CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2007-3374

    Last Modified: 23 Apr 2026

    Buffer overflow in cluster/cman/daemon/daemon.c in cman (redhat-cluster-suite) before 20070622 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via long client messages.

    Published: 19 Jun 2007
    7.5
    High

    CVE-2007-3294

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an unspecified vector to the tidy_repair_string function. NOTE: this might only be an issue in environments where vsnprintf is implemented as a wrapper for vsprintf.

    Published: 19 Jun 2007
    4.7
    Medium

    CVE-2007-3304

    Last Modified: 23 Apr 2026

    Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."

    Published: 19 Jun 2007
    9.3
    Critical

    CVE-2007-2923

    Last Modified: 23 Apr 2026

    The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands.

    Published: 18 Jun 2007
    4.3
    Medium

    CVE-2007-3101

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the client.

    Published: 18 Jun 2007
    7.8
    High

    CVE-2007-3248

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (system crash) via certain network traffic.

    Published: 18 Jun 2007
    7.5
    High

    CVE-2007-3250

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mod_banners.php in Elxis CMS before 2006.4 20070613 allows remote attackers to execute arbitrary SQL commands via the mb_tracker cookie. NOTE: the product was patched without updating the version number; later downloads of 2006.4 are not affected.

    Published: 18 Jun 2007
    7.8
    High

    CVE-2007-3251

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the adminlang cookie to admin/functions.php or (2) read arbitrary local files via the img parameter to admin/show_img.php.

    Published: 18 Jun 2007
    7.8
    High

    CVE-2007-3252

    Last Modified: 23 Apr 2026

    PortalApp stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for 8691.mdb, a different vector than CVE-2004-1786.

    Published: 18 Jun 2007
    7.1
    High

    CVE-2007-3207

    Last Modified: 23 Apr 2026

    Buffer overflow in the NFS mount daemon (XNFS.NLM) in Novell NetWare 6.5 SP6, and probably earlier, allows remote attackers to cause a denial of service (abend) via a long path in a mount request.

    Published: 18 Jun 2007
    6.8
    Medium

    CVE-2007-3247

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in VirtueMart before 1.0.11 allows remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly related to improper input validation of the PATH_INFO (PHP_SELF) by virtuemart_parser.php.

    Published: 18 Jun 2007
    4.3
    Medium

    CVE-2007-3249

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mod_lettermansubscribe.php in the Letterman Subscriber (mod_letterman) before 1.2.5 module for Joomla! allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter.

    Published: 18 Jun 2007
    7.8
    High

    CVE-2007-3253

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers to cause a denial of service via (1) certain email, which stops the SMTP Proxy during scanning; (2) certain HTTP traffic, which stops or slows down the HTTP proxy during HTTP responses containing virus scanned web pages; and (3) a disconnection during a streaming session.

    Published: 18 Jun 2007
    6.8
    Medium

    CVE-2007-5198

    Last Modified: 23 Apr 2026

    Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web servers to execute arbitrary code via Location header responses (redirects) with a large number of leading "L" characters.

    Published: 17 Jun 2007
    6.9
    Medium

    CVE-2007-3278

    Last Modified: 23 Apr 2026

    PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

    Published: 16 Jun 2007
    5
    Medium

    CVE-2007-3233

    Last Modified: 23 Apr 2026

    The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files via the SaveImage method.

    Published: 15 Jun 2007
    7.5
    High

    CVE-2007-3234

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Published: 15 Jun 2007
    4.3
    Medium

    CVE-2007-3235

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection.

    Published: 15 Jun 2007
    7.5
    High

    CVE-2007-3236

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the xoopsConfig[root_path] parameter.

    Published: 15 Jun 2007
    10
    Critical

    CVE-2007-3232

    Last Modified: 23 Apr 2026

    The IBM TotalStorage DS400 with firmware 4.15 uses a blank password for the (1) root, (2) user, (3) manager, (4) administrator, and (5) operator accounts, which allows remote attackers to gain login access via certain Linux daemons, including a telnet daemon on a nonstandard port, tcp/6000.

    Published: 15 Jun 2007
    4.3
    Medium

    CVE-2007-3240

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in 404.php in the Vistered-Little theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI) that accesses index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

    Published: 15 Jun 2007
    4.3
    Medium

    CVE-2007-3241

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in blogroll.php in the cordobo-green-park theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI.

    Published: 15 Jun 2007
    7.5
    High

    CVE-2007-3242

    Last Modified: 23 Apr 2026

    The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the titles of items in a personal menu.

    Published: 15 Jun 2007
    4.3
    Medium

    CVE-2007-3243

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bb-login.php in bbPress 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the re parameter. NOTE: exploitation may require forcing the client to send a certain Referer header.

    Published: 15 Jun 2007
    7.5
    High

    CVE-2007-3244

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bb-includes/formatting-functions.php in bbPress before 0.8.1 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors to forums/bb-edit.php, as demonstrated by a PRE element, aka the "quircky slashes bug."

    Published: 15 Jun 2007
    6
    Medium

    CVE-2007-3238

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

    Published: 15 Jun 2007
    5
    Medium

    CVE-2007-3246

    Last Modified: 23 Apr 2026

    The do_set_password function in modules/chanserv/set.c in IRC Services before 5.0.60 preserves channel founder privileges across a channel password change (ChanServ SET PASSWORD), which allows remote authenticated users to obtain the new password through automated e-mail, or perform privileged actions without knowing the new password.

    Published: 15 Jun 2007
    6.8
    Medium

    CVE-2007-3237

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Published: 15 Jun 2007
    4.3
    Medium

    CVE-2007-3239

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in searchform.php in the AndyBlue theme before 20070607 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to index.php. NOTE: this can be leveraged for PHP code execution in an administrative session.

    Published: 15 Jun 2007
    5
    Medium

    CVE-2007-3245

    Last Modified: 23 Apr 2026

    IRC Services before 5.0.62, and 5.1 before 5.1pre3, allows remote attackers to disconnect users with guest nicknames by linking a guest nickname to a nickname that is already registered.

    Published: 15 Jun 2007
    9.3
    Critical

    CVE-2007-2921

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3220

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this may be a duplicate of CVE-2006-4656.

    Published: 14 Jun 2007
    6.4
    Medium

    CVE-2007-3225

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Directory Server (slapd) 6.0, and 5.2 with Patch 3 or 4, allows remote attackers to modify certain data via unknown vectors.

    Published: 14 Jun 2007
    4.3
    Medium

    CVE-2007-3227

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3230

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3228

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CMS 4.2.12 and earlier might allow remote attackers to execute arbitrary PHP code via a URL in the FORUM[LIB] parameter. NOTE: by default, access to the PhpDocumentor directory tree is blocked by .htaccess.

    Published: 14 Jun 2007
    7.5
    High

    CVE-2007-3231

    Last Modified: 23 Apr 2026

    Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors.

    Published: 14 Jun 2007
    2.1
    Low

    CVE-2007-2448

    Last Modified: 23 Apr 2026

    Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.

    Published: 14 Jun 2007
    7.5
    High

    CVE-2007-3222

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the dir_module parameter.

    Published: 14 Jun 2007
    5
    Medium

    CVE-2007-3224

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun ONE/Java System Directory Server (slapd) 6.0, and 5.x before 5.2 Patch 5, allows remote attackers to determine the existence of attributes of an entry via unspecified vectors.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3221

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Published: 14 Jun 2007
    4.3
    Medium

    CVE-2007-3226

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dotProject before 2.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-2851 and CVE-2006-3240.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3229

    Last Modified: 23 Apr 2026

    index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message.

    Published: 14 Jun 2007
    7.8
    High

    CVE-2007-3223

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.

    Published: 14 Jun 2007
    4.3
    Medium

    CVE-2007-3212

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.

    Published: 14 Jun 2007
    4.3
    Medium

    CVE-2007-3213

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in Sporum Forum 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) mode parameters.

    Published: 14 Jun 2007
    7.8
    High

    CVE-2007-3219

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers to modify another user's profile data, such as an AIM screen name or Yahoo! identity.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3215

    Last Modified: 23 Apr 2026

    PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

    Published: 14 Jun 2007
    10
    Critical

    CVE-2007-3216

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.1 allow remote attackers to execute arbitrary code via crafted arguments to the (1) rxsAddNewUser, (2) rxsSetUserInfo, (3) rxsRenameUser, (4) rxsSetMessageLogSettings, (5) rxsExportData, (6) rxsSetServerOptions, (7) rxsRenameFile, (8) rxsACIManageSend, (9) rxsExportUser, (10) rxsImportUser, (11) rxsMoveUserData, (12) rxsUseLicenseIni, (13) rxsLicGetSiteId, (14) rxsGetLogFileNames, (15) rxsGetBackupLog, (16) rxsBackupComplete, (17) rxsSetDataProtectionSecurityData, (18) rxsSetDefaultConfigName, (19) rxsGetMessageLogSettings, (20) rxsHWDiskGetTotal, (21) rxsHWDiskGetFree, (22) rxsGetSubDirs, (23) rxsGetServerDBPathName, (24) rxsSetServerOptions, (25) rxsDeleteFile, (26) rxsACIManageSend, (27) rxcReadBackupSetList, (28) rxcWriteConfigInfo, (29) rxcSetAssetManagement, (30) rxcWriteFileListForRestore, (31) rxcReadSaveSetProfile, (32) rxcInitSaveSetProfile, (33) rxcAddSaveSetNextAppList, (34) rxcAddSaveSetNextFilesPathList, (35) rxcAddNextBackupSetIncWildCard, (36) rxcGetRevisions, (37) rxrAddMovedUser, (38) rxrSetClientVersion, or (39) rxsSetDataGrowthScheduleAndFilter commands.

    Published: 14 Jun 2007
    7.5
    High

    CVE-2007-3217

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Prototype of an PHP application 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the path_inc parameter to (1) index.php in gestion/; (2) identification.php, (3) disconnect.php, (4) loginliste.php, (5) loginmodif.php, (6) index.php, and (7) ident.inc.php in ident/; (8) menuadministration.php and (9) menuprincipal.php in menu/; (10) param.inc.php in param/; (11) index.php in plugins/phpgacl/; and (12) index.php and (13) common.inc.php.

    Published: 14 Jun 2007