CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-3218

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in request.php in PHP Live! 3.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the pagex parameter.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3214

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in style.php in e-Vision CMS 2.02 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the template parameter.

    Published: 14 Jun 2007
    7.8
    High

    CVE-2007-3209

    Last Modified: 23 Apr 2026

    Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 14 Jun 2007
    9.3
    Critical

    CVE-2007-3210

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in nptoken.mox in the Cellosoft Tokens Object 2.0.0.6 extension for Vitalize! allows remote attackers to execute arbitrary code via a long string argument to the RemoveChr method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Jun 2007
    4.3
    Medium

    CVE-2007-3211

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in 404.php in Domain Technologie Control (DTC) before 0.25.9 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI). NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Jun 2007
    10
    Critical

    CVE-2007-3208

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Yet another Bulletin Board (YaBB) 2.1 allows remote attackers to obtain administrative access via requests to (1) register.pl or (2) profile.pl that write CRLF sequences to a .vars file. NOTE: this can be leveraged to execute arbitrary code.

    Published: 14 Jun 2007
    4.3
    Medium

    CVE-2007-2391

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the current page.

    Published: 14 Jun 2007
    6.8
    Medium

    CVE-2007-3257

    Last Modified: 23 Apr 2026

    Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

    Published: 14 Jun 2007
    5
    Medium

    CVE-2007-3205

    Last Modified: 23 Apr 2026

    The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.

    Published: 13 Jun 2007
    4.3
    Medium

    CVE-2007-2449

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrated by a URI containing a "snp/snoop.jsp;" sequence.

    Published: 13 Jun 2007
    3.5
    Low

    CVE-2007-2450

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.

    Published: 13 Jun 2007
    6.8
    Medium

    CVE-2006-4168

    Last Modified: 23 Apr 2026

    Integer overflow in the exif_data_load_data_entry function in libexif/exif-data.c in Libexif before 0.6.16 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via an image with many EXIF components, which triggers a heap-based buffer overflow.

    Published: 13 Jun 2007
    10
    Critical

    CVE-2007-3181

    Last Modified: 23 Apr 2026

    Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3188

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in down_indir.asp in Fullaspsite GeometriX Download Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Jun 2007
    4.3
    Medium

    CVE-2007-3189

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 12 Jun 2007
    6.8
    Medium

    CVE-2007-3190

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.

    Published: 12 Jun 2007
    9.4
    Critical

    CVE-2007-3191

    Last Modified: 23 Apr 2026

    Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3196

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3197

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 12 Jun 2007
    4.3
    Medium

    CVE-2007-3198

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in comments.php in Maran PHP Blog (Maran Blog), possibly only versions before 20070610, allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3199

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3203

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in smtpdll.dll in the SMTP service in 602Pro LAN SUITE 2003 2003.0.03.0828 allows remote attackers to execute arbitrary code via an e-mail message with a long address. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Jun 2007
    10
    Critical

    CVE-2007-3193

    Last Modified: 23 Apr 2026

    lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

    Published: 12 Jun 2007
    4.3
    Medium

    CVE-2007-3202

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document.

    Published: 12 Jun 2007
    9.4
    Critical

    CVE-2007-3192

    Last Modified: 23 Apr 2026

    admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.

    Published: 12 Jun 2007
    9.8
    Critical

    CVE-2007-3194

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE: another researcher disputes the vulnerability because the files are protected against direct requests, contain no relevant include statements, or do not exist

    Published: 12 Jun 2007
    4.3
    Medium

    CVE-2007-3195

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ERFAN WIKI 1.00 allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Jun 2007
    4.9
    Medium

    CVE-2007-3200

    Last Modified: 23 Apr 2026

    NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file.

    Published: 12 Jun 2007
    7.1
    High

    CVE-2007-3201

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3204

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Jun 2007
    7.8
    High

    CVE-2007-3185

    Last Modified: 23 Apr 2026

    Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-3186

    Last Modified: 23 Apr 2026

    Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.

    Published: 12 Jun 2007
    7.5
    High

    CVE-2007-3187

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a denial of service or execute arbitrary code, possibly involving memory corruption, and a different issue from CVE-2007-3185 and CVE-2007-3186. NOTE: as of 20070612, the original disclosure has no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 12 Jun 2007
    4.3
    Medium

    CVE-2007-2227

    Last Modified: 23 Apr 2026

    The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."

    Published: 12 Jun 2007
    7.2
    High

    CVE-2007-3184

    Last Modified: 23 Apr 2026

    Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System Preferences, including passwords, by invoking the Apple Menu when the Access Control Server (ACS) produces a user notification message after posture validation.

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-2219

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.

    Published: 12 Jun 2007
    4.3
    Medium

    CVE-2007-2225

    Last Modified: 23 Apr 2026

    A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure Vulnerability."

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-0218

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-0934

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-2218

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Windows Schannel Security Package for Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, allows remote servers to execute arbitrary code or cause a denial of service via crafted digital signatures that are processed during an SSL handshake.

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-1750

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.

    Published: 12 Jun 2007
    7.2
    High

    CVE-2007-2229

    Last Modified: 23 Apr 2026

    Microsoft Windows Vista uses insecure default permissions for unspecified "local user information data stores" in the registry and the file system, which allows local users to obtain sensitive information such as administrative passwords, aka "Permissive User Information Store ACLs Information Disclosure Vulnerability."

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-3027

    Last Modified: 23 Apr 2026

    Race condition in Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to install multiple language packs in a way that triggers memory corruption, aka "Language Pack Installation Vulnerability."

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-0936

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerability."

    Published: 12 Jun 2007
    Unknown

    CVE-2007-1752

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-1499. Reason: This candidate is a duplicate of CVE-2007-1499. Notes: All CVE users should reference CVE-2007-1499 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-1751

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-2222

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.

    Published: 12 Jun 2007
    7.8
    High

    CVE-2007-2796

    Last Modified: 23 Apr 2026

    Arris Cadant C3 CMTS allows remote attackers to cause a denial of service (service termination) via a malformed IP packet with an invalid IP option.

    Published: 12 Jun 2007
    9.4
    Critical

    CVE-2007-3180

    Last Modified: 23 Apr 2026

    Buffer overflow in Help and Support Center before 4.4 C on HP Windows systems allows remote attackers to read or write arbitrary files via unknown vectors.

    Published: 12 Jun 2007
    9.3
    Critical

    CVE-2007-0245

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in OpenOffice.org (OOo) 2.2.1 and earlier allows remote attackers to execute arbitrary code via a RTF file with a crafted prtdata tag with a length parameter inconsistency, which causes vtable entries to be overwritten.

    Published: 12 Jun 2007