CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-3975

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter in a ptopic action, a different vulnerability than CVE-2005-3412.

    Published: 25 Jul 2007
    4.3
    Medium

    CVE-2007-3977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bwired allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Jul 2007
    4.3
    Medium

    CVE-2007-3978

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in bwired allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 25 Jul 2007
    6.8
    Medium

    CVE-2007-3979

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3984

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChecker allows remote attackers to execute arbitrary code via a long argument to the Scan method. NOTE: this is probably a different issue than CVE-2007-2987.

    Published: 25 Jul 2007
    6.6
    Medium

    CVE-2007-3531

    Last Modified: 23 Apr 2026

    The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3971

    Last Modified: 23 Apr 2026

    Integer overflow in ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted ASPACK packed file, which triggers an infinite loop.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3981

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL commands via the catid parameter in a displaycat action.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3982

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveLayout method.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3983

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveReports 2.0 Professional Edition 2.5.0.1308 (SP5 RC) allows remote attackers to create or overwrite arbitrary files via a full pathname in an argument to the SaveLayout method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jul 2007
    9.3
    Critical

    CVE-2007-3026

    Last Modified: 23 Apr 2026

    Integer overflow in Panda Software AdminSecure allows remote attackers to execute arbitrary code via crafted packets with modified length values to TCP ports 19226 or 19227, resulting in a heap-based buffer overflow.

    Published: 25 Jul 2007
    9.3
    Critical

    CVE-2007-3963

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3967

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHP Directory Lister (dirLIST) before 0.1.1 allows remote attackers to list the contents of a parent directory via a .. (dot dot) in the folder parameter.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3972

    Last Modified: 23 Apr 2026

    ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service via a crafted (1) ASPACK or (2) FSG packed file, which triggers a divide-by-zero error.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3966

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Munch Pro allows remote attackers to execute arbitrary SQL commands via the login field to /admin, a different vulnerability than CVE-2006-5880.

    Published: 25 Jul 2007
    7.6
    High

    CVE-2007-3970

    Last Modified: 23 Apr 2026

    Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.

    Published: 25 Jul 2007
    7.5
    High

    CVE-2007-3976

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the newsID parameter.

    Published: 25 Jul 2007
    10
    Critical

    CVE-2007-3980

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.

    Published: 25 Jul 2007
    6.8
    Medium

    CVE-2007-2953

    Last Modified: 23 Apr 2026

    Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.

    Published: 25 Jul 2007
    5
    Medium

    CVE-2007-3957

    Last Modified: 23 Apr 2026

    Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request with a long URI.

    Published: 24 Jul 2007
    7.1
    High

    CVE-2007-3958

    Last Modified: 23 Apr 2026

    Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certain GIF file, as demonstrated by Art.gif.

    Published: 24 Jul 2007
    9.3
    Critical

    CVE-2007-3960

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM WebSphere Application Server (WAS) before Fix Pack 21 (6.0.2.21) have unknown impact and attack vectors, aka (1) PK33799, or (2) a "Potential security exposure" in the Samples component (PK40213).

    Published: 24 Jul 2007
    6.8
    Medium

    CVE-2007-3955

    Last Modified: 23 Apr 2026

    Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information.

    Published: 24 Jul 2007
    5
    Medium

    CVE-2007-3959

    Last Modified: 23 Apr 2026

    The IM Server (aka IMserve or IMserver) 2.0.5.30 and probably earlier in Ipswitch Instant Messaging before 2.07 in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (daemon crash) via certain data to TCP port 5179 that overwrites a destructor, as reachable by the (1) DoAttachVideoSender, (2) DoAttachVideoReceiver, (3) DoAttachAudioSender, and (4) DoAttachAudioReceiver functions.

    Published: 24 Jul 2007
    7.8
    High

    CVE-2007-3956

    Last Modified: 23 Apr 2026

    TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534.

    Published: 24 Jul 2007
    7.5
    High

    CVE-2007-3951

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Norman Antivirus 5.90 allow remote attackers to execute arbitrary code via a crafted (1) ACE or (2) LZH file, resulting from an "integer cast around."

    Published: 24 Jul 2007
    7.5
    High

    CVE-2007-3952

    Last Modified: 23 Apr 2026

    The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to bypass the malware detection via a crafted DOC file, resulting from an "integer cast around".

    Published: 24 Jul 2007
    4.3
    Medium

    CVE-2007-3953

    Last Modified: 23 Apr 2026

    The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to cause a denial of service via a crafted DOC file that triggers a divide-by-zero error.

    Published: 24 Jul 2007
    4.3
    Medium

    CVE-2007-3954

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking SeaMonkey.exe, a related issue to CVE-2007-3670.

    Published: 24 Jul 2007
    8.3
    High

    CVE-2007-3949

    Last Modified: 23 Apr 2026

    mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.

    Published: 24 Jul 2007
    4.3
    Medium

    CVE-2007-3950

    Last Modified: 23 Apr 2026

    lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.

    Published: 24 Jul 2007
    6.4
    Medium

    CVE-2007-3946

    Last Modified: 23 Apr 2026

    mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.

    Published: 24 Jul 2007
    4.3
    Medium

    CVE-2007-3948

    Last Modified: 23 Apr 2026

    connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.

    Published: 24 Jul 2007
    5.8
    Medium

    CVE-2007-3947

    Last Modified: 23 Apr 2026

    request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.

    Published: 24 Jul 2007
    6.4
    Medium

    CVE-2007-3945

    Last Modified: 23 Apr 2026

    Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.

    Published: 23 Jul 2007
    7.2
    High

    CVE-2007-2950

    Last Modified: 23 Apr 2026

    Centennial Discovery 2006 Feature Pack 1, which is used by (1) Numara Asset Manager 8.0 and (2) Symantec Discovery 6.5, uses insecure permissions on certain directories, which allows local users to gain privileges.

    Published: 23 Jul 2007
    9.3
    Critical

    CVE-2007-3944

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions. NOTE: this issue was originally reported only for MobileSafari on the iPhone. NOTE: it is not clear whether this stems from an issue in the original distribution of PCRE, which might already have a separate CVE identifier.

    Published: 23 Jul 2007
    1.9
    Low

    CVE-2007-4308

    Last Modified: 23 Apr 2026

    The (1) aac_cfg_open and (2) aac_compat_ioctl functions in the SCSI layer ioctl path in aacraid in the Linux kernel before 2.6.23-rc2 do not check permissions for ioctls, which might allow local users to cause a denial of service or gain privileges.

    Published: 23 Jul 2007
    5.8
    Medium

    CVE-2007-2925

    Last Modified: 23 Apr 2026

    The default access control lists (ACL) in ISC BIND 9.4.0, 9.4.1, and 9.5.0a1 through 9.5.0a5 do not set the allow-recursion and allow-query-cache ACLs, which allows remote attackers to make recursive queries and query the cache.

    Published: 23 Jul 2007
    4.3
    Medium

    CVE-2007-2926

    Last Modified: 23 Apr 2026

    ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.

    Published: 23 Jul 2007
    7.8
    High

    CVE-2007-3926

    Last Modified: 23 Apr 2026

    Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an "overwritten destructor."

    Published: 21 Jul 2007
    7.6
    High

    CVE-2007-3928

    Last Modified: 23 Apr 2026

    Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638.

    Published: 21 Jul 2007
    7.5
    High

    CVE-2007-3933

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the CFTOKEN parameter, a different vector than CVE-2006-2053.

    Published: 21 Jul 2007
    6.4
    Medium

    CVE-2007-3936

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote attackers to delete arbitrary files via unspecified filename references in the delfiles parameter.

    Published: 21 Jul 2007
    4.4
    Medium

    CVE-2007-3931

    Last Modified: 23 Apr 2026

    The wrap_setuid_third_party_application function in the installation script for the Samsung SCX-4200 Driver 2.00.95 adds setuid permissions to third party applications such as xsane and xscanimage, which allows local users to gain privileges.

    Published: 21 Jul 2007
    7.5
    High

    CVE-2007-3932

    Last Modified: 23 Apr 2026

    uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit when it detects an attempt to upload a non-JPEG file, which allows remote attackers to upload and execute arbitrary PHP code in the img/ folder.

    Published: 21 Jul 2007
    4.3
    Medium

    CVE-2007-3940

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in QuickerSite 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the svalue parameter in a search action. NOTE: some of these details are obtained from third party information.

    Published: 21 Jul 2007
    4.3
    Medium

    CVE-2007-3941

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile.php in Jasmine CMS 1.0_1 allows remote authenticated users to inject arbitrary web script or HTML via the profile_email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jul 2007
    5.8
    Medium

    CVE-2007-3942

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray are defined before use

    Published: 21 Jul 2007
    7.5
    High

    CVE-2007-3943

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Infinite Responder before 1.48 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 21 Jul 2007