CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2007-3474

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the GIF reader in the GD Graphics Library (libgd) before 2.0.35 have unspecified impact and user-assisted remote attack vectors.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3473

    Last Modified: 23 Apr 2026

    The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3472

    Last Modified: 23 Apr 2026

    Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact.

    Published: 21 Jun 2007
    4.6
    Medium

    CVE-2007-3105

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the random number generator (RNG) implementation in the Linux kernel before 2.6.22 might allow local root users to cause a denial of service or gain privileges by setting the default wakeup threshold to a value greater than the output pool size, which triggers writing random numbers to the stack by the pool transfer function involving "bound check ordering". NOTE: this issue might only cross privilege boundaries in environments that have granular assignment of privileges for root.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3476

    Last Modified: 23 Apr 2026

    Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

    Published: 21 Jun 2007
    4.3
    Medium

    CVE-2007-3475

    Last Modified: 23 Apr 2026

    The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map.

    Published: 21 Jun 2007
    Unknown

    CVE-2007-4168

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4168. Reason: This candidate is a duplicate of CVE-2006-4168. It was inadvertently used in a vendor advisory when the "2006" year was intended. Notes: All CVE users should reference CVE-2006-4168 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Jun 2007
    7.5
    High

    CVE-2007-3301

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.

    Published: 20 Jun 2007
    4.3
    Medium

    CVE-2007-3299

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in AWFFull before 3.7.4, when AllSearchStr (aka the All Search Terms report) is enabled, allows remote attackers to inject arbitrary web script or HTML via a search string.

    Published: 20 Jun 2007
    9.3
    Critical

    CVE-2007-3300

    Last Modified: 23 Apr 2026

    Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.

    Published: 20 Jun 2007
    4.9
    Medium

    CVE-2007-3303

    Last Modified: 23 Apr 2026

    Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.

    Published: 20 Jun 2007
    7.5
    High

    CVE-2007-3298

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Spey before 0.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to MessageProcessor.cc and possibly other components.

    Published: 20 Jun 2007
    9.3
    Critical

    CVE-2007-3290

    Last Modified: 23 Apr 2026

    categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.

    Published: 20 Jun 2007
    7.5
    High

    CVE-2007-3293

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 20 Jun 2007
    9.3
    Critical

    CVE-2007-3296

    Last Modified: 23 Apr 2026

    The ThunderServer.webThunder.1 ActiveX control in xunlei Web Thunderbolt 1.7.3.109 allows remote attackers to download arbitrary files and conduct other unauthorized actions by invoking dangerous methods.

    Published: 20 Jun 2007
    7.5
    High

    CVE-2007-3297

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[ini_array][EXTLIB_PATH] parameter to (1) msDb.php, (2) modules/MusooTemplateLite.php, or (3) modules/SoundImporter.php.

    Published: 20 Jun 2007
    4.3
    Medium

    CVE-2007-3288

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer field.

    Published: 20 Jun 2007
    7.5
    High

    CVE-2007-3289

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Published: 20 Jun 2007
    7.5
    High

    CVE-2007-3292

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article.

    Published: 20 Jun 2007
    4.3
    Medium

    CVE-2007-3291

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php.

    Published: 20 Jun 2007
    6.5
    Medium

    CVE-2007-3295

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Yet another Bulletin Board (YaBB) 2.1 and earlier allows remote authenticated users to execute arbitrary Perl code via a .. (dot dot) in the userlanguage profile setting, which sets the userlanguage key of the member hash, and is propagated to the language variable in (1) HelpCentre.pl and (2) ICQPager.pl, (3) the use_lang variable in Subs.pl, and the actlang variable in (4) Post.pl and (5) InstantMessage.pl; as demonstrated by pointing userlanguage to the English folder, modifying English/HelpCentre.lng file to contain Perl statements, and then invoking the help action in YaBB.pl.

    Published: 20 Jun 2007
    6.8
    Medium

    CVE-2007-3285

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.

    Published: 20 Jun 2007
    4.3
    Medium

    CVE-2006-5752

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.

    Published: 20 Jun 2007
    7.8
    High

    CVE-2007-3282

    Last Modified: 23 Apr 2026

    Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.

    Published: 19 Jun 2007
    6.8
    Medium

    CVE-2007-3283

    Last Modified: 23 Apr 2026

    GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.

    Published: 19 Jun 2007
    7.8
    High

    CVE-2007-3284

    Last Modified: 23 Apr 2026

    corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.

    Published: 19 Jun 2007
    10
    Critical

    CVE-2007-2924

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in RealNetworks GameHouse dldisplay ActiveX control (ghdlctl.dll) allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 19 Jun 2007
    10
    Critical

    CVE-2007-3270

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the strIncludePrefix parameter.

    Published: 19 Jun 2007
    7.5
    High

    CVE-2007-3271

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/2blue/bodyTemplate.php in YourFreeScreamer 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter.

    Published: 19 Jun 2007
    7.8
    High

    CVE-2007-3272

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter in a register action.

    Published: 19 Jun 2007
    4.3
    Medium

    CVE-2007-3274

    Last Modified: 23 Apr 2026

    Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.

    Published: 19 Jun 2007
    10
    Critical

    CVE-2007-3277

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the localization before 1.2 module for WIKINDX allows attackers to access certain administrative capabilities via unknown vectors.

    Published: 19 Jun 2007
    9
    Critical

    CVE-2007-3280

    Last Modified: 23 Apr 2026

    The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

    Published: 19 Jun 2007
    4.3
    Medium

    CVE-2007-3281

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 19 Jun 2007
    2.6
    Low

    CVE-2007-3129

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.

    Published: 19 Jun 2007
    3.5
    Low

    CVE-2007-3269

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in a GET request or (2) the Title field of a visitor comment, and (3) allow remote authenticated users to inject arbitrary web script or HTML via a message to another user. NOTE: vector (2) might overlap CVE-2006-3571.1.

    Published: 19 Jun 2007
    7.5
    High

    CVE-2007-3273

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Jun 2007
    4.3
    Medium

    CVE-2007-3276

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Site@School (S@S) 2.4.10 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Jun 2007
    10
    Critical

    CVE-2007-3279

    Last Modified: 23 Apr 2026

    PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote attackers to create and execute functions, as demonstrated by functions that perform local brute-force password guessing attacks, which may evade intrusion detection.

    Published: 19 Jun 2007
    7.1
    High

    CVE-2007-3275

    Last Modified: 23 Apr 2026

    MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.

    Published: 19 Jun 2007
    10
    Critical

    CVE-2007-3263

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository."

    Published: 19 Jun 2007
    10
    Critical

    CVE-2007-3264

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors.

    Published: 19 Jun 2007
    4.3
    Medium

    CVE-2007-3265

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Jun 2007
    9
    Critical

    CVE-2007-3266

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter.

    Published: 19 Jun 2007
    4.3
    Medium

    CVE-2007-3267

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.

    Published: 19 Jun 2007
    4.3
    Medium

    CVE-2007-3261

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in widgets/widget_search.php in dKret before 2.6 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Published: 19 Jun 2007
    9
    Critical

    CVE-2007-3260

    Last Modified: 23 Apr 2026

    HP System Management Homepage (SMH) before 2.1.9 for Linux, when used with Novell eDirectory, assigns the eDirectory members to the root group, which allows remote authenticated eDirectory users to gain privileges.

    Published: 19 Jun 2007
    7.8
    High

    CVE-2007-3262

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to cause a denial of service related to a thread hang, and possibly related to a "TCP issue," or to MPAlarmThread and a resultant memory leak.

    Published: 19 Jun 2007
    6.4
    Medium

    CVE-2007-3128

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 19 Jun 2007
    5
    Medium

    CVE-2007-3127

    Last Modified: 23 Apr 2026

    content.php in WSPortal 1.0, when magic_quotes_gpc is disabled, allows remote attackers to obtain sensitive information via a "';" (quote semicolon) sequence in the page parameter, which reveals the installation path in the resulting forced SQL error message.

    Published: 19 Jun 2007