CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2007-3685

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3684

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Unobtrusive Ajax Star Rating Bar before 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) q and (2) t parameters in (a) db.php and (b) rpc.php.

    Published: 11 Jul 2007
    7.2
    High

    CVE-2007-3680

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the odm_searchpath function in libodm in IBM AIX 5.2.0 and 5.3.0 allows local users to execute arbitrary code via a long ODMPATH environment variable.

    Published: 11 Jul 2007
    4.3
    Medium

    CVE-2007-3457

    Last Modified: 23 Apr 2026

    Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file.

    Published: 11 Jul 2007
    7.6
    High

    CVE-2007-3678

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MSWord text-import extension (Word 6-2000 Filter.xnt) in QuarkXPress 7.2 for Windows, when using the Rectangle Text Box tool for importing text, allows user-assisted remote attackers to execute arbitrary code via a long font name.

    Published: 11 Jul 2007
    7.5
    High

    CVE-2007-3677

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Maxsi eVisit Analyst allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) idsp1.pl, (2) ip.pl, and (3) einsite_director.pl. NOTE: this issue can be leveraged for path disclosure from resulting error messages.

    Published: 11 Jul 2007
    6.2
    Medium

    CVE-2007-3103

    Last Modified: 23 Apr 2026

    The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.

    Published: 11 Jul 2007
    7.8
    High

    CVE-2007-0042

    Last Modified: 23 Apr 2026

    Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that try to constrain the final substring of a string, via %00 characters, related to use of %00 as a string terminator within POSIX functions but a data character within .NET strings, aka "Null Byte Termination Vulnerability."

    Published: 10 Jul 2007
    9.3
    Critical

    CVE-2007-0043

    Last Modified: 23 Apr 2026

    The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3028

    Last Modified: 23 Apr 2026

    The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, related to "client sent LDAP request logic," aka "Windows Active Directory Denial of Service Vulnerability". NOTE: this is probably a different issue than CVE-2007-0040.

    Published: 10 Jul 2007
    9.3
    Critical

    CVE-2007-3029

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.

    Published: 10 Jul 2007
    7.6
    High

    CVE-2007-3030

    Last Modified: 23 Apr 2026

    Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file involving the "denoting [of] the start of a Workspace designation", which results in memory corruption, aka the "Workbook Memory Corruption Vulnerability".

    Published: 10 Jul 2007
    7.8
    High

    CVE-2007-3038

    Last Modified: 23 Apr 2026

    The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka "Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability."

    Published: 10 Jul 2007
    10
    Critical

    CVE-2007-0040

    Last Modified: 23 Apr 2026

    The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."

    Published: 10 Jul 2007
    9.3
    Critical

    CVE-2007-0041

    Last Modified: 23 Apr 2026

    The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.

    Published: 10 Jul 2007
    9.3
    Critical

    CVE-2007-1756

    Last Modified: 23 Apr 2026

    Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerability".

    Published: 10 Jul 2007
    9.3
    Critical

    CVE-2007-1754

    Last Modified: 23 Apr 2026

    PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypasses a sanitization procedure that initializes critical pointers to NULL, aka the "Publisher Invalid Memory Reference Vulnerability".

    Published: 10 Jul 2007
    4.3
    Medium

    CVE-2007-3672

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ecrire/tools.php in DotClear 1.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified form fields on the blogroll page.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3666

    Last Modified: 23 Apr 2026

    Buffer overflow in RemoteCommand.DLL in Symantec Norton Ghost 12.0 allows remote attackers to execute arbitrary code via the Connect function.

    Published: 10 Jul 2007
    4.6
    Medium

    CVE-2007-3659

    Last Modified: 23 Apr 2026

    Buffer overflow in the doBrowserAction function in FreeWRL 1.19.3 allows local users to execute arbitrary code via a crafted BROWSER environment variable. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 10 Jul 2007
    4.3
    Medium

    CVE-2007-3670

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3664

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Eltima Software RunService ActiveX control (RunService.dll) allow remote attackers to cause a denial of service via certain functions when "improperly used", as demonstrated by the AcceptControls subroutine.

    Published: 10 Jul 2007
    6.8
    Medium

    CVE-2007-3663

    Last Modified: 23 Apr 2026

    Divide-by-zero error in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted MPA file.

    Published: 10 Jul 2007
    4.3
    Medium

    CVE-2007-3657

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely mechanism of action that would lead to a DoS condition.

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3661

    Last Modified: 23 Apr 2026

    Eltima Software Virtual Serial Port (VSPAX) ActiveX control (VSPort.DLL) allows remote attackers to cause a denial of service via certain function calls, as demonstrated via the (1) Attach, (2) Write, and (3) WriteStr functions.

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3667

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in EXCLEXPT.DLL in ActiveReportsExcelReport allows remote attackers to cause a denial of service via the DDRow Height variable.

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3668

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in NMSDVDXU.DLL in NuMedia NMSDVDX allow remote attackers to cause a denial of service via "improperly initialized" (1) LoadSegmentWord, (2) PartitionType, (3) SectorCount, and (4) BootFilePath variables.

    Published: 10 Jul 2007
    4.3
    Medium

    CVE-2007-3669

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Innovasys DockStudioXP InnovaDSXP2.OCX ActiveX Control have unspecified attack vectors and impact, including a denial of service via "improper use" of the SaveToFile function.

    Published: 10 Jul 2007
    7.8
    High

    CVE-2007-3671

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in Microsoft Windows Vista has unspecified remote attack vectors and impact, as shown in the "0day IPO" presentation at SyScan'07.

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3665

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in FileBackup.DLL in Symantec Norton Ghost 12.0 allow remote attackers to cause a denial of service via unspecified vectors involving the UpdateCatalog and other functions.

    Published: 10 Jul 2007
    6.8
    Medium

    CVE-2007-3662

    Last Modified: 23 Apr 2026

    Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FLV file.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3660

    Last Modified: 23 Apr 2026

    The Nonnoi ASP/Barcode ActiveX control (nonnoi_ASPBarcode.dll) allows remote attackers to overwrite arbitrary files via an argument to the SaveBarcode function.

    Published: 10 Jul 2007
    5
    Medium

    CVE-2007-3658

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Register Server (REGSVR) allows attackers to cause a denial of service via a crafted DLL library.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3648

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Webmatic before 2.6.2, and possibly other versions before 2.7, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly related to admin/admin_album.php and admin/admin_downloads.php. NOTE: some of these details are obtained from third party information.

    Published: 10 Jul 2007
    6.8
    Medium

    CVE-2007-3649

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.

    Published: 10 Jul 2007
    10
    Critical

    CVE-2007-3647

    Last Modified: 23 Apr 2026

    The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the username cookie to "traffic." NOTE: some of these details are obtained from third party information.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3646

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action.

    Published: 10 Jul 2007
    7.8
    High

    CVE-2007-3642

    Last Modified: 23 Apr 2026

    The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference.

    Published: 10 Jul 2007
    10
    Critical

    CVE-2007-3643

    Last Modified: 23 Apr 2026

    admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions.

    Published: 10 Jul 2007
    6.8
    Medium

    CVE-2007-3655

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and earlier, allows remote attackers to execute arbitrary code via a long codebase attribute in a JNLP file.

    Published: 10 Jul 2007
    9.3
    Critical

    CVE-2007-3456

    Last Modified: 23 Apr 2026

    Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value for a (1) Long string or (2) XML variable type in a crafted (a) FLV or (b) SWF file, related to an "input validation error," including a signed comparison of values that are assumed to be non-negative.

    Published: 10 Jul 2007
    6.4
    Medium

    CVE-2007-3630

    Last Modified: 23 Apr 2026

    changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for password changes, which allows remote attackers to change passwords for arbitrary users via a modified password parameter.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3631

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.

    Published: 10 Jul 2007
    6.8
    Medium

    CVE-2007-3632

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.

    Published: 10 Jul 2007
    6.4
    Medium

    CVE-2007-3633

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.

    Published: 10 Jul 2007
    6
    Medium

    CVE-2007-3638

    Last Modified: 23 Apr 2026

    Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 10 Jul 2007
    4
    Medium

    CVE-2007-3639

    Last Modified: 23 Apr 2026

    WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; and possibly other vectors related to (2) wp-includes/pluggable.php and (3) the wp_nonce_ays function in wp-includes/functions.php.

    Published: 10 Jul 2007
    4.3
    Medium

    CVE-2007-3640

    Last Modified: 23 Apr 2026

    Adobe Integrated Runtime (AIR, aka Apollo) allows context-dependent attackers to modify arbitrary files within an executing .air file (compiled AIR application) and perform cross-site scripting (XSS) attacks, as demonstrated by an application that modifies an HTML file inside itself via JavaScript that uses an APPEND open operation and the writeUTFBytes function. NOTE: this may be an intended consequence of the AIR permission model; if so, then perhaps this issue should not be included in CVE.

    Published: 10 Jul 2007
    6.5
    Medium

    CVE-2007-3634

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the G/PGP (GPG) Plugin 2.0 for Squirrelmail 1.4.10a allows remote authenticated users to execute arbitrary commands via unspecified vectors, possibly related to the passphrase variable in the gpg_sign_attachment function, aka ZD-00000004. this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 10 Jul 2007
    4.3
    Medium

    CVE-2007-3635

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin before 2.1 for Squirrelmail might allow "local authenticated users" to inject certain commands via unspecified vectors. NOTE: this might overlap CVE-2005-1924, CVE-2006-4169, or CVE-2007-3634.

    Published: 10 Jul 2007