CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2007-3537

    Last Modified: 23 Apr 2026

    IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3538

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in qtg_msg_view.php in QuickTalk guestbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Jul 2007
    5
    Medium

    CVE-2007-3533

    Last Modified: 23 Apr 2026

    The 3Com IntelliJack Switch NJ220 before 2.0.23 allows remote attackers to cause a denial of service (reboot and reporting outage) via a loopback packet with zero in the length field.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3541

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Kurinton sHTTPd 20070408 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3542

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 3 Jul 2007
    6
    Medium

    CVE-2007-3543

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code by making a post that specifies a .php filename in the _wp_attached_file metadata field; and then sending this file's content, along with its post_ID value, to (1) wp-app.php or (2) app.php.

    Published: 3 Jul 2007
    6.5
    Medium

    CVE-2007-3544

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in (1) wp-app.php and (2) app.php in WordPress 2.2.1 and WordPress MU 1.2.3 allows remote authenticated users to upload and execute arbitrary PHP code via unspecified vectors, possibly related to the wp_postmeta table and the use of custom fields in normal (non-attachment) posts. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-3543.

    Published: 3 Jul 2007
    7.1
    High

    CVE-2007-3545

    Last Modified: 23 Apr 2026

    Buffer overflow in Warzone 2100 Resurrection before 2.0.7 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename when setting background music.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3540

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in search.asp in rwAuction Pro 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) show, (3) searchtype, (4) catid, and (5) searchtxt parameters, a different version and vectors than CVE-2005-4060.

    Published: 3 Jul 2007
    7.8
    High

    CVE-2007-3547

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in qti_checkname.php in QuickTicket 1.2 allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the lang parameter.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3546

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Windows GUI in Nessus Vulnerability Scanner before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3539

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in qti_usr.php; and the (6) f parameter in qti_ind_topic.php. NOTE: it was later reported that vector 5 also affects 1.4, 1.5, and 1.5.0.3.

    Published: 3 Jul 2007
    3.6
    Low

    CVE-2007-2837

    Last Modified: 23 Apr 2026

    The (1) getRule and (2) getChains functions in server/rules.cpp in fireflierd (fireflier-server) in FireFlier 1.1.6 allow local users to overwrite arbitrary files via a symlink attack on the /tmp/fireflier.rules temporary file.

    Published: 3 Jul 2007
    10
    Critical

    CVE-2007-3515

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_event.php in TotalCalendar 2.402 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3516

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in kayit.asp in Gorki Online Santrac Sitesi allow remote attackers to inject arbitrary web script or HTML via the (1) kullanici, (2) posta, or (3) takim_adi parameter to uyeler.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3521

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3519

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in eventdisplay.php in phpEventCalendar 0.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3520

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

    Published: 3 Jul 2007
    7.8
    High

    CVE-2007-3525

    Last Modified: 23 Apr 2026

    Ripe Website Manager 0.8.9 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3526

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the news_id parameter to view_news.php, (2) the cat_id parameter to view_events.php, or (3) the member_id parameter to video_gallery.php.

    Published: 3 Jul 2007
    6.8
    Medium

    CVE-2007-3527

    Last Modified: 23 Apr 2026

    Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain database operations with multi-byte character sets that trigger an attempt to use the value 65536 for a 16-bit integer, which is treated as 0 and causes an infinite loop on zero-length data.

    Published: 3 Jul 2007
    5
    Medium

    CVE-2007-3528

    Last Modified: 23 Apr 2026

    The blowfish mode in DAR before 2.3.4 uses weak Blowfish-CBC cryptography by (1) discarding random bits by the blowfish::make_ivec function in libdar/crypto.cpp that results in predictable and repeating IV values, and (2) direct use of a password for keying, which makes it easier for context-dependent attackers to decrypt files.

    Published: 3 Jul 2007
    7.8
    High

    CVE-2007-3529

    Last Modified: 23 Apr 2026

    videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.

    Published: 3 Jul 2007
    6.4
    Medium

    CVE-2007-3523

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter.

    Published: 3 Jul 2007
    7.5
    High

    CVE-2007-3518

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in msg.php in HispaH YouTube Clone Script (youtubeclone) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Jul 2007
    6.8
    Medium

    CVE-2007-3524

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php.

    Published: 3 Jul 2007
    4.3
    Medium

    CVE-2007-3517

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) index.php, (2) demo/claroline170/index.php, and possibly other scripts.

    Published: 3 Jul 2007
    6.8
    Medium

    CVE-2007-3522

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.

    Published: 3 Jul 2007
    7.2
    High

    CVE-2007-3530

    Last Modified: 23 Apr 2026

    PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.

    Published: 3 Jul 2007
    9.3
    Critical

    CVE-2007-3512

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375.

    Published: 3 Jul 2007
    8.5
    High

    CVE-2007-3514

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.

    Published: 3 Jul 2007
    7.2
    High

    CVE-2007-2838

    Last Modified: 23 Apr 2026

    The populate_conns function in src/populate_conns.c in GSAMBAD 0.1.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gsambadtmp temporary file.

    Published: 3 Jul 2007
    6.8
    Medium

    CVE-2007-2835

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in (1) CCE_pinyin.c and (2) xl_pinyin.c in ImmModules/cce/ in unicon-imc2 3.0.4, as used by zhcon and other applications, allow local users to gain privileges via a long HOME environment variable.

    Published: 3 Jul 2007
    2.1
    Low

    CVE-2007-3107

    Last Modified: 23 Apr 2026

    The signal handling in the Linux kernel before 2.6.22, including 2.6.2, when running on PowerPC systems using HTX, allows local users to cause a denial of service via unspecified vectors involving floating point corruption and concurrency, related to clearing of MSR bits.

    Published: 3 Jul 2007
    7.2
    High

    CVE-2007-3508

    Last Modified: 23 Apr 2026

    Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution

    Published: 3 Jul 2007
    5
    Medium

    CVE-2007-3568

    Last Modified: 23 Apr 2026

    The _LoadBMP function in imlib 1.9.15 and earlier allows context-dependent attackers to cause a denial of service (infinite loop) via a BMP image with a Bits Per Page (BPP) value of 0.

    Published: 3 Jul 2007
    6.4
    Medium

    CVE-2007-2836

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout.

    Published: 2 Jul 2007
    6.4
    Medium

    CVE-2007-3505

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.

    Published: 2 Jul 2007
    7.5
    High

    CVE-2007-3506

    Last Modified: 23 Apr 2026

    The ft_bitmap_assure_buffer function in src/base/ftbimap.c in FreeType 2.3.3 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors involving bitmap fonts, related to a "memory buffer overwrite bug."

    Published: 2 Jul 2007
    9.3
    Critical

    CVE-2007-3507

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the local__vcentry_parse_value function in vorbiscomment.c in flac123 (aka flac-tools or flac) before 0.0.10 allows user-assisted remote attackers to execute arbitrary code via a large comment value_length.

    Published: 2 Jul 2007
    9.3
    Critical

    CVE-2007-3504

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, for Windows allows remote attackers to perform unauthorized actions via an application that grants file overwrite privileges to itself. NOTE: this can be leveraged to execute arbitrary code by overwriting a .java.policy file.

    Published: 30 Jun 2007
    4.3
    Medium

    CVE-2007-3501

    Last Modified: 12 Dec 2025

    Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508.

    Published: 30 Jun 2007
    4.3
    Medium

    CVE-2007-2801

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) err and (2) warn parameters. NOTE: the vendor disputes the significance of the issue, stating that "eTicket is not designed to work with register_globals On."

    Published: 30 Jun 2007
    7.5
    High

    CVE-2007-3502

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the web-based product configuration system in Kaspersky Anti-Spam before 3.0 MP1 allows remote attackers to obtain access to certain directories.

    Published: 30 Jun 2007
    4.3
    Medium

    CVE-2007-3511

    Last Modified: 23 Apr 2026

    The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field.

    Published: 30 Jun 2007
    4.9
    Medium

    CVE-2006-7211

    Last Modified: 23 Apr 2026

    fb_lock_mgr in Firebird 1.5 uses weak permissions (0666) for the semaphore array, which allows local users to cause a denial of service (blocked query processing) by locking semaphores.

    Published: 29 Jun 2007
    6.8
    Medium

    CVE-2006-7212

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Firebird 1.5, one of which affects WNET, have unknown impact and attack vectors. NOTE: this issue might overlap CVE-2006-1240.

    Published: 29 Jun 2007
    6.4
    Medium

    CVE-2007-3487

    Last Modified: 23 Apr 2026

    Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.

    Published: 29 Jun 2007
    7.5
    High

    CVE-2007-3490

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified vectors, possibly related to the sheet name, as demonstrated by 2670.xls.

    Published: 29 Jun 2007
    4.3
    Medium

    CVE-2007-3495

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the SAP Internet Communication Framework (BC-MID-ICF) in the SAP Basis component 700 before SP12, and 640 before SP20, allow remote attackers to inject arbitrary web script or HTML via certain parameters associated with the default login error page.

    Published: 29 Jun 2007