CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-3865

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Customer Intelligence component in Oracle E-Business Suite 12.0.1 has unknown impact and remote attack vectors, aka APPS01.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3867

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and attack vectors, related to (1) APPS04, (2) APPS05, and (3) APPS06 in (a) Oracle Application Object Library, (4) APPS07 in Oracle Customer Intelligence, (5) APPS08 in Oracle Payments, (7) APPS10 in Oracle Human Resources, and (8) APPS11 in iRecruitment.

    Published: 18 Jul 2007
    6.5
    Medium

    CVE-2007-3857

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 allow remote authenticated users to have an unknown impact via (a) the Oracle Text component, including (1) unspecified vectors (DB05), (2) CTXSYS.DRVXMD (DB06), (3) CTXSYS.DRI_MOVE_CTXSYS (DB07), (4) CTXSYS.DRVXMD (DB08), and (b) JavaVM (DB14).

    Published: 18 Jul 2007
    5
    Medium

    CVE-2007-3765

    Last Modified: 23 Apr 2026

    The STUN implementation in Asterisk 1.4.x before 1.4.8, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted STUN length attribute in a STUN packet sent on an RTP port.

    Published: 18 Jul 2007
    7.5
    High

    CVE-2007-3564

    Last Modified: 23 Apr 2026

    libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allows remote attackers to bypass certain access restrictions.

    Published: 18 Jul 2007
    9.3
    Critical

    CVE-2007-3762

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to execute arbitrary code by sending a long (1) voice or (2) video RTP frame.

    Published: 18 Jul 2007
    5
    Medium

    CVE-2007-3763

    Last Modified: 23 Apr 2026

    The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.

    Published: 18 Jul 2007
    5
    Medium

    CVE-2007-3764

    Last Modified: 23 Apr 2026

    The Skinny channel driver (chan_skinny) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a certain data length value in a crafted packet, which results in an "overly large memcpy."

    Published: 18 Jul 2007
    9.3
    Critical

    CVE-2007-3738

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.

    Published: 18 Jul 2007
    9.3
    Critical

    CVE-2007-3737

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."

    Published: 18 Jul 2007
    9.3
    Critical

    CVE-2007-3735

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.

    Published: 18 Jul 2007
    4.3
    Medium

    CVE-2007-3736

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

    Published: 18 Jul 2007
    9.3
    Critical

    CVE-2007-3734

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.

    Published: 18 Jul 2007
    6.8
    Medium

    CVE-2007-3922

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

    Published: 18 Jul 2007
    7.6
    High

    CVE-2007-3796

    Last Modified: 23 Apr 2026

    The password reset feature in the Spam Quarantine HTTP interface for MailMarshal SMTP 6.2.0.x before 6.2.1 allows remote attackers to modify arbitrary account information via a UserId variable with a large amount of trailing whitespace followed by a malicious value, which triggers SQL buffer truncation due to length inconsistencies between variables.

    Published: 17 Jul 2007
    9.3
    Critical

    CVE-2007-3832

    Last Modified: 23 Apr 2026

    Buffer overflow in the AOL Instant Messenger (AIM) protocol handler in AIM.DLL in Cerulean Studios Trillian allows remote attackers to execute arbitrary code via a malformed aim: URI, as demonstrated by a long URI beginning with the aim:///#1111111/ substring.

    Published: 17 Jul 2007
    5
    Medium

    CVE-2007-3833

    Last Modified: 23 Apr 2026

    The AOL Instant Messenger (AIM) protocol handler in Cerulean Studios Trillian allows remote attackers to create files with arbitrary contents via certain aim: URIs, as demonstrated by a URI that begins with the "aim: &c:\" substring and contains a full pathname in the ini field. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 17 Jul 2007
    4.3
    Medium

    CVE-2007-3834

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ex Libris ALEPH allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a URL that can be discovered through a keyword search. NOTE: this may be related to the MetaLib XSS issue, CVE-2007-3835.

    Published: 17 Jul 2007
    7.8
    High

    CVE-2007-3837

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in HydraIRC 0.3.151 allows remote IRC servers to cause a denial of service (application crash) via a long CTCP request message containing '%' (percent) characters.

    Published: 17 Jul 2007
    4
    Medium

    CVE-2007-3839

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 010306 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Jul 2007
    4.3
    Medium

    CVE-2007-3842

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise Filter before 2.0.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this may be the same as CVE-2007-2970.

    Published: 17 Jul 2007
    2.6
    Low

    CVE-2007-3838

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3840

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL commands via the offset parameter.

    Published: 17 Jul 2007
    9
    Critical

    CVE-2007-3841

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Pidgin (formerly Gaim) 2.0.2 for Linux allows remote authenticated users, who are listed in a users list, to execute certain commands via unspecified vectors, aka ZD-00000035. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 17 Jul 2007
    7.8
    High

    CVE-2007-3836

    Last Modified: 23 Apr 2026

    Format string vulnerability in HydraIRC 0.3.151 allows remote attackers to cause a denial of service via format string specifiers in certain data related to failed DCC file transfer negotiation.

    Published: 17 Jul 2007
    9.3
    Critical

    CVE-2007-3826

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 on Windows XP SP2 allows remote attackers to prevent users from leaving a site, spoof the address bar, and conduct phishing and other attacks via repeated document.open function calls after a user requests a new page, but before the onBeforeUnload function is called.

    Published: 17 Jul 2007
    5
    Medium

    CVE-2007-3827

    Last Modified: 23 Apr 2026

    Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

    Published: 17 Jul 2007
    9.3
    Critical

    CVE-2007-3831

    Last Modified: 23 Apr 2026

    PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 17 Jul 2007
    9.3
    Critical

    CVE-2007-3829

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in (a) InterActual Player 2.60.12.0717 and (b) Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via a (1) long FailURL attribute in the IAMCE ActiveX Control (IAMCE.dll) or a (2) long URLCode attribute in the IAKey ActiveX Control (IAKey.dll). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Jul 2007
    10
    Critical

    CVE-2007-3828

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in mDNSResponder in Apple Mac OS X allows remote attackers to execute arbitrary code via unspecified vectors, a related issue to CVE-2007-2386.

    Published: 17 Jul 2007
    3.5
    Low

    CVE-2007-3830

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter.

    Published: 17 Jul 2007
    4.3
    Medium

    CVE-2007-3817

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the LoginToboggan module 4.7.x-1.0, 4.7.x-1.x-dev, and 5.x-1.x-dev before 20070712 for Drupal, when configured to display a "Log out" link, allows remote attackers to inject arbitrary web script or HTML via a crafted username. NOTE: Drupal sanitizes the username by removing certain characters, so this might not be a vulnerability on default installations.

    Published: 17 Jul 2007
    3.5
    Low

    CVE-2007-3818

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission to inject arbitrary JavaScript and gain privileges via "the message displayed above the default user login block."

    Published: 17 Jul 2007
    5
    Medium

    CVE-2007-3819

    Last Modified: 23 Apr 2026

    Opera 9.21 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.

    Published: 17 Jul 2007
    7.8
    High

    CVE-2007-3823

    Last Modified: 23 Apr 2026

    The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string to port 5151/udp.

    Published: 17 Jul 2007
    10
    Critical

    CVE-2007-3824

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands via the katID parameter.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3821

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Webcit before 7.11 allows remote attackers to modify configurations and perform other actions as arbitrary users via unspecified vectors.

    Published: 17 Jul 2007
    2.6
    Low

    CVE-2007-3822

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Webcit before 7.11 allow remote attackers to inject arbitrary web script or HTML via (1) the who parameter to showuser; and other vectors involving (2) calendar mode, (3) bulletin board mode, (4) room names, and (5) uploaded file names.

    Published: 17 Jul 2007
    6.8
    Medium

    CVE-2007-3806

    Last Modified: 23 Apr 2026

    The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter, probably related to memory corruption or an invalid read on win32 platforms, and possibly related to lack of initialization for a glob structure.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3816

    Last Modified: 23 Apr 2026

    JWIG might allow context-dependent attackers to cause a denial of service (service degradation) via loops of references to external templates. NOTE: this issue has been disputed by multiple third parties who state that only the application developer can trigger the issue, so no privilege boundaries are crossed. However, it seems possible that this is a vulnerability class to which an JWIG application may be vulnerable if template contents can be influenced, but this would be an issue in the application itself, not JWIG

    Published: 17 Jul 2007
    4.9
    Medium

    CVE-2007-3815

    Last Modified: 23 Apr 2026

    Buffer overflow in pirs32.exe in Poslovni informator Republike Slovenije (PIRS) 2007 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long search string in certain fields in the GUI. NOTE: this may cross privilege boundaries if PIRS is used by data-entry workers who do not have full access to the underlying Windows environment.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3814

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.

    Published: 17 Jul 2007
    2.6
    Low

    CVE-2007-3807

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.

    Published: 17 Jul 2007
    4
    Medium

    CVE-2007-3017

    Last Modified: 23 Apr 2026

    The WYSIWYG editor applet in activeWeb contentserver CMS before 5.6.2964 only filters malicious tags from articles sent to admin/applets/wysiwyg/rendereditor.asp, which allows remote authenticated users to inject arbitrary JavaScript via a request to admin/worklist/worklist_edit.asp.

    Published: 17 Jul 2007
    4
    Medium

    CVE-2007-3018

    Last Modified: 23 Apr 2026

    activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3809

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action to directory.php, and other unspecified vectors.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3810

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3811

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php or (2) the name parameter to page.php.

    Published: 17 Jul 2007
    7.5
    High

    CVE-2007-3812

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL commands via the f parameter in a forums action to index.php.

    Published: 17 Jul 2007
    4.3
    Medium

    CVE-2007-3813

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH parameter.

    Published: 17 Jul 2007