CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2007-3924

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which are inserted into the command line that is created when invoking netscape.exe, a related issue to CVE-2007-3670. NOTE: there has been debate about whether the issue is in Internet Explorer or Netscape. As of 20070713, it is CVE's opinion that IE appears to not properly delimit the URL argument when invoking Netscape; this issue could arise with other protocol handlers in IE.

    Published: 21 Jul 2007
    6.5
    Medium

    CVE-2007-3925

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.

    Published: 21 Jul 2007
    9.3
    Critical

    CVE-2007-3929

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the BitTorrent support in Opera before 9.22 allows user-assisted remote attackers to execute arbitrary code via a crafted header in a torrent file, which leaves a dangling pointer to an invalid object.

    Published: 21 Jul 2007
    4.3
    Medium

    CVE-2007-3930

    Last Modified: 23 Apr 2026

    Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.

    Published: 21 Jul 2007
    7.5
    High

    CVE-2007-3934

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute arbitrary PHP code via a URL in the p_mode parameter.

    Published: 21 Jul 2007
    7.5
    High

    CVE-2007-3938

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a view action in the Topics module, a different vulnerability than CVE-2006-1676.

    Published: 21 Jul 2007
    7.8
    High

    CVE-2007-3923

    Last Modified: 23 Apr 2026

    The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets to port (1) 139 or (2) 445.

    Published: 21 Jul 2007
    9.3
    Critical

    CVE-2007-3935

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 21 Jul 2007
    6.8
    Medium

    CVE-2007-3939

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 21 Jul 2007
    10
    Critical

    CVE-2007-3927

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe."

    Published: 21 Jul 2007
    7.5
    High

    CVE-2007-3937

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Jul 2007
    5
    Medium

    CVE-2007-4045

    Last Modified: 23 Apr 2026

    The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.

    Published: 20 Jul 2007
    5.5
    Medium

    CVE-2008-4302

    Last Modified: 23 Apr 2026

    fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG and system crash), as demonstrated by the fio I/O tool.

    Published: 20 Jul 2007
    4.3
    Medium

    CVE-2007-3910

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bandersnatch 0.4 allows remote attackers to inject arbitrary JavaScript via a Jabber resource name and possibly other data items, which are stored in conversation logs.

    Published: 19 Jul 2007
    5
    Medium

    CVE-2007-3906

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Kaspersky Anti-Virus for Check Point FireWall-1 before Critical Fix 1 (5.5.161.0) might allow attackers to cause a denial of service (kernel hang) via unspecified vectors. NOTE: it is not clear whether there is an attacker role.

    Published: 19 Jul 2007
    4.6
    Medium

    CVE-2007-3908

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP ServiceGuard for Linux for Red Hat Enterprise Linux (RHEL) 2.1 SG A.11.14.04 through A.11.14.06; RHEL 3.0 SG A.11.16.04 through A.11.16.10; and ServiceGuard Cluster Object Manager B.03.01.02 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2007-0980.

    Published: 19 Jul 2007
    7.5
    High

    CVE-2007-3905

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Zoph before 0.7.0.1 might allow remote attackers to execute arbitrary SQL commands via the _order parameter to (1) photos.php and (2) edit_photos.php.

    Published: 19 Jul 2007
    7.5
    High

    CVE-2007-3909

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Bandersnatch 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) date and (2) limit parameters to index.php, and other unspecified vectors.

    Published: 19 Jul 2007
    10
    Critical

    CVE-2007-3907

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in login.pl in LedgerSMB 1.2.0 through 1.2.6 allows remote attackers to bypass authentication and perform certain actions as an arbitrary user via unspecified vectors involving a URL with a redirect parameter value, along with a callback parameter containing an escaped URL that specifies the action.

    Published: 19 Jul 2007
    5
    Medium

    CVE-2007-6304

    Last Modified: 23 Apr 2026

    The federated engine in MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4, when performing a certain SHOW TABLE STATUS query, allows remote MySQL servers to cause a denial of service (federated handler crash and daemon crash) via a response that lacks the minimum required number of columns.

    Published: 19 Jul 2007
    3.5
    Low

    CVE-2007-6303

    Last Modified: 23 Apr 2026

    MySQL 5.0.x before 5.0.51a, 5.1.x before 5.1.23, and 6.0.x before 6.0.4 does not update the DEFINER value of a view when the view is altered, which allows remote authenticated users to gain privileges via a sequence of statements including a CREATE SQL SECURITY DEFINER VIEW statement and an ALTER VIEW statement.

    Published: 19 Jul 2007
    5
    Medium

    CVE-2007-3961

    Last Modified: 23 Apr 2026

    Off-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before 0.9 allows remote attackers to cause a denial of service via a directory entry whose length is exactly MAXNAMELEN, which prevents a terminating null byte from being added.

    Published: 19 Jul 2007
    7.5
    High

    CVE-2007-3962

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in fsplib.c in fsplib before 0.9 might allow remote attackers to execute arbitrary code via (1) a long filename that is not properly handled by the fsp_readdir_native function when MAXNAMLEN is greater than 255, or (2) a long d_name directory (dirent) field in the fsp_readdir function.

    Published: 19 Jul 2007
    7.5
    High

    CVE-2007-3881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3882

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Expert Advisor allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Jul 2007
    4.3
    Medium

    CVE-2007-3886

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in Element CMS allows remote attackers to inject arbitrary web script or HTML via the s parameter in a search pID action.

    Published: 18 Jul 2007
    4.3
    Medium

    CVE-2007-3887

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in mesaj_formu.asp in ASP Ziyaretci Defteri 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Isim, (2) Mesajiniz, and (3) E-posta fields. NOTE: these probably correspond to the isim, mesaj, and posta parameters to save.php.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3889

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified vectors.

    Published: 18 Jul 2007
    6.8
    Medium

    CVE-2006-4183

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Microsoft DirectX SDK (February 2006) and probably earlier, including 9.0c End User Runtimes, allows context-dependent attackers to execute arbitrary code via a crafted Targa file with a run-length-encoding (RLE) compression that produces more data than expected when decoding.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3884

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3268

    Last Modified: 23 Apr 2026

    The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error.

    Published: 18 Jul 2007
    9.3
    Critical

    CVE-2007-3825

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers to execute arbitrary code by sending certain data to unspecified RPC procedures.

    Published: 18 Jul 2007
    4.3
    Medium

    CVE-2007-3885

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in philboard_search.asp in husrevforum 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Jul 2007
    4.3
    Medium

    CVE-2007-3888

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous blog entry, possibly involving the (a) posted_by, (b) subject, and (c) content parameters to index.php; as demonstrated by the onmouseover attribute of certain elements. NOTE: some of these details are obtained from third party information.

    Published: 18 Jul 2007
    5.1
    Medium

    CVE-2007-3883

    Last Modified: 23 Apr 2026

    The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3) SaveMenuUsageData method.

    Published: 18 Jul 2007
    6.5
    Medium

    CVE-2007-3853

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to have unknown impact via (1) DBMS_JAVA_TEST in the JavaVM component (DB01), (2) Oracle Text component (DB09), and (3) MDSYS.SDO_GEOR_INT in the Spatial component (DB15). NOTE: a reliable researcher claims that DB01 is SQL injection in DBMS_PRVTAQIS.

    Published: 18 Jul 2007
    6.5
    Medium

    CVE-2007-3855

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17). NOTE: a reliable researcher claims that DB17 is for using Views to perform unauthorized insert, update, or delete actions.

    Published: 18 Jul 2007
    6.5
    Medium

    CVE-2007-3856

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Data Mining component for Oracle Database 10g Release 2 10.2.0.2 and 10.2.0.3, 10g 10.1.0.5, and Oracle9i Database Release 2 9.2.0.7, 9.2.0.8, and 9.2.0.8DV has unknown impact and remote authenticated attack vectors related to DMSYS.DMP_SYS, aka DB04.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3860

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Express (formerly Oracle HTML DB) 2.2.0.00.32 up to 3.0.0.00.20 allows developers to have an unknown impact via unknown attack vectors, aka APEX01. NOTE: a reliable researcher states that this is SQL injection in the wwv_flow_security.check_db_password function due to insufficient checks for '"' characters.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3861

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Jdeveloper in Oracle Application Server 10.1.2.2 and Collaboration Suite 10.1.2 allows context-dependent attackers to have an unknown impact via custom applications that use JBO.KEY, aka JDEV01.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3862

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Server 9.0.4.3 and 10.1.2.0.2 allows remote attackers to have an unknown impact via Oracle Single Sign On, aka AS01.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3863

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Collaboration Suite 10.1.2, allows context-dependent attackers to have an unknown impact via custom applications that use JBO.SERVER, aka JDEV02.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3864

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10.1.2 have unknown impact and remote attack vectors via (1) Instant Messaging/Presence (OCS01) and (2) Oracle Single Sign On (AS02).

    Published: 18 Jul 2007
    6.5
    Medium

    CVE-2007-3868

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in PeopleTools in Oracle PeopleSoft Enterprise 8.22.15, 8.47.13, 8.48.10, and 8.49.02 allows remote authenticated users or attackers to have an unknown impact via multiple vectors, aka (1) PSE01, (2) PSE02, and (3) PSE03.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3869

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Customer Relationship Management Online Marketing component in Oracle PeopleSoft Enterprise 8.9 Bundle 26 and 9.0 Bundle 7 allow remote authenticated users to have an unknown impact, aka (1) PSE04 and (2) PSE05.

    Published: 18 Jul 2007
    4.6
    Medium

    CVE-2007-3870

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Human Capital Management component in Oracle PeopleSoft Enterprise 8.9 Bundle 11 allow local users to have unknown impact via unknown vectors, aka (1) PSE06 and (2) PSE07.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3858

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 allow remote authenticated users to have an unknown impact via (1) EXFSYS.DBMS_RLMGR_UTL in Rules Manager (DB11) and (2) Program Interface (DB13).

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3866

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 and 12.0.1 allow remote attackers to have an unknown impact via (a) Oracle Configurator (APPS02), (b) Oracle iExpenses (APPS03), (c) Oracle Application Object Library (APPS09), and (1) APPS12, (2) APPS13, and (3) APPS14 in (d) Oracle Payables.

    Published: 18 Jul 2007
    5.5
    Medium

    CVE-2007-3854

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is for a buffer overflow.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3859

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Internet Directory component for Oracle Database 9.2.0.8 and 9.2.0.8DV; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 10.1.2 has unknown impact and remote attack vectors, aka OID01.

    Published: 18 Jul 2007