CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-3179

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in archives.php in Particle Blogger 1.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the month parameter and other unspecified vectors.

    Published: 11 Jun 2007
    9.3
    Critical

    CVE-2007-2920

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Zoomify Viewer ActiveX control in ZActiveX.dll might allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3153

    Last Modified: 23 Apr 2026

    The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.

    Published: 11 Jun 2007
    10
    Critical

    CVE-2007-3154

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.

    Published: 11 Jun 2007
    10
    Critical

    CVE-2007-3155

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier.

    Published: 11 Jun 2007
    4.3
    Medium

    CVE-2007-3156

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in pam_login.cgi in Webmin before 1.350 and Usermin before 1.280 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) message, or (3) question parameter. NOTE: some of these details are obtained from third party information.

    Published: 11 Jun 2007
    6.8
    Medium

    CVE-2007-3161

    Last Modified: 23 Apr 2026

    Buffer overflow in Ace-FTP Client 1.24a allows user-assisted, remote FTP servers to execute arbitrary code via a long response.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3162

    Last Modified: 23 Apr 2026

    Buffer overflow in the NotSafe function in the idaiehlp ActiveX control in idaiehlp.dll 1.9.1.74 in Internet Download Accelerator (ida) 5.2 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long argument.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3163

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3165

    Last Modified: 23 Apr 2026

    Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.

    Published: 11 Jun 2007
    4.3
    Medium

    CVE-2007-3170

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Uebimiau Webmail allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to redirect.php or (2) the selected_theme parameter to demo/pop3/error.php.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3171

    Last Modified: 23 Apr 2026

    Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3172

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in demo/pop3/error.php in Uebimiau Webmail allows remote attackers to determine the existence of arbitrary directories via an absolute pathname and .. (dot dot) in the selected_theme parameter.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3173

    Last Modified: 23 Apr 2026

    Almnzm allows remote attackers to obtain sensitive information via an activateorder request to index.php with an invalid orderid parameter, probably related to '[' and ']' characters.

    Published: 11 Jun 2007
    4.3
    Medium

    CVE-2007-3174

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in auth.w2b in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the adtype parameter, a different vector than CVE-2006-1980.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3151

    Last Modified: 23 Apr 2026

    rpttop.htm in the web management interface in Packeteer PacketShaper 7.3.0g2 and 7.5.0g1 allows remote attackers to cause a denial of service (device reboot) via a request with empty values of the OP.MEAS.DATAQUERY and MEAS.TYPE parameters.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3159

    Last Modified: 23 Apr 2026

    http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header.

    Published: 11 Jun 2007
    4
    Medium

    CVE-2007-3176

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Ingate Firewall and SIParator before 4.5.2 allows remote authenticated users without full privileges to download a Support Report.

    Published: 11 Jun 2007
    7.5
    High

    CVE-2007-3152

    Last Modified: 23 Apr 2026

    c-ares before 1.4.0 uses a predictable seed for the random number generator for the DNS Transaction ID field, which might allow remote attackers to spoof DNS responses by guessing the field value.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3157

    Last Modified: 23 Apr 2026

    IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related to the IPv6 support for IPSec.

    Published: 11 Jun 2007
    7.5
    High

    CVE-2007-3160

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.

    Published: 11 Jun 2007
    5.8
    Medium

    CVE-2007-3164

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7, when prompting for HTTP Basic Authentication for an IDN web site, uses ACE labels for the domain name in the status bar, but uses internationalized labels for this name in the authentication dialog, which might allow remote attackers to perform phishing attacks if the user misinterprets confusable characters in the internationalized labels, as demonstrated by displaying xn--theshmogroup-bgk.com only in the status bar.

    Published: 11 Jun 2007
    7.6
    High

    CVE-2007-3167

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to execute arbitrary code via a long PtzUrl property value.

    Published: 11 Jun 2007
    7.8
    High

    CVE-2007-3168

    Last Modified: 23 Apr 2026

    A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.

    Published: 11 Jun 2007
    7.5
    High

    CVE-2007-3178

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Zindizayn Okul Web Sistemi 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) pass parameter to (a) mezungiris.asp or (b) ogretmenkontrol.asp.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3158

    Last Modified: 23 Apr 2026

    download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter.

    Published: 11 Jun 2007
    6.8
    Medium

    CVE-2007-3166

    Last Modified: 23 Apr 2026

    Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command.

    Published: 11 Jun 2007
    9.3
    Critical

    CVE-2007-3169

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long first argument to the HttpDownloadFile method.

    Published: 11 Jun 2007
    7.5
    High

    CVE-2007-3175

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in W2B Online Banking allow remote attackers to execute arbitrary SQL commands via (1) the draft parameter to mailer.w2b or (2) the listDocPay parameter to DocPay.w2b.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3177

    Last Modified: 23 Apr 2026

    Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.

    Published: 11 Jun 2007
    4.3
    Medium

    CVE-2006-3974

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk parameter.

    Published: 11 Jun 2007
    9.3
    Critical

    CVE-2007-3150

    Last Modified: 23 Apr 2026

    Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file, which is displayed in the "results stored on your computer" portion of the search results, and when clicked invokes Google Desktop to execute this file.

    Published: 11 Jun 2007
    6.8
    Medium

    CVE-2007-3141

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in core/editor.php in phpWebThings 1.5.2 allows remote attackers to execute arbitrary PHP code via a URL in the editor_insert_top parameter. NOTE: the editor_insert_bottom vector is already covered by CVE-2006-6042.

    Published: 11 Jun 2007
    5.8
    Medium

    CVE-2007-3142

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Opera 9.21 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after 34 characters, as demonstrated by a phishing attack using HTTP Basic Authentication.

    Published: 11 Jun 2007
    5
    Medium

    CVE-2007-3146

    Last Modified: 23 Apr 2026

    Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb.

    Published: 11 Jun 2007
    9.3
    Critical

    CVE-2007-3148

    Last Modified: 23 Apr 2026

    Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.

    Published: 11 Jun 2007
    5.8
    Medium

    CVE-2007-3145

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Galeon 2.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.

    Published: 11 Jun 2007
    6.4
    Medium

    CVE-2007-3144

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.

    Published: 11 Jun 2007
    9.3
    Critical

    CVE-2007-3147

    Last Modified: 23 Apr 2026

    Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party information.

    Published: 11 Jun 2007
    1.9
    Low

    CVE-2007-2873

    Last Modified: 23 Apr 2026

    SpamAssassin 3.1.x, 3.2.0, and 3.2.1 before 20070611, when running as root in unusual configurations using vpopmail or virtual users, allows local users to cause a denial of service (corrupt arbitrary files) via a symlink attack on a file that is used by spamd.

    Published: 11 Jun 2007
    2.1
    Low

    CVE-2007-3099

    Last Modified: 23 Apr 2026

    usr/mgmt_ipc.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 checks the client's UID on the listening AF_LOCAL socket instead of the new connection, which allows remote attackers to access the management interface and cause a denial of service (iscsid exit or iSCSI connection loss).

    Published: 11 Jun 2007
    2.1
    Low

    CVE-2007-3100

    Last Modified: 23 Apr 2026

    usr/log.c in iscsid in open-iscsi (iscsi-initiator-utils) before 2.0-865 uses a semaphore with insecure permissions (world-writable/world-readable) for managing log messages using shared memory, which allows local users to cause a denial of service (hang) by grabbing the semaphore.

    Published: 11 Jun 2007
    4.9
    Medium

    CVE-2007-3513

    Last Modified: 23 Apr 2026

    The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption).

    Published: 11 Jun 2007
    10
    Critical

    CVE-2007-1685

    Last Modified: 23 Apr 2026

    Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.

    Published: 8 Jun 2007
    4.3
    Medium

    CVE-2007-3131

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 8 Jun 2007
    5
    Medium

    CVE-2007-3132

    Last Modified: 23 Apr 2026

    Multiple vulnerabilities in Symantec Ghost Solution Suite 2.0.0 and earlier, with Ghost 8.0.992 and possibly other versions, allow remote attackers to cause a denial of service (client or server crash) via malformed requests to the daemon port, 1346/udp or 1347/udp.

    Published: 8 Jun 2007
    6.8
    Medium

    CVE-2007-3133

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in urunbak.asp in W1L3D4 WEBmarket 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 8 Jun 2007
    7.5
    High

    CVE-2007-3138

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in an sLanguage cookie, which is used to define a value in config/general.php.

    Published: 8 Jun 2007
    6.8
    Medium

    CVE-2007-3139

    Last Modified: 23 Apr 2026

    config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to access the application via a login action to admin.php. NOTE: this can be leveraged to upload and execute arbitrary code.

    Published: 8 Jun 2007
    6.5
    Medium

    CVE-2007-3140

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL commands via a parameter value in an XML RPC wp.suggestCategories methodCall, a different vector than CVE-2007-1897.

    Published: 8 Jun 2007