CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-4464

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to spoof the information in the Image File Header tab via strings with CRLF sequences in the IMAGE_EXPORT_DIRECTORY array in a PE file, which could complicate forensics investigations.

    Published: 21 Aug 2007
    7.1
    High

    CVE-2007-4459

    Last Modified: 23 Apr 2026

    Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages.

    Published: 21 Aug 2007
    7.2
    High

    CVE-2007-4460

    Last Modified: 23 Apr 2026

    The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4458

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/class/class_tpl.php in Firesoft allows remote attackers to execute arbitrary PHP code via a URL in the cache_file parameter.

    Published: 21 Aug 2007
    6.8
    Medium

    CVE-2007-4454

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in environment.php in Olate Download (od) 3.4.1 allows context-dependent attackers to execute arbitrary code via a crafted version string, as referenced by the (1) PDO::ATTR_SERVER_VERSION or (2) PDO::ATTR_CLIENT_VERSION attribute.

    Published: 21 Aug 2007
    4.3
    Medium

    CVE-2007-4453

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8 allow remote attackers to inject arbitrary web code or HTML via the (1) s parameter to index.php, and the (2) q parameter to (a) faq.php, (b) member.php, (c) memberlist.php, (d) calendar.php, (e) search.php, (f) forumdisplay.php, (g) showgroups.php, (h) online.php, and (i) sendmessage.php. NOTE: these issues have been disputed by the vendor, stating "I can't reproduce a single one of these". The researcher is known to be unreliable

    Published: 21 Aug 2007
    7.1
    High

    CVE-2007-4213

    Last Modified: 23 Apr 2026

    Palm OS on Treo 650, 680, 700p, and 755p Smart phones allows remote attackers to cause a denial of service (device reset or hang) via a flood of large ICMP echo requests. NOTE: this is probably a different vulnerability than CVE-2003-0293.

    Published: 21 Aug 2007
    7.2
    High

    CVE-2007-4216

    Last Modified: 23 Apr 2026

    vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.

    Published: 21 Aug 2007
    4
    Medium

    CVE-2007-5093

    Last Modified: 23 Apr 2026

    The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.

    Published: 21 Aug 2007
    6.8
    Medium

    CVE-2007-4134

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in extract.c in star before 1.5a84 allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4440

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.

    Published: 21 Aug 2007
    4.6
    Medium

    CVE-2007-4441

    Last Modified: 23 Apr 2026

    Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attackers to execute arbitrary code via a long string in the filename argument to the win_browse_file function.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4442

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4446

    Last Modified: 23 Apr 2026

    Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the NICK command (client nickname) when entering a game.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4448

    Last Modified: 23 Apr 2026

    The server in Toribash 2.71 and earlier does not properly handle partially joined clients that are temporarily assigned the ID of -1, which allows remote attackers to cause a denial of service (daemon crash) via a GRIP command with the ID of -1.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4449

    Last Modified: 23 Apr 2026

    The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (application hang) via a command without an LF character, as demonstrated by a SAY command.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4439

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4451

    Last Modified: 23 Apr 2026

    The server in Toribash 2.71 and earlier on Windows allows remote attackers to cause a denial of service (continuous beep and server hang) via certain commands that contain many 0x07 or other invalid characters.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4443

    Last Modified: 23 Apr 2026

    The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and possibly other unspecified vectors.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4444

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Image Space rFactor 1.250 and earlier allow remote attackers to execute arbitrary code via a packet with ID (1) 0x80 or (2) 0x88 to UDP port 34297, related to the buffer containing the server version number.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4445

    Last Modified: 23 Apr 2026

    Image Space rFactor 1.250 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) an ID 0x30 packet, (2) an ID 0x38 packet, and an invalid 13-bit integer in (3) an ID 0x60 packet and (4) an ID 0x68 packet; and a denial of service (UDP port block) via (5) an ID 0x20 packet and (6) an ID 0x28 packet.

    Published: 21 Aug 2007
    7.5
    High

    CVE-2007-4447

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the client in Toribash 2.71 and earlier allow remote attackers to (1) execute arbitrary code via a long game command in a replay (.rpl) file and (2) cause a denial of service (application crash) via a long SAY command that omits a required LF character; and allow remote Toribash servers to execute arbitrary code via (3) a long game command and (4) a long SAY command that omits a required LF character.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4450

    Last Modified: 23 Apr 2026

    The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients without a required LF character, as demonstrated by a SAY command. NOTE: the security impact of this violation is not clear, although it probably makes exploitation of CVE-2007-4449 easier.

    Published: 21 Aug 2007
    5
    Medium

    CVE-2007-4452

    Last Modified: 23 Apr 2026

    The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (disconnection) via a long (1) emote or (2) SPEC command.

    Published: 21 Aug 2007
    6.8
    Medium

    CVE-2007-4438

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 20 Aug 2007
    5
    Medium

    CVE-2007-4436

    Last Modified: 23 Apr 2026

    The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote attackers to (1) obtain sensitive via the Tracker Module and the Recent posts page; (2) obtain project names via unspecified vectors; (3) obtain sensitive information via the statistics pages; and (4) read CVS project activity.

    Published: 20 Aug 2007
    6.8
    Medium

    CVE-2007-4437

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albums.php in Ampache before 3.3.3.5 allows remote attackers to execute arbitrary SQL commands via the match parameter. NOTE: some details are obtained from third party information.

    Published: 20 Aug 2007
    7.5
    High

    CVE-2007-4435

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2) account-settings.php, and possibly (3) backend/functions.php.

    Published: 20 Aug 2007
    6.8
    Medium

    CVE-2007-4431

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript frame hijacking."

    Published: 20 Aug 2007
    4.6
    Medium

    CVE-2007-4432

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the wrapper scripts for the (1) rug, (2) zen-updater, (3) zen-installer, and (4) zen-remover programs on SUSE Linux 10.1 and Enterprise 10 allows local users to gain privileges via modified (a) LD_LIBRARY_PATH and (b) MONO_GAC_PREFIX environment variables.

    Published: 20 Aug 2007
    4.3
    Medium

    CVE-2007-4433

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in textfilesearch.aspx in the Text File Search ASP.NET edition allows remote attackers to inject arbitrary web script or HTML via the search field.

    Published: 20 Aug 2007
    4.3
    Medium

    CVE-2007-4434

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 20 Aug 2007
    5
    Medium

    CVE-2007-4430

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

    Published: 20 Aug 2007
    3.5
    Low

    CVE-2007-4427

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote authenticated users to modify data on a server, related to encoding of certain parameter values by this redirection logic, aka MAK2116.

    Published: 20 Aug 2007
    6.8
    Medium

    CVE-2007-4428

    Last Modified: 23 Apr 2026

    Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-2006-4116.

    Published: 20 Aug 2007
    5
    Medium

    CVE-2007-4429

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via unknown vectors related to sending long URIs, as claimed to be actively exploited on 20070817 using a "call to a specific number." NOTE: this identifier is for the en.securitylab.ru disclosure. According to the vendor, this issue is separate from the "sign-on issues" that reduced Skype service on 20070817, which appears to be a site-specific problem. As of 20070821, it is not clear whether this issue is simply a symptom of the larger sign-on problem.

    Published: 20 Aug 2007
    3.5
    Low

    CVE-2007-0437

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in csp/samples/; and allow remote authenticated users to inject arbitrary web script or HTML via (4) the ERROR parameter to csp/samples/xmlclasseserror.csp, and unspecified vectors in (5) object.csp and (6) lotteryhistory.csp in csp/samples/.

    Published: 20 Aug 2007
    6
    Medium

    CVE-2007-4425

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Live for Speed (LFS) demo, S1, and S2 allow remote authenticated users to (1) cause a denial of service (server crash) and probably execute arbitrary code via an ID 3 packet with a long nickname field, and (2) cause a denial of service (server crash) via an ID 10 packet containing a long string corresponding to an unavailable track.

    Published: 20 Aug 2007
    5
    Medium

    CVE-2007-4426

    Last Modified: 23 Apr 2026

    Live for Speed (LFS) S1 and S2 allows remote attackers to cause a denial of service (server crash) via (1) a certain 0x00 byte in a pre-login ID 3 packet, which triggers a NULL dereference; or (2) a pre-login ID 5 packet that lacks certain strings, which triggers an invalid pointer dereference.

    Published: 20 Aug 2007
    4.3
    Medium

    CVE-2007-4424

    Last Modified: 23 Apr 2026

    Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribute of an OBJECT element. NOTE: it could be argued that this is not a vulnerability because a dangerous file is not actually launched, but as of 2007, it is generally accepted that web browsers should prompt users before saving dangerous content.

    Published: 18 Aug 2007
    6.9
    Medium

    CVE-2007-4270

    Last Modified: 23 Apr 2026

    Multiple race conditions in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain root privileges via a symlink attack on certain files.

    Published: 18 Aug 2007
    2.1
    Low

    CVE-2007-4271

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE: this issue might be related to symlink following.

    Published: 18 Aug 2007
    6.9
    Medium

    CVE-2007-4275

    Last Modified: 23 Apr 2026

    Multiple untrusted search path vulnerabilities in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allow local users to gain privileges via certain vectors related to (1) DB2 instance or FMP startup on Linux and Solaris; (2) exec of executables while running as root on non-Windows systems, as demonstrated by AIX; and unspecified vectors involving (3) db2licm and (4) db2pd.

    Published: 18 Aug 2007
    6.9
    Medium

    CVE-2007-4276

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows attackers to execute arbitrary code via a long DASPROF and possibly other environment variables, which are copied into the buildDasPaths buffer.

    Published: 18 Aug 2007
    6.8
    Medium

    CVE-2007-4399

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the xmms.bx 1.0 script for BitchX allows user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

    Published: 18 Aug 2007
    6.8
    Medium

    CVE-2007-4401

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

    Published: 18 Aug 2007
    6.8
    Medium

    CVE-2007-4402

    Last Modified: 23 Apr 2026

    Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.

    Published: 18 Aug 2007
    6.8
    Medium

    CVE-2007-4398

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

    Published: 18 Aug 2007
    7.5
    High

    CVE-2007-4406

    Last Modified: 23 Apr 2026

    ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS), which allows remote attackers to gain control of a channel during a split.

    Published: 18 Aug 2007
    5
    Medium

    CVE-2007-4408

    Last Modified: 23 Apr 2026

    ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a netjoin by causing a bounce while a server with an older version of the channel is linking.

    Published: 18 Aug 2007