CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-2520

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3182

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Calendarix 0.7.20070307, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) year and (2) month parameters to calendar.php, and the (3) leftfooter parameter to cal_footer.inc.php. NOTE: the ycyear parameter to yearcal.php is already covered by CVE-2006-1835.

    Published: 26 Jun 2007
    6.8
    Medium

    CVE-2007-3183

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Calendarix 0.7.20070307, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters to calendar.php and the (3) search string to cal_search.php.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3396

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3399

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.

    Published: 26 Jun 2007
    Unknown

    CVE-2007-3395

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2836. Reason: This candidate is a duplicate of CVE-2007-2836. Notes: All CVE users should reference CVE-2007-2836 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3403

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload and execute arbitrary PHP code in uploads/images/ via the uploadedFile[] parameter.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3404

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3397

    Last Modified: 23 Apr 2026

    The web container in IBM WebSphere Application Server (WAS) before 6.0.2.21, and 6.1.x before 6.1.0.9, sends response data intended for a different request in certain circumstances after a closed connection error, which might allow remote attackers to obtain sensitive information.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3401

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary PHP code via a URL in the tfooter parameter.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3259

    Last Modified: 23 Apr 2026

    Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3394

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.

    Published: 26 Jun 2007
    7.5
    High

    CVE-2007-3402

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in pagetool 1.07 allows remote attackers to execute arbitrary SQL commands via the news_id parameter in a pagetool_news action.

    Published: 26 Jun 2007
    4.3
    Medium

    CVE-2007-3405

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ad and (2) konu parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jun 2007
    8.3
    High

    CVE-2007-2443

    Last Modified: 23 Apr 2026

    Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.

    Published: 26 Jun 2007
    10
    Critical

    CVE-2007-2442

    Last Modified: 23 Apr 2026

    The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.

    Published: 26 Jun 2007
    9
    Critical

    CVE-2007-2798

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.

    Published: 26 Jun 2007
    5
    Medium

    CVE-2007-3380

    Last Modified: 23 Apr 2026

    The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the DLM port, which probably prevents other processes from accessing the service.

    Published: 26 Jun 2007
    9.3
    Critical

    CVE-2007-3410

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.

    Published: 26 Jun 2007
    9.3
    Critical

    CVE-2007-3376

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple Safari 3.0.2 on Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long value in the title HTML tag, which triggers the overflow when the user adds the page as a bookmark.

    Published: 25 Jun 2007
    6.8
    Medium

    CVE-2007-3375

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Lhaca File Archiver before 1.21 allows user-assisted remote attackers to execute arbitrary code via a crafted LZH archive, as exploited by malware such as Trojan.Lhdropper.

    Published: 25 Jun 2007
    5
    Medium

    CVE-2007-3373

    Last Modified: 23 Apr 2026

    daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests.

    Published: 25 Jun 2007
    9.3
    Critical

    CVE-2007-2399

    Last Modified: 23 Apr 2026

    WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.

    Published: 25 Jun 2007
    4.3
    Medium

    CVE-2007-2400

    Last Modified: 23 Apr 2026

    Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.

    Published: 25 Jun 2007
    4.3
    Medium

    CVE-2007-2401

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks.

    Published: 25 Jun 2007
    10
    Critical

    CVE-2007-3336

    Last Modified: 23 Apr 2026

    Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.

    Published: 22 Jun 2007
    2.1
    Low

    CVE-2007-3337

    Last Modified: 23 Apr 2026

    wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file.

    Published: 22 Jun 2007
    4.3
    Medium

    CVE-2007-3343

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in RaidenHTTPD before 2.0.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jun 2007
    4.3
    Medium

    CVE-2007-3344

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in netjukebox 4.01b allow remote attackers to inject arbitrary web script or HTML via the (1) album_id, (2) order, (3) sort, (4) filter, and (5) genre_id parameters to (a) index.php; and the (6) url parameter to (b) ridirect.php. NOTE: the attack also reveals the installation path.

    Published: 22 Jun 2007
    7.5
    High

    CVE-2007-3345

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in PHPAccounts 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) Outgoing_Type_ID, (2) Outgoing_ID, (3) Project_ID, (4) Client_ID, (5) Invoice_ID, or (6) Vendor_ID parameter.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3350

    Last Modified: 23 Apr 2026

    AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP INVITE requests.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3351

    Last Modified: 23 Apr 2026

    The SJPhone SIP soft phone 1.60.303c, when installed on the Dell Axim X3 running Windows Mobile 2003, allows remote attackers to cause a denial of service (device hang and traffic amplification) via a direct crafted INVITE transaction, which causes the phone to transmit many RTP packets.

    Published: 22 Jun 2007
    4.3
    Medium

    CVE-2007-3352

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the preview form in Stephen Ostermiller Contact Form before 2.00.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that contain an apostrophe.

    Published: 22 Jun 2007
    7.5
    High

    CVE-2007-3353

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/template.php in MyEvent 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter. NOTE: a reliable third party disputes this issue, saying "the entire file is a class.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3348

    Last Modified: 23 Apr 2026

    The D-Link DPH-540/DPH-541 phone allows remote attackers to cause a denial of service (device outage) via a malformed SDP header in a SIP INVITE message.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3349

    Last Modified: 23 Apr 2026

    The Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to (1) cause a denial of service (device freeze) via a malformed SIP message of a certain length or (2) cause a denial of service (continuous ring) via a malformed SIP message of a certain other length.

    Published: 22 Jun 2007
    10
    Critical

    CVE-2007-3357

    Last Modified: 23 Apr 2026

    NetClassifieds Premium Edition does not use encryption for (1) stored passwords or (2) sensitive data, which might allow attackers to obtain information via certain vectors.

    Published: 22 Jun 2007
    6.8
    Medium

    CVE-2007-3358

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter.

    Published: 22 Jun 2007
    6.8
    Medium

    CVE-2007-3359

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SerWeb 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _SERWEB[serwebdir] parameter to (1) html/load_apu.php or (2) html/mail_prepend.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jun 2007
    9.3
    Critical

    CVE-2007-3360

    Last Modified: 23 Apr 2026

    hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes shell commands.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3361

    Last Modified: 23 Apr 2026

    The Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to cause a denial of service (device crash) via a SIP message with a malformed header.

    Published: 22 Jun 2007
    4.3
    Medium

    CVE-2007-3366

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3368

    Last Modified: 23 Apr 2026

    Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3369

    Last Modified: 23 Apr 2026

    Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial of service (device hang or reboot) via an INVITE message with a long Via header.

    Published: 22 Jun 2007
    7.5
    High

    CVE-2007-3354

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.

    Published: 22 Jun 2007
    4.3
    Medium

    CVE-2007-3355

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NetClassifieds Premium Edition allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jun 2007
    7.5
    High

    CVE-2007-3371

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in plugins/widgets/htmledit/htmledit.php in Powl 0.94 allows remote attackers to execute arbitrary PHP code via a URL in the _POWL[installPath] parameter.

    Published: 22 Jun 2007
    10
    Critical

    CVE-2006-7207

    Last Modified: 23 Apr 2026

    Buffer overflow in ageet AGEphone before 1.4.0 might allow remote attackers to have an unknown impact via unspecified vectors.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3347

    Last Modified: 23 Apr 2026

    The D-Link DPH-540/DPH-541 phone accepts SIP INVITE messages that are not from the Call Server's IP address, which allows remote attackers to engage in arbitrary SIP communication with the phone, as demonstrated by communication with forged caller ID.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3356

    Last Modified: 23 Apr 2026

    NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Common.php and (2) imageresizer.php, and (3) the use of __FILE__ in error reporting by imageresizer.php; and (4) via certain requests that reveal the table name and complete query, related to the Halt_On_Error setting in Mysql_db.php.

    Published: 22 Jun 2007