CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2007-3362

    Last Modified: 23 Apr 2026

    ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of service (call disruption and device hang) via a SIP message with a malformed header and (2) cause a denial of service (call disruption, false ring indication, and device outage) via a SIP message with a malformed SDP delimiter.

    Published: 22 Jun 2007
    10
    Critical

    CVE-2007-3363

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ageet AGEphone before 1.6.3 allow remote attackers to have an unknown impact via malformed SIP packets.

    Published: 22 Jun 2007
    7.5
    High

    CVE-2007-3365

    Last Modified: 23 Apr 2026

    MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions, which allows remote attackers to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3367

    Last Modified: 23 Apr 2026

    Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive information via a direct request, which reveals the path in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2007-3346

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHPAccounts 0.5 allows remote attackers to include arbitrary local files via unspecified manipulations of the page parameter.

    Published: 22 Jun 2007
    10
    Critical

    CVE-2007-3338

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allow remote attackers to execute arbitrary code via the (1) uuid_from_char or (2) duve_get_args functions.

    Published: 22 Jun 2007
    4.3
    Medium

    CVE-2007-3364

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the cgi-bin/post.mscgi sample page in MyServer 0.8.9 allows remote attackers to inject arbitrary web script or HTML via the body content.

    Published: 22 Jun 2007
    7.5
    High

    CVE-2007-3370

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrary PHP code via a URL in (1) the sunPath parameter to include.php or (2) the dir parameter to skin/board/default/doctype.php.

    Published: 22 Jun 2007
    4.6
    Medium

    CVE-2007-0773

    Last Modified: 23 Apr 2026

    The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.

    Published: 22 Jun 2007
    7.8
    High

    CVE-2006-7206

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating a ADODB.Recordset object and making a series of calls to the NextRecordset method with a long string argument, which causes an "invalid memory access" in the SysFreeString function, a different issue than CVE-2006-3510 and CVE-2006-3899.

    Published: 22 Jun 2007
    2.1
    Low

    CVE-2007-3372

    Last Modified: 23 Apr 2026

    The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.

    Published: 22 Jun 2007
    4.9
    Medium

    CVE-2007-3104

    Last Modified: 23 Apr 2026

    The sysfs_readdir function in the Linux kernel 2.6, as used in Red Hat Enterprise Linux (RHEL) 4.5 and other distributions, allows users to cause a denial of service (kernel OOPS) by dereferencing a null pointer to an inode in a dentry.

    Published: 22 Jun 2007
    10
    Critical

    CVE-2007-3341

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the FTP implementation in Microsoft Internet Explorer allows remote attackers to "see a valid memory address" via unspecified vectors, a different issue than CVE-2007-0217.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3342

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Movable Type (MT) before 3.34 allow remote attackers to inject arbitrary web script or HTML via comments that have (1) a malformed SGML numeric character reference with a '\0' (0x00) character in a javascript: URI or (2) an attribute in an element that lacks the '>' character at the end of the start tag, a different vulnerability than CVE-2007-0231.

    Published: 21 Jun 2007
    10
    Critical

    CVE-2007-3334

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 21 Jun 2007
    7.8
    High

    CVE-2007-3340

    Last Modified: 23 Apr 2026

    BugHunter HTTP SERVER (httpsv.exe) 1.6.2 allows remote attackers to cause a denial of service (application crash) via a large number of requests for nonexistent pages.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3339

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3) FTVAR_SCRIPTRUN parameter to (b) forum/include/common/comfinish.cfm and (c) blog/include/common/comfinish.cfm.

    Published: 21 Jun 2007
    7.8
    High

    CVE-2007-2833

    Last Modified: 23 Apr 2026

    Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3332

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Satellite.php in Satel Lite for PhpNuke allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the name parameter in a modload action.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3335

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the admin panel in PHPEcho CMS before 1.6 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Jun 2007
    7.8
    High

    CVE-2007-3317

    Last Modified: 23 Apr 2026

    The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (device crash) via a malformed SIP message.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3318

    Last Modified: 23 Apr 2026

    Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (call reception outage) via a malformed SIP message.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3319

    Last Modified: 23 Apr 2026

    The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept communications.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3320

    Last Modified: 23 Apr 2026

    The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified impact.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3325

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/language.php in LAN Management System (LMS) 1.9.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _LIB_DIR parameter, a different vector than CVE-2007-1643 and CVE-2007-2205.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3327

    Last Modified: 23 Apr 2026

    httpsv.exe in HTTP Server 1.6.2 allows remote attackers to obtain sensitive information (script source code) via a URI with a trailing %20 (encoded space).

    Published: 21 Jun 2007
    6.8
    Medium

    CVE-2007-3314

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (English Trial), and 2.0 with Portable Executable Viewer 1.00 (English Trial), allows remote attackers to execute arbitrary code via a long PDB debug filename in a PE file.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3323

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comersus_optReviewReadExec.asp in Comersus Shop Cart 7.07 allows remote attackers to execute arbitrary SQL commands via the idProduct parameter. NOTE: this might be the same as CVE-2005-2190.2.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3331

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that is posted automatically by JavaScript or (2) a news post.

    Published: 21 Jun 2007
    9
    Critical

    CVE-2007-3312

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrators to include and execute arbitrary local files a .. (dot dot) in the u parameter. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

    Published: 21 Jun 2007
    6.8
    Medium

    CVE-2007-3315

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter to bodyTemplate.php in (1) templates/Classic/, (2) templates/Classic Guestbook/, (3) templates/DarkNights/, and (4) templates/Simplistic/, different vectors than CVE-2007-3271. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jun 2007
    9.3
    Critical

    CVE-2007-3316

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3324

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Comersus Cart 7.07 allow remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter to (1) comersus_customerAuthenticateForm.asp or (2) comersus_message.asp, different vectors than CVE-2004-0681.

    Published: 21 Jun 2007
    5.8
    Medium

    CVE-2007-3326

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and other attacks, a different vulnerability than CVE-2005-3025.2.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3328

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Interact 2.4 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) module_key parameter to (a) kb/kb.php, (b) quiz/runquiz.php, (c) quiz/quiz.php, (d) forum/forum.php, (e) forum/byname.php, and (f) journal/journalview.php in modules/, and unspecified other scripts; the (2) tag_key parameter to modules/journal/journalview.php; the (3) user_group_key parameter to (g) users/secureaccounts.php; and (4) the request_uri parameter to (h) login.php.

    Published: 21 Jun 2007
    6.8
    Medium

    CVE-2007-3329

    Last Modified: 23 Apr 2026

    Multiple array index errors in the (1) get_intra_block, (2) get_inter_block_h263, and (3) get_inter_block_mpeg functions in src/bitstream/mbcoding.c in Xvid 1.1.2 allow remote attackers to execute arbitrary code via a crafted (a) Avi, (b) H.263, or (c) MPEG file.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3313

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3321

    Last Modified: 23 Apr 2026

    The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) via a flood of packets to the BOOTP port (68/udp).

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3322

    Last Modified: 23 Apr 2026

    The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of service (audio quality loss) via a flood of packets to the RTP port.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3330

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is stored in news/ without sanitization.

    Published: 21 Jun 2007
    7.1
    High

    CVE-2007-2398

    Last Modified: 23 Apr 2026

    Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the window content, which could facilitate phishing attacks.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3311

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3307

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3309

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.

    Published: 21 Jun 2007
    9.3
    Critical

    CVE-2007-3305

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execute arbitrary code via a message sent through the MSN protocol, or possibly other protocols, with a crafted UTF-8 string, which triggers improper memory allocation for word wrapping when a window width is used as a buffer size, a different vulnerability than CVE-2007-2478.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3308

    Last Modified: 23 Apr 2026

    Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack.

    Published: 21 Jun 2007
    7.5
    High

    CVE-2007-3306

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter, a different vector than CVE-2006-4489.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3310

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in arama.asp in TDizin allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3478

    Last Modified: 23 Apr 2026

    Race condition in gdImageStringFTEx (gdft_draw_bitmap) in gdft.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving truetype font (TTF) support.

    Published: 21 Jun 2007
    5
    Medium

    CVE-2007-3477

    Last Modified: 23 Apr 2026

    The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.

    Published: 21 Jun 2007