498

    Last Modified: 23 Apr 2026

    The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a certain SIP INVITE message followed by a certain "SIP/2.0 183 Session Progress" message.

    Published: 23 Aug 2007
    6.9
    Medium

    CVE-2007-4501

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PassphraseRequester in SSHKeychain before 0.8.2 beta allows attackers to obtain sensitive information (passwords) via unknown vectors, related to "poor protection."

    Published: 23 Aug 2007
    6.8
    Medium

    CVE-2007-4508

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.

    Published: 23 Aug 2007
    6.9
    Medium

    CVE-2007-4500

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in TunnelRunner in SSHKeychain before 0.8.2 beta, and possibly later versions, allows local users to gain privileges via unspecified vectors.

    Published: 23 Aug 2007
    7.5
    High

    CVE-2007-4506

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an offer_view action.

    Published: 23 Aug 2007
    10
    Critical

    CVE-2007-4493

    Last Modified: 23 Apr 2026

    eZ publish before 3.8.9, and 3.9 before 3.9.3, does not properly check permissions on module views that lack a policy function, which has unknown impact and attack vectors, as demonstrated by a vulnerability in the discount functionality in the shop module.

    Published: 23 Aug 2007
    5
    Medium

    CVE-2007-4494

    Last Modified: 23 Apr 2026

    The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.

    Published: 23 Aug 2007
    4.9
    Medium

    CVE-2007-4495

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ata disk driver in Sun Solaris 10 on the x86 platform before 20070821 allows local users to cause a denial of service (system panic) via an unspecified ioctl function, aka Bug 6433124.

    Published: 23 Aug 2007
    7.5
    High

    CVE-2007-4491

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in uyeler2.php in Gurur haber 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Aug 2007
    6.8
    Medium

    CVE-2007-2958

    Last Modified: 23 Apr 2026

    Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.

    Published: 23 Aug 2007
    4.9
    Medium

    CVE-2007-4492

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the ata disk driver in Sun Solaris 8, 9, and 10 on the x86 platform before 20070821 allow local users to cause a denial of service (system panic) via unspecified ioctl functions, aka Bug 6433123.

    Published: 23 Aug 2007
    5
    Medium

    CVE-2007-4477

    Last Modified: 23 Apr 2026

    The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4478

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6.0 and 7 allows user-assisted remote attackers to inject arbitrary web script or HTML in the local zone via a URI, when the document at the associated URL is saved to a local file, which then contains the URI string along with the document's original content.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4479

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4480

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the Sirius 1.0 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 22 Aug 2007
    6.8
    Medium

    CVE-2007-4485

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in visitor.php in Butterfly online visitors counter 1.08, when used with certain older versions of PHP with improper SERVER superglobal handling, allows remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter. NOTE: it could be argued that this vulnerability is caused by a problem in PHP and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in Butterfly online visitors counter.

    Published: 22 Aug 2007
    7.5
    High

    CVE-2007-4486

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) styl[top], (2) url_eintrag, or (3) styl[themen] parameter.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4487

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision Power Board (IPB or IP.Board) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4488

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Siemens Gigaset SE361 WLAN router with firmware 1.00.0 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI immediately following the filename for (1) a GIF filename, which triggers display of the GIF file in text format and an unspecified denial of service (crash); or (2) the login.tri filename, which triggers a continuous loop of the browser attempting to visit the login page.

    Published: 22 Aug 2007
    6.8
    Medium

    CVE-2007-4489

    Last Modified: 23 Apr 2026

    Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary code via a long Username argument to the ReInit method.

    Published: 22 Aug 2007
    6.9
    Medium

    CVE-2007-3873

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in vstlib32.dll 1.2.0.1012 in the SSAPI Engine 5.0.0.1066 through 5.2.0.1012 in Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security 2007 15.0 through 15.3, when the Venus Spy Trap (VST) feature is enabled, allows local users to cause a denial of service (service crash) or execute arbitrary code via a file with a long pathname, which triggers the overflow during a ReadDirectoryChangesW callback notification.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4483

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the WordPress Classic 1.5 theme in WordPress before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 22 Aug 2007
    10
    Critical

    CVE-2007-4218

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the ServerProtect service (SpntSvc.exe) in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allow remote attackers to execute arbitrary code via certain RPC requests to certain TCP ports that are processed by the (1) RPCFN_ENG_NewManualScan, (2) RPCFN_ENG_TimedNewManualScan, and (3) RPCFN_SetComputerName functions in (a) StRpcSrv.dll; the (4) RPCFN_CMON_SetSvcImpersonateUser and (5) RPCFN_OldCMON_SetSvcImpersonateUser functions in (b) Stcommon.dll; the (6) RPCFN_ENG_TakeActionOnAFile and (7) RPCFN_ENG_AddTaskExportLogItem functions in (c) Eng50.dll; the (8) NTF_SetPagerNotifyConfig function in (d) Notification.dll; or the (9) RPCFN_CopyAUSrc function in the (e) ServerProtect Agent service.

    Published: 22 Aug 2007
    7.5
    High

    CVE-2007-4484

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in login.php in My_REFERER 1.08 allows remote attackers to execute arbitrary PHP code via a URL in the value parameter.

    Published: 22 Aug 2007
    10
    Critical

    CVE-2007-4219

    Last Modified: 23 Apr 2026

    Integer overflow in the RPCFN_SYNC_TASK function in StRpcSrv.dll, as used by the ServerProtect service (SpntSvc.exe), in Trend Micro ServerProtect for Windows before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a certain integer field in a request packet to TCP port 5168, which triggers a heap-based buffer overflow.

    Published: 22 Aug 2007
    10
    Critical

    CVE-2007-4490

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in EarthAgent.exe in Trend Micro ServerProtect 5.58 for Windows before Security Patch 4 allow remote attackers to have an unknown impact via certain RPC function calls to (1) RPCFN_EVENTBACK_DoHotFix or (2) CMD_CHANGE_AGENT_REGISTER_INFO.

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4481

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 22 Aug 2007
    4.3
    Medium

    CVE-2007-4482

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 22 Aug 2007
    5
    Medium

    CVE-2007-4455

    Last Modified: 23 Apr 2026

    The SIP channel driver (chan_sip) in Asterisk Open Source 1.4.x before 1.4.11, AsteriskNOW before beta7, Asterisk Appliance Developer Kit 0.x before 0.8.0, and s800i (Asterisk Appliance) 1.x before 1.0.3 allows remote attackers to cause a denial of service (memory exhaustion) via a SIP dialog that causes a large number of history entries to be created.

    Published: 22 Aug 2007
    9.3
    Critical

    CVE-2007-3618

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a "long invalid subcmd."

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4456

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.

    Published: 21 Aug 2007
    6.4
    Medium

    CVE-2007-4457

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in forumreply.php in Dalai Forum 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the chemin parameter.

    Published: 21 Aug 2007
    4.3
    Medium

    CVE-2007-4461

    Last Modified: 23 Apr 2026

    NuFW 2.2.3, and certain other versions after 2.0, allows remote attackers to bypass time-based packet filtering rules via certain "out of period" choices of packet transmission time.

    Published: 21 Aug 2007
    3.3
    Low

    CVE-2007-4462

    Last Modified: 23 Apr 2026

    lib/Locale/Po4a/Po.pm in po4a before 0.32 allows local users to overwrite arbitrary files via a symlink attack on the gettextization.failed.po temporary file.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4463

    Last Modified: 23 Apr 2026

    The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.

    Published: 21 Aug 2007