CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-4025

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-4026

    Last Modified: 23 Apr 2026

    epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information.

    Published: 26 Jul 2007
    6.6
    Medium

    CVE-2007-4027

    Last Modified: 23 Apr 2026

    Buffer overflow in cli32 in Areca CLI 1.72.250 and earlier might allow local users to gain privileges via a long argument. NOTE: this program is not setuid by default, but there are some usage scenarios in which an administrator might make it setuid.

    Published: 26 Jul 2007
    7.5
    High

    CVE-2007-4028

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4023

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login CGI program in Aruba Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier FIPS versions, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4022

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4024

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in W1L3D4_aramasonuc.asp in W1L3D4 Philboard 0.3 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4020

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in login.php in AdMan 1.0.20051202 FF 3 patch and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.

    Published: 26 Jul 2007
    7.5
    High

    CVE-2007-3566

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 before SP2 allows remote attackers to execute arbitrary code via a long size value in a create request to port 3050/tcp.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-4018

    Last Modified: 23 Apr 2026

    Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.

    Published: 26 Jul 2007
    Unknown

    CVE-2007-4015

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-0011. Reason: This candidate is a duplicate of CVE-2007-0011. Notes: All CVE users should reference CVE-2007-0011 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4014

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jul 2007
    7.6
    High

    CVE-2007-4017

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators.

    Published: 26 Jul 2007
    9.3
    Critical

    CVE-2007-4013

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 have unknown impact and attack vectors, possibly related to buffer overflows. NOTE: vector 3 might overlap CVE-2007-3679.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-4016

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-4006

    Last Modified: 23 Apr 2026

    Buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 has unknown impact and remote attack vectors, aka ZD-00000034. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 26 Jul 2007
    9.3
    Critical

    CVE-2007-3302

    Last Modified: 23 Apr 2026

    The CallCode ActiveX control in caller.dll 3.0 before 20070713, and 3.0 SP1 before 3.0.5.81, in CA (formerly Computer Associates) eTrust Intrusion Detection allows remote attackers to load arbitrary DLLs on a client system, and execute code from these DLLs, via unspecified "scriptable functions."

    Published: 26 Jul 2007
    5
    Medium

    CVE-2007-4005

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the shell port (514/tcp). NOTE: this might overlap CVE-2007-4006.

    Published: 26 Jul 2007
    9.3
    Critical

    CVE-2007-4009

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the thisdir parameter.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-4010

    Last Modified: 23 Apr 2026

    The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote attackers to execute arbitrary commands via the win_shell_execute function.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4065

    Last Modified: 23 Apr 2026

    lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.

    Published: 26 Jul 2007
    9.3
    Critical

    CVE-2007-4007

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-4029

    Last Modified: 23 Apr 2026

    libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service via (1) an invalid mapping type, which triggers an out-of-bounds read in the vorbis_info_clear function in info.c, and (2) invalid blocksize values that trigger a segmentation fault in the read function in block.c.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-4066

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the _psy_noiseguards_8 array.

    Published: 26 Jul 2007
    5.5
    Medium

    CVE-2007-6716

    Last Modified: 23 Apr 2026

    fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

    Published: 26 Jul 2007
    9.3
    Critical

    CVE-2007-0060

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain Unicenter products, allows remote attackers to execute arbitrary code via a crafted message to TCP port 3104.

    Published: 26 Jul 2007
    6.8
    Medium

    CVE-2007-3106

    Last Modified: 23 Apr 2026

    lib/info.c in libvorbis 1.1.2, and possibly other versions before 1.2.0, allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via invalid (1) blocksize_0 and (2) blocksize_1 values, which trigger a "heap overwrite" in the _01inverse function in res0.c. NOTE: this issue has been RECAST so that CVE-2007-4029 handles additional vectors.

    Published: 26 Jul 2007
    4.3
    Medium

    CVE-2007-3875

    Last Modified: 23 Apr 2026

    arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.

    Published: 26 Jul 2007
    7.5
    High

    CVE-2007-4008

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter.

    Published: 26 Jul 2007
    7.1
    High

    CVE-2007-4011

    Last Modified: 23 Apr 2026

    Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software before 3.2 20070727, 4.0 before 20070727, and 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (traffic amplification or ARP storm) via a crafted unicast ARP request that (1) has a destination MAC address unknown to the Layer-2 infrastructure, aka CSCsj69233; or (2) occurs during Layer-3 roaming across IP subnets, aka CSCsj70841.

    Published: 26 Jul 2007
    7.1
    High

    CVE-2007-4012

    Last Modified: 23 Apr 2026

    Cisco 4100 and 4400, Airespace 4000, and Catalyst 6500 and 3750 Wireless LAN Controller (WLC) software 4.1 before 4.1.180.0 allows remote attackers to cause a denial of service (ARP storm) via a broadcast ARP packet that "targets the IP address of a known client context", aka CSCsj50374.

    Published: 26 Jul 2007
    7.5
    High

    CVE-2007-4033

    Last Modified: 23 Apr 2026

    Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent attackers to execute arbitrary code via a long FileName parameter. NOTE: this issue was originally reported to be in the imagepsloadfont function in php_gd2.dll in the gd (PHP_GD2) extension in PHP 5.2.3.

    Published: 26 Jul 2007
    Unknown

    CVE-2007-5645

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-5645. Reason: This candidate is a duplicate of CVE-2006-5645, due to a typo. Notes: All CVE users should reference CVE-2006-5645 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3986

    Last Modified: 23 Apr 2026

    file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.

    Published: 25 Jul 2007
    4.3
    Medium

    CVE-2007-3991

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cv.asp in Asp cvmatik 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz (Ady), (2) Soyadiniz (Soyady), (3) Ehliyet, (4) Askerlik, and (5) GSM parameters; and possibly other unspecified vectors.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3992

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vir_login.asp in iExpress Property Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the Username parameter is covered by CVE-2006-6029. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jul 2007
    10
    Critical

    CVE-2007-3993

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.

    Published: 25 Jul 2007
    6.8
    Medium

    CVE-2007-3988

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3985

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to download arbitrary files via a .. (dot dot) in the name parameter.

    Published: 25 Jul 2007
    4.3
    Medium

    CVE-2007-3989

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in default.asp in Dora Emlak 1.0, when the goster parameter is set to iletisim, allow remote attackers to inject arbitrary web script or HTML via the (1) Adiniz and (2) Soyadiniz parameters; and possibly other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3990

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Dora Emlak 1.0, when the goster parameter is set to emlakdetay, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3987

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SearchResults.asp in ImageRacer 1.0, when WordSearchCrit is enabled, allows remote attackers to execute arbitrary SQL commands via the SearchWord parameter.

    Published: 25 Jul 2007
    4.3
    Medium

    CVE-2007-3383

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SendMailServlet in the examples web application (examples/jsp/mail/sendmail.jsp) in Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.36 allows remote attackers to inject arbitrary web script or HTML via the From field and possibly other fields, related to generation of error messages.

    Published: 25 Jul 2007
    4.3
    Medium

    CVE-2007-3679

    Last Modified: 23 Apr 2026

    The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3964

    Last Modified: 23 Apr 2026

    Itaka before 0.2.1, when using Authentication mode, allows remote attackers to bypass authentication and obtain sensitive information by downloading screenshots via a direct request for /screenshot.

    Published: 25 Jul 2007
    6.8
    Medium

    CVE-2007-3965

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in uFMOD before 1.2.5 has unknown impact and attack vectors, possibly related to malformed files, and possibly an integer signedness error for relative note instruments.

    Published: 25 Jul 2007
    5.3
    Medium

    CVE-2007-3968

    Last Modified: 23 Apr 2026

    index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name.

    Published: 25 Jul 2007
    9.3
    Critical

    CVE-2007-3969

    Last Modified: 23 Apr 2026

    Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from an "Integer Cast Around."

    Published: 25 Jul 2007
    6.8
    Medium

    CVE-2007-3973

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3974

    Last Modified: 23 Apr 2026

    admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accounts via modified mot and droit parameters.

    Published: 25 Jul 2007