CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-3425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-3436

    Last Modified: 23 Apr 2026

    Microsoft MSN Messenger 4.7 on Windows XP allows remote attackers to cause a denial of service (resource consumption) via a flood of SIP INVITE requests to the port specified for voice conversation.

    Published: 27 Jun 2007
    7.8
    High

    CVE-2007-3438

    Last Modified: 23 Apr 2026

    Buffer overflow in the SIP header parsing module in the Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to execute arbitrary code via a malformed message, a different vulnerability than CVE-2007-3361.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-3439

    Last Modified: 23 Apr 2026

    The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to read a list of missed calls, received calls, and dialed numbers via a direct request to the web server on port 1800.

    Published: 27 Jun 2007
    6.4
    Medium

    CVE-2007-3440

    Last Modified: 23 Apr 2026

    The Snom 320 SIP Phone, running snom320 linux 3.25, snom320-SIP 6.2.3, and snom320 jffs23.36, allows remote attackers to place calls to arbitrary phone numbers via certain requests to the web server on port 1800.

    Published: 27 Jun 2007
    4.3
    Medium

    CVE-2007-3444

    Last Modified: 23 Apr 2026

    The Research in Motion BlackBerry 7270 with 4.0 SP1 Bundle 83 allows remote attackers to cause a denial of service (blocked call reception) via a malformed SIP invite message, possibly related to multiple format string specifiers in the From field, a spoofed source IP address, and limitations of the function stack frame.

    Published: 27 Jun 2007
    4.3
    Medium

    CVE-2007-3445

    Last Modified: 23 Apr 2026

    Buffer overflow in SJ Labs SJphone 1.60.303c, running under Windows Mobile 2003 on the Samsung SCH-i730 phone, allows remote attackers to cause a denial of service (device hang and call termination) via a malformed SIP INVITE message, a different vulnerability than CVE-2007-3351.

    Published: 27 Jun 2007
    7.5
    High

    CVE-2007-3446

    Last Modified: 23 Apr 2026

    BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.

    Published: 27 Jun 2007
    6.8
    Medium

    CVE-2007-3447

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.

    Published: 27 Jun 2007
    4.3
    Medium

    CVE-2007-3448

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.

    Published: 27 Jun 2007
    7.5
    High

    CVE-2007-3453

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Papoo 3.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the selmenuid parameter to certain components.

    Published: 27 Jun 2007
    10
    Critical

    CVE-2007-3455

    Last Modified: 23 Apr 2026

    cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."

    Published: 27 Jun 2007
    7.8
    High

    CVE-2007-3437

    Last Modified: 23 Apr 2026

    AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application crash) via a malformed header value in a SIP INVITE message, a different vulnerability than CVE-2007-3350.

    Published: 27 Jun 2007
    2.3
    Low

    CVE-2007-3442

    Last Modified: 23 Apr 2026

    Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header.

    Published: 27 Jun 2007
    7.5
    High

    CVE-2007-3452

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL commands via the doc_id parameter in an inline action.

    Published: 27 Jun 2007
    10
    Critical

    CVE-2007-3454

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-3434

    Last Modified: 23 Apr 2026

    index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the page parameter, which reveals the table prefix in an error message.

    Published: 27 Jun 2007
    9.3
    Critical

    CVE-2007-3435

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.

    Published: 27 Jun 2007
    2.3
    Low

    CVE-2007-3443

    Last Modified: 23 Apr 2026

    The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered.

    Published: 27 Jun 2007
    6.8
    Medium

    CVE-2007-3450

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jun 2007
    6.5
    Medium

    CVE-2007-3451

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to execute arbitrary PHP code via a URL in the pg parameter.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-1663

    Last Modified: 23 Apr 2026

    Memory leak in the image message functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-1664

    Last Modified: 23 Apr 2026

    ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service (NULL pointer dereference) via a vector related to the token OCR functionality.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-1665

    Last Modified: 23 Apr 2026

    Memory leak in the token OCR functionality in ekg before 1:1.7~rc2-1etch1 on Debian GNU/Linux Etch allows remote attackers to cause a denial of service.

    Published: 27 Jun 2007
    6.8
    Medium

    CVE-2007-2949

    Last Modified: 23 Apr 2026

    Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.

    Published: 27 Jun 2007
    7.5
    High

    CVE-2007-3432

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.

    Published: 27 Jun 2007
    7.5
    High

    CVE-2007-3433

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter in an add action.

    Published: 27 Jun 2007
    5
    Medium

    CVE-2007-3441

    Last Modified: 23 Apr 2026

    Format string vulnerability in the Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to cause a denial of service (blocked call reception and slow calling) via format string specifiers in an SDP header value, a different vulnerability than CVE-2007-3349.

    Published: 27 Jun 2007
    6.8
    Medium

    CVE-2007-3449

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Published: 27 Jun 2007
    4.3
    Medium

    CVE-2007-3413

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in bosDataGrid 2.50 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GridSearch, (2) gsearch, or (3) ParentID parameter to an unspecified component.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3415

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in phpRaider 1.0.0 rc8 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) type parameter.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3419

    Last Modified: 23 Apr 2026

    The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat.dat, (6) states.dat, and (7) ages.dat files before saving profile settings of members, which has unknown impact and remote attack vectors.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3420

    Last Modified: 23 Apr 2026

    The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has unknown impact and remote attack vectors.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3421

    Last Modified: 23 Apr 2026

    The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP before 0.9.9.7 do not verify presence of users in memberlist.dat, which has unknown impact and remote attack vectors.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3422

    Last Modified: 23 Apr 2026

    The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do not commonly occur in URLs, or (3) invalid URL encoding sequences, which has unknown impact and remote attack vectors.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3423

    Last Modified: 23 Apr 2026

    cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function reads (a) an internal IM, or a message from a (b) guest or (c) removed member, which has unknown impact and remote attack vectors.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3416

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org WebAPP 0.8 through 0.9.9.6; and (b) web-app.net WebAPP 0.9.9.3.3, 0.9.9.3.4, and 2007; allow remote attackers to perform deletions as administrators.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3412

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3417

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search string, which is not sanitized when an HREF attribute is printed by the (1) process_search or (2) show_recent_searches function.

    Published: 26 Jun 2007
    6.5
    Medium

    CVE-2007-3418

    Last Modified: 23 Apr 2026

    The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authenticated users to impersonate other users.

    Published: 26 Jun 2007
    6.8
    Medium

    CVE-2006-7208

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3411

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in edit_image.asp in ClickGallery Server 5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the image_id parameter.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3414

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in access2asp 4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) od and (2) search parameters to (a) suppliersList.asp and (b) contactsList.asp.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3424

    Last Modified: 23 Apr 2026

    The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an instant message, which has unknown impact and remote attack vectors.

    Published: 26 Jun 2007
    9.3
    Critical

    CVE-2007-2951

    Last Modified: 23 Apr 2026

    The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3406

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in Microsoft Internet Explorer 6 on Windows XP SP2 allow remote attackers to access arbitrary local files via the file: URI in the (1) src attribute of a (a) bgsound, (b) input, (c) EMBED, (d) img, or (e) script tag; (2) data attribute of an object tag; (3) value attribute of a param tag; (4) background attribute of a body tag; or (5) the background:url attribute declared in the BODY parameter of a STYLE tag.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3407

    Last Modified: 23 Apr 2026

    Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20).

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3408

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involving the use of vulnerable FreeType libraries that contain CVE-2007-2754 and/or CVE-2007-1351.

    Published: 26 Jun 2007
    9.3
    Critical

    CVE-2007-3400

    Last Modified: 23 Apr 2026

    The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3398

    Last Modified: 23 Apr 2026

    LiteWEB 2.7 allows remote attackers to cause a denial of service (hang) via a large number of requests for nonexistent pages.

    Published: 26 Jun 2007