CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-3727

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Webmatic before 2.7 have unknown impact and attack vectors, related to the "administration area."

    Published: 12 Jul 2007
    5
    Medium

    CVE-2007-3730

    Last Modified: 23 Apr 2026

    The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 does not log the source IP address or attempted username for login attempts, which might help remote attackers to avoid identification.

    Published: 12 Jul 2007
    5
    Medium

    CVE-2007-3729

    Last Modified: 23 Apr 2026

    The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid POP usernames.

    Published: 12 Jul 2007
    5
    Medium

    CVE-2007-3728

    Last Modified: 23 Apr 2026

    Buffer overflow in lib/silcclient/client_notify.c of SILC Client and SILC Toolkit before 1.1.2 allows remote attackers to cause a denial of service via "NICK_CHANGE" notifications.

    Published: 12 Jul 2007
    4.3
    Medium

    CVE-2007-3725

    Last Modified: 23 Apr 2026

    The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.

    Published: 12 Jul 2007
    4.3
    Medium

    CVE-2007-3726

    Last Modified: 23 Apr 2026

    Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.

    Published: 12 Jul 2007
    2.1
    Low

    CVE-2007-3721

    Last Modified: 23 Apr 2026

    The ULE process scheduler in the FreeBSD kernel gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

    Published: 12 Jul 2007
    2.1
    Low

    CVE-2007-3719

    Last Modified: 23 Apr 2026

    The process scheduler in the Linux kernel 2.6.16 gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

    Published: 12 Jul 2007
    2.1
    Low

    CVE-2007-3720

    Last Modified: 23 Apr 2026

    The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

    Published: 12 Jul 2007
    2.1
    Low

    CVE-2007-3722

    Last Modified: 23 Apr 2026

    The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock interrupt, as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

    Published: 12 Jul 2007
    2.1
    Low

    CVE-2007-3723

    Last Modified: 23 Apr 2026

    The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and performs scheduling based upon CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

    Published: 12 Jul 2007
    2.1
    Low

    CVE-2007-3724

    Last Modified: 23 Apr 2026

    The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges."

    Published: 12 Jul 2007
    7.5
    High

    CVE-2007-3718

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.

    Published: 12 Jul 2007
    6.9
    Medium

    CVE-2007-3717

    Last Modified: 23 Apr 2026

    rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.

    Published: 12 Jul 2007
    7.5
    High

    CVE-2007-3509

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the RPC subsystem in Symantec Backup Exec for Windows Servers 10.0, 10d, and 11d allows remote attackers to cause a denial of service (process exit) and possibly execute arbitrary code via crafted ncacn_ip_tcp requests.

    Published: 12 Jul 2007
    7.5
    High

    CVE-2006-5272

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted ping packet.

    Published: 12 Jul 2007
    7.6
    High

    CVE-2006-5271

    Last Modified: 23 Apr 2026

    Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet, which causes stack corruption.

    Published: 12 Jul 2007
    7.6
    High

    CVE-2006-5273

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 through 3.6.0.453 allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 12 Jul 2007
    7.6
    High

    CVE-2006-5274

    Last Modified: 23 Apr 2026

    Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA Framework service crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 12 Jul 2007
    4.3
    Medium

    CVE-2007-3712

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in HiddenChest "is ve Bayi Basvuru Formu" (Yb ve Bayi Babvuru Formu) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Jul 2007
    4.3
    Medium

    CVE-2007-3708

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CodeIgniter 1.5.3 before 20070626 allows remote attackers to inject arbitrary web script or HTML via (1) String.fromCharCode and (2) malformed nested tag manipulations in an unspecified component, related to insufficient sanitization by the xss_clean function.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3705

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm.

    Published: 11 Jul 2007
    9.3
    Critical

    CVE-2007-3715

    Last Modified: 23 Apr 2026

    Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.

    Published: 11 Jul 2007
    5
    Medium

    CVE-2007-3714

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this is probably a different issue than CVE-2004-2464. NOTE: it was later reported that 0.6.21 and earlier is also affected.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3713

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Konst CenterICQ 4.9.11 through 4.21 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might overlap CVE-2007-0160.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3711

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in TOS 2.1.x, 2.2.x before 2.2.5, and 2.5.x before 2.5.2 on TippingPoint IPS allows remote attackers to avoid detection by sending certain fragmented packets.

    Published: 11 Jul 2007
    5
    Medium

    CVE-2007-3707

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in CodeIgniter 1.5.3 before 20070628, when enable_query_strings is true, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter.

    Published: 11 Jul 2007
    2.1
    Low

    CVE-2007-3706

    Last Modified: 23 Apr 2026

    The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie.

    Published: 11 Jul 2007
    5
    Medium

    CVE-2007-3702

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.

    Published: 11 Jul 2007
    6.8
    Medium

    CVE-2007-3703

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method. NOTE: this is probably a different issue than CVE-2007-2987.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3704

    Last Modified: 23 Apr 2026

    Entertainment CMS allows remote attackers to bypass authentication and perform certain administrative actions by setting the adminLogged cookie to "Administrator."

    Published: 11 Jul 2007
    1.7
    Low

    CVE-2007-3700

    Last Modified: 23 Apr 2026

    Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local users to gain privileges by reading /var/opt/SUNWam/debug/amAuth.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3701

    Last Modified: 23 Apr 2026

    TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.

    Published: 11 Jul 2007
    5
    Medium

    CVE-2007-3709

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the redirect function in url_helper.php in CodeIgniter 1.5.3 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in an unspecified parameter, as demonstrated by a Set-Cookie header.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3710

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in example/gamedemo/inc.functions.php in PHP Comet-Server allows remote attackers to execute arbitrary PHP code via a URL in the projectPath parameter.

    Published: 11 Jul 2007
    9.3
    Critical

    CVE-2007-3716

    Last Modified: 23 Apr 2026

    The Java XML Digital Signature implementation in Sun JDK and JRE 6 before Update 2 does not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715.

    Published: 11 Jul 2007
    4.3
    Medium

    CVE-2007-3693

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Gobi as of 20070711, built on Helma, allows remote attackers to inject arbitrary web script or HTML via the q parameter to the search function.

    Published: 11 Jul 2007
    7.8
    High

    CVE-2007-3696

    Last Modified: 23 Apr 2026

    CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference.

    Published: 11 Jul 2007
    10
    Critical

    CVE-2007-3695

    Last Modified: 23 Apr 2026

    Buffer overflow in LICRCMD.EXE in CA ERwin Process Modeler (formerly AllFusion Process Modeler) 7.1 allows attackers to execute arbitrary code via a long filename. NOTE: the researcher does not suggest any circumstances in which the filename would come from an untrusted source, and therefore perhaps the issue does not cross privilege boundaries and should not be included in CVE.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3697

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter.

    Published: 11 Jul 2007
    7.8
    High

    CVE-2007-3690

    Last Modified: 23 Apr 2026

    The Forward module before 4.7-1.1 and 5.x before 5.x-1.0 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3683

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary SQL commands via the topic_id parameter.

    Published: 11 Jul 2007
    6.6
    Medium

    CVE-2007-3681

    Last Modified: 23 Apr 2026

    The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters.

    Published: 11 Jul 2007
    7.8
    High

    CVE-2007-3692

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.cgi in EZFactory KDDI Download CGI 1.x allows remote attackers to read and download arbitrary files via a .. (dot dot) in the name parameter.

    Published: 11 Jul 2007
    6.8
    Medium

    CVE-2007-3691

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in changePW.php in AV Tutorial Script (avtutorial) 1.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) userid parameters, a different issue than CVE-2007-3630.

    Published: 11 Jul 2007
    2.6
    Low

    CVE-2007-3688

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in DotClear 1.2.6 allow remote attackers to perform actions as arbitrary users via the (1) tool_url parameter to ecrire/tools.php and multiple fields on the (2) blogconf, (3) blogroll, (4) ecrire/redacteur.php, and (5) ecrire/user_prefs.php pages.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3686

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in db.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary HTTP headers and data via CRLF sequences in the HTTP_REFERER parameter.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3682

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 11 Jul 2007
    6.5
    Medium

    CVE-2007-3687

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inferno.php in the Inferno Technologies RPG Inferno 2.4 and earlier, a vBulletin module, allows remote authenticated attackers to execute arbitrary SQL commands via the id parameter in a ScanMember do action.

    Published: 11 Jul 2007
    7.8
    High

    CVE-2007-3689

    Last Modified: 23 Apr 2026

    The Print module before 4.7-1.0 and 5.x before 5.x-1.2 for Drupal allows remote attackers to read restricted posts in (1) Organic Groups, (2) Taxonomy Access Control, (3) Taxonomy Access Lite, and other unspecified node access modules, via modified URL arguments.

    Published: 11 Jul 2007