CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2007-3798

    Last Modified: 23 Apr 2026

    Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.

    Published: 10 Jul 2007
    7.8
    High

    CVE-2006-7220

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SAP SAPLPD and SAPSPRINT allows remote attackers to cause a denial of service (application crash) via a certain print job request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3636

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the G/PGP (GPG) Plugin 2.1 for Squirrelmail allow remote attackers to execute arbitrary commands via unspecified vectors. NOTE: this information is based upon a vague pre-advisory from a reliable researcher.

    Published: 10 Jul 2007
    7.5
    High

    CVE-2007-3637

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MKPortal 1.1.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZD-00000008. this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

    Published: 10 Jul 2007
    7.8
    High

    CVE-2007-3698

    Last Modified: 23 Apr 2026

    The Java Secure Socket Extension (JSSE) in Sun JDK and JRE 6 Update 1 and earlier, JDK and JRE 5.0 Updates 7 through 11, and SDK and JRE 1.4.2_11 through 1.4.2_14, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service (CPU consumption) via certain SSL/TLS handshake requests.

    Published: 10 Jul 2007
    10
    Critical

    CVE-2007-3624

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group.

    Published: 9 Jul 2007
    5
    Medium

    CVE-2007-3625

    Last Modified: 23 Apr 2026

    The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certain request that uses content redirection and a long pathname.

    Published: 9 Jul 2007
    7.5
    High

    CVE-2007-3621

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject arbitrary shell commands via the (1) IN and (2) OUT parameters.

    Published: 9 Jul 2007
    7.5
    High

    CVE-2007-3627

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Jul 2007
    5
    Medium

    CVE-2007-3620

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Maia Mailguard 1.0.2 and earlier might allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) prevlang and (2) super parameters to (a) php/login.php; the (3) charset parameter to (a) php/login.php, (b) php/internal-init.php, and (c) php/xlogin.php; the (4) lang parameter to (b) php/internal-init.php; and the (5) language parameter to (c) php/xlogin.php.

    Published: 9 Jul 2007
    2.6
    Low

    CVE-2007-3622

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.

    Published: 9 Jul 2007
    4.3
    Medium

    CVE-2007-3623

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Hitachi JP1/HiCommand Device Manager, Tiered Storage Manager, Replication Monitor, and GlobalLink Availability Manager before 20070528 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.

    Published: 9 Jul 2007
    5
    Medium

    CVE-2007-3628

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipulate the generated sorting queries."

    Published: 9 Jul 2007
    10
    Critical

    CVE-2007-3629

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in oku.asp in Levent Veysi Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Jul 2007
    5
    Medium

    CVE-2007-3619

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Published: 9 Jul 2007
    7.8
    High

    CVE-2007-3626

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ADM daemon in Hitachi TPBroker before 20070706 allows remote attackers to cause a denial of service (daemon crash) via a certain request.

    Published: 9 Jul 2007
    4.3
    Medium

    CVE-2007-3741

    Last Modified: 23 Apr 2026

    The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a denial of service (crash or memory consumption) via crafted image files, as discovered using the fusil fuzzing tool.

    Published: 9 Jul 2007
    6.8
    Medium

    CVE-2007-3656

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.

    Published: 9 Jul 2007
    6.8
    Medium

    CVE-2006-4519

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the image loader plug-ins in GIMP before 2.2.16 allow user-assisted remote attackers to execute arbitrary code via crafted length values in (1) DICOM, (2) PNM, (3) PSD, (4) PSP, (5) Sun RAS, (6) XBM, and (7) XWD files.

    Published: 9 Jul 2007
    2.6
    Low

    CVE-2007-5273

    Last Modified: 23 Apr 2026

    Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.

    Published: 9 Jul 2007
    4
    Medium

    CVE-2006-7218

    Last Modified: 23 Apr 2026

    eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.

    Published: 6 Jul 2007
    8.5
    High

    CVE-2007-3599

    Last Modified: 23 Apr 2026

    vtiger CRM before 5.0.3 allows remote authenticated users to import and export the information for a contact even when they only have the View permission.

    Published: 6 Jul 2007
    4
    Medium

    CVE-2007-3600

    Last Modified: 23 Apr 2026

    WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.

    Published: 6 Jul 2007
    4
    Medium

    CVE-2007-3604

    Last Modified: 23 Apr 2026

    vtiger CRM before 5.0.3 allows remote authenticated users with access to the Analytics DashBoard menu to bypass data restrictions and read the pipeline of the entire organization, possibly involving modules/Potentials/Potentials.php.

    Published: 6 Jul 2007
    7.6
    High

    CVE-2007-3605

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.

    Published: 6 Jul 2007
    7.6
    High

    CVE-2007-3606

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.

    Published: 6 Jul 2007
    5
    Medium

    CVE-2007-3607

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.

    Published: 6 Jul 2007
    5
    Medium

    CVE-2007-3608

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.

    Published: 6 Jul 2007
    9.3
    Critical

    CVE-2007-3611

    Last Modified: 23 Apr 2026

    admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act parameter.

    Published: 6 Jul 2007
    6.5
    Medium

    CVE-2007-3616

    Last Modified: 23 Apr 2026

    index.php in vtiger CRM before 5.0.3 allows remote authenticated users to perform administrative changes to arbitrary profile settings via a certain profilePrivileges action in the Users module.

    Published: 6 Jul 2007
    4
    Medium

    CVE-2007-3617

    Last Modified: 23 Apr 2026

    The report module in vtiger CRM before 5.0.3 does not properly apply security rules, which allows remote authenticated users to read arbitrary private module entries.

    Published: 6 Jul 2007
    5.5
    Medium

    CVE-2007-3602

    Last Modified: 23 Apr 2026

    The SOAP webservice in vtiger CRM before 5.0.3 does not ensure that authenticated accounts are active, which allows remote authenticated users with inactive accounts to access and modify data, as demonstrated by the Thunderbird plugin.

    Published: 6 Jul 2007
    7.5
    High

    CVE-2007-3612

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long response to a JOIN command.

    Published: 6 Jul 2007
    7.5
    High

    CVE-2007-3614

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."

    Published: 6 Jul 2007
    5.5
    Medium

    CVE-2007-3598

    Last Modified: 23 Apr 2026

    index.php in vtiger CRM before 5.0.3 allows remote authenticated users to obtain all users' names and e-mail addresses, and possibly change user settings, via a modified record parameter in a DetailView action to the Users module. NOTE: the vendor disputes the changing of settings, reporting that the attack vector results in a "You are not permitted to execute this Operation" error message in a 5.0.3 demo.

    Published: 6 Jul 2007
    2.1
    Low

    CVE-2007-3601

    Last Modified: 23 Apr 2026

    vtiger CRM before 5.0.3, when a migrated build is used, allows remote authenticated users to read certain other users' calendar activities via a (1) home page or (2) event list view.

    Published: 6 Jul 2007
    6.5
    Medium

    CVE-2007-3603

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the dashboard (include/utils/SearchUtils.php) in vtiger CRM before 5.0.3 allows remote authenticated users to execute arbitrary SQL commands via the assigned_user_id parameter in a Potentials ListView action to index.php.

    Published: 6 Jul 2007
    7.5
    High

    CVE-2007-3609

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) b.php and (2) account/gallery.php, and other unspecified vectors.

    Published: 6 Jul 2007
    7.8
    High

    CVE-2007-3615

    Last Modified: 23 Apr 2026

    Internet Communication Manager (aka ICMAN.exe or ICM) in SAP NetWeaver Application Server 6.x and 7.x, possibly only on Windows, allows remote attackers to cause a denial of service (process crash) via a URI of a certain length that contains a sap-isc-key parameter, related to configuration of a web cache.

    Published: 6 Jul 2007
    4
    Medium

    CVE-2006-7219

    Last Modified: 23 Apr 2026

    eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.

    Published: 6 Jul 2007
    7.5
    High

    CVE-2007-3610

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 6 Jul 2007
    4.3
    Medium

    CVE-2007-3613

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.

    Published: 6 Jul 2007
    5
    Medium

    CVE-2007-3591

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks.

    Published: 6 Jul 2007
    6.5
    Medium

    CVE-2007-3592

    Last Modified: 23 Apr 2026

    PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields.

    Published: 6 Jul 2007
    4.3
    Medium

    CVE-2007-3596

    Last Modified: 23 Apr 2026

    inc/vul_check.inc in phpVideoPro before 0.8.8 permits non-alphanumeric characters in the sess_id parameter, which has unknown impact and remote attack vectors, probably cross-site scripting (XSS).

    Published: 6 Jul 2007
    8.5
    High

    CVE-2007-3597

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.

    Published: 6 Jul 2007
    2.6
    Low

    CVE-2007-3594

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c) reports/ReportViewAction.do; the (5) operation parameter to (d) admin/ServiceConfiguration.do; and the (6) selectedNode and (7) selectedTab parameters to (e) admin/DeviceAssociation.do. NOTE: the searchTerm parameter in Search.do is already covered by CVE-2006-2343.

    Published: 6 Jul 2007
    Unknown

    CVE-2007-3595

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-3399. Reason: This candidate is a duplicate of CVE-2007-3399. Notes: All CVE users should reference CVE-2007-3399 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Jul 2007
    4.3
    Medium

    CVE-2007-3593

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c) netflow/jspui/index.jsp, and the (4) rtype parameter in (d) netflow/jspui/selectDevice.jsp and (e) netflow/jspui/customReport.jsp. NOTE: it was later reported that vector 3 also affects 7.5 build 7500.

    Published: 6 Jul 2007
    4.3
    Medium

    CVE-2007-3590

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 5 Jul 2007