CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-3808

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000.

    Published: 17 Jul 2007
    Unknown

    CVE-2007-3802

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-0447. Reason: This candidate is a duplicate of CVE-2007-0447. Notes: All CVE users should reference CVE-2007-0447 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Jul 2007
    Unknown

    CVE-2007-3801

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-3699. Reason: This candidate is a duplicate of CVE-2007-3699. Notes: All CVE users should reference CVE-2007-3699 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Jul 2007
    6
    Medium

    CVE-2007-3800

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Real-time scanner (RTVScan) component in Symantec AntiVirus Corporate Edition 9.0 through 10.1 and Client Security 2.0 through 3.1, when the Notification Message window is enabled, allows local users to gain privileges via crafted code.

    Published: 16 Jul 2007
    5.4
    Medium

    CVE-2007-3805

    Last Modified: 23 Apr 2026

    The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allows remote attackers to cause a denial of service (gateway stop) via certain certificates.

    Published: 16 Jul 2007
    5
    Medium

    CVE-2007-3804

    Last Modified: 23 Apr 2026

    The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.

    Published: 16 Jul 2007
    10
    Critical

    CVE-2007-3803

    Last Modified: 23 Apr 2026

    The SMTP ALG in Clavister CorePlus before 8.80.04, and 8.81.00, does not properly parse SMTP commands in certain circumstances, which allows remote attackers to bypass address blacklists.

    Published: 16 Jul 2007
    7.5
    High

    CVE-2007-3789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Inmostore 4.0 allows remote attackers to execute arbitrary SQL commands via the Password field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Jul 2007
    7.5
    High

    CVE-2007-3787

    Last Modified: 23 Apr 2026

    The eSoft InstaGate EX2 UTM device does not require entry of the old password when changing the admin password, which might allow remote attackers to gain privileges by conducting a CSRF attack, making a password change from an unattended workstation, or other attacks.

    Published: 15 Jul 2007
    4
    Medium

    CVE-2007-3785

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in PGPBBox.dll in EldoS SecureBlackbox (sbb) 5.1.0.112 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Jul 2007
    10
    Critical

    CVE-2007-3794

    Last Modified: 23 Apr 2026

    Buffer overflow in Hitachi Cosminexus V4 through V7, Processing Kit for XML before 20070511, Developer's Kit for Java before 20070312, and third-party products that use this software, allows attackers to have an unknown impact via certain GIF images, related to use of GIF image processing APIs by a Java application.

    Published: 15 Jul 2007
    4.3
    Medium

    CVE-2007-3792

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/.

    Published: 15 Jul 2007
    5.8
    Medium

    CVE-2007-3790

    Last Modified: 23 Apr 2026

    The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial of service via a long argument.

    Published: 15 Jul 2007
    7.5
    High

    CVE-2007-3791

    Last Modified: 23 Apr 2026

    Buffer overflow in the w_read function in sockets.c in Cami Sardinha and Nigel Kukard policyd before 1.81 for Postfix allows remote attackers to cause a denial of service and possibly execute arbitrary code via long SMTP commands. NOTE: some of these details are obtained from third party information.

    Published: 15 Jul 2007
    4.3
    Medium

    CVE-2007-3014

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in activeWeb contentserver before 5.6.2964 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) errors/rights.asp or (2) errors/transaction.asp, or (3) the name of a MIME type (mimetype).

    Published: 15 Jul 2007
    4.3
    Medium

    CVE-2007-3784

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Belkin G Plus Router F5D7231-4 with firmware 4.05.03 allows remote attackers to inject arbitrary web script or HTML via a hostname of a DHCP client.

    Published: 15 Jul 2007
    7.6
    High

    CVE-2007-3788

    Last Modified: 23 Apr 2026

    The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document.

    Published: 15 Jul 2007
    7.5
    High

    CVE-2007-3793

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Job Management Partner 1/NETM/DM (JP1/NETM/DM) Manager on Windows before 20070413 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jul 2007
    7.1
    High

    CVE-2007-3795

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi TP1/Server Base before 03-05-/P, 05-00-x before 05-00-/G, 05-01-x before 05-01-/A, and 05-02-x before 05-02-/C on HP-UX 11.0 through 11i v3 allows attackers to cause a denial of service by sending certain data to a port.

    Published: 15 Jul 2007
    6.5
    Medium

    CVE-2007-3013

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in activeWeb contentserver before 5.6.2964 allows remote authenticated users with edit permission to execute arbitrary SQL commands via the id parameter to admin/picture/picture_real_edit.asp, and probably other unspecified vectors.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-3786

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer

    Published: 15 Jul 2007
    7.8
    High

    CVE-2007-3774

    Last Modified: 23 Apr 2026

    Dvbbs 7.1.0 SP1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Data/Dvbbs7.mdb.

    Published: 15 Jul 2007
    7.5
    High

    CVE-2007-3783

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in enVivo!CMS allows remote attackers to execute arbitrary SQL commands via the ID parameter in an article action. NOTE: this is probably different from CVE-2005-1413.4.

    Published: 15 Jul 2007
    5
    Medium

    CVE-2007-3776

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.

    Published: 15 Jul 2007
    7.8
    High

    CVE-2007-3775

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allows remote attackers to cause a denial of service (loss of cluster services) via unspecified vectors, aka (1) CSCsj09859 and (2) CSCsj19985.

    Published: 15 Jul 2007
    5.5
    Medium

    CVE-2006-4169

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the G/PGP (GPG) Plugin 2.0, and 2.1dev before 20070614, for Squirrelmail allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the help parameter to (1) gpg_help.php or (2) gpg_help_base.php.

    Published: 15 Jul 2007
    10
    Critical

    CVE-2006-5278

    Last Modified: 23 Apr 2026

    Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.

    Published: 15 Jul 2007
    4.6
    Medium

    CVE-2007-3771

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. NOTE: the original vendor advisory referenced CVE-2006-3456, but this was an error.

    Published: 15 Jul 2007
    6.4
    Medium

    CVE-2007-3772

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-3773

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.

    Published: 15 Jul 2007
    7.2
    High

    CVE-2007-3777

    Last Modified: 23 Apr 2026

    avg7core.sys 7.5.0.444 in Grisoft AVG Anti-Virus 7.5.448 and Free Edition 7.5.446, provides an internal function that copies data to an arbitrary address, which allows local users to gain privileges via arbitrary address arguments to a function provided by the 0x5348E004 IOCTL for the generic DeviceIoControl handler.

    Published: 15 Jul 2007
    7.5
    High

    CVE-2007-3778

    Last Modified: 23 Apr 2026

    The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the messageSignedText parameter to the gpg_check_sign_pgp_mime function in gpg_hook_functions.php. NOTE: a parameter value can be set in the contents of an e-mail message.

    Published: 15 Jul 2007
    4.3
    Medium

    CVE-2007-3779

    Last Modified: 23 Apr 2026

    PHP local file inclusion vulnerability in gpg_pop_init.php in the G/PGP (GPG) Plugin before 20070707 for Squirrelmail allows remote attackers to include and execute arbitrary local files, related to the MOD parameter.

    Published: 15 Jul 2007
    6.9
    Medium

    CVE-2007-3673

    Last Modified: 23 Apr 2026

    Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in an IOCTL 0x83022323 request to \\symTDI\, which results in memory overwrite.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-2397

    Last Modified: 23 Apr 2026

    QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2006-5277

    Last Modified: 23 Apr 2026

    Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-2392

    Last Modified: 23 Apr 2026

    Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption.

    Published: 15 Jul 2007
    4.3
    Medium

    CVE-2007-2402

    Last Modified: 23 Apr 2026

    QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets.

    Published: 15 Jul 2007
    5.8
    Medium

    CVE-2007-3769

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account.

    Published: 15 Jul 2007
    7.8
    High

    CVE-2007-3770

    Last Modified: 23 Apr 2026

    The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-2393

    Last Modified: 23 Apr 2026

    The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-2394

    Last Modified: 23 Apr 2026

    Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation.

    Published: 15 Jul 2007
    10
    Critical

    CVE-2007-2417

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.

    Published: 15 Jul 2007
    9.3
    Critical

    CVE-2007-2396

    Last Modified: 23 Apr 2026

    The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets.

    Published: 15 Jul 2007
    4.3
    Medium

    CVE-2007-3645

    Last Modified: 23 Apr 2026

    archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a NULL pointer dereference, a different issue than CVE-2007-3644.

    Published: 15 Jul 2007
    8.5
    High

    CVE-2007-3768

    Last Modified: 23 Apr 2026

    The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.

    Published: 15 Jul 2007
    4.9
    Medium

    CVE-2007-3731

    Last Modified: 23 Apr 2026

    The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in %cs (the xcs field) during ptrace single-step operations, which allows local users to cause a denial of service (NULL dereference and OOPS) via certain code that makes ptrace PTRACE_SETREGS and PTRACE_SINGLESTEP requests, related to the TRACE_IRQS_ON function, and possibly related to the arch_ptrace function.

    Published: 15 Jul 2007
    2.6
    Low

    CVE-2007-3820

    Last Modified: 23 Apr 2026

    konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.

    Published: 14 Jul 2007
    9.3
    Critical

    CVE-2007-3641

    Last Modified: 23 Apr 2026

    archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR archive that triggers a buffer overflow.

    Published: 14 Jul 2007
    4.3
    Medium

    CVE-2007-3644

    Last Modified: 23 Apr 2026

    archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.

    Published: 14 Jul 2007