CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-3130

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the OpenWiki (formerly JD-Wiki) component (com_jd-wiki) 1.0.2, and possibly earlier, for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) dwpage.php or (2) wantedpages.php, different vectors than CVE-2006-4074. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Jun 2007
    7.5
    High

    CVE-2007-3136

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute arbitrary PHP code via a URL in the newsSync_NUKE_PATH parameter.

    Published: 8 Jun 2007
    4.3
    Medium

    CVE-2007-3137

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in 4print.asp in WmsCMS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) sbl, (2) sbr, or (3) search parameter. NOTE: the original disclosure claims the pageid parameter in index.php is affected, but this is incorrect.

    Published: 8 Jun 2007
    4.3
    Medium

    CVE-2007-3135

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom Photoblog 1.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tag parameter.

    Published: 8 Jun 2007
    4.3
    Medium

    CVE-2007-3134

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using "Approve Comments."

    Published: 8 Jun 2007
    5
    Medium

    CVE-2007-3126

    Last Modified: 23 Apr 2026

    Gimp before 2.8.22 allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, a similar issue to CVE-2007-2237.

    Published: 8 Jun 2007
    4.4
    Medium

    CVE-2007-3740

    Last Modified: 23 Apr 2026

    The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.

    Published: 8 Jun 2007
    4.3
    Medium

    CVE-2007-3843

    Last Modified: 23 Apr 2026

    The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing despite sec=ntlmv2i in a SetupAndX request.

    Published: 8 Jun 2007
    4.6
    Medium

    CVE-2007-3124

    Last Modified: 23 Apr 2026

    Buffer overflow in backup/src/vmsbackup.c (aka the backup utility) in FreeVMS before 0.3.6 might allow local users to gain privileges via a long string in response to an "extract [ny]" prompt.

    Published: 7 Jun 2007
    Unknown

    CVE-2007-3125

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-6772. Reason: This candidate is a duplicate of CVE-2006-6772. Notes: All CVE users should reference CVE-2006-6772 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Jun 2007
    5
    Medium

    CVE-2007-3025

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service (hang) via unknown vectors related to the isURL function and regular expressions.

    Published: 7 Jun 2007
    2.1
    Low

    CVE-2007-3024

    Last Modified: 23 Apr 2026

    libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.

    Published: 7 Jun 2007
    9.3
    Critical

    CVE-2007-2948

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in stream/stream_cddb.c in MPlayer before 1.0rc1try3 allow remote attackers to execute arbitrary code via a CDDB entry with a long (1) album title or (2) category.

    Published: 7 Jun 2007
    10
    Critical

    CVE-2007-3023

    Last Modified: 23 Apr 2026

    unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors.

    Published: 7 Jun 2007
    6.4
    Medium

    CVE-2007-3109

    Last Modified: 23 Apr 2026

    The CERN Image Map Dispatcher (htimage.exe) in Microsoft FrontPage allows remote attackers to determine the existence, and possibly partial contents, of arbitrary files under the web root via a relative pathname in the PATH_INFO.

    Published: 7 Jun 2007
    5
    Medium

    CVE-2007-3114

    Last Modified: 23 Apr 2026

    Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.3.03, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3115 and CVE-2007-3116.

    Published: 7 Jun 2007
    7.8
    High

    CVE-2007-3115

    Last Modified: 23 Apr 2026

    Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x before 1.3.05, allow remote attackers to cause a denial of service (memory consumption) via (1) reverse lookups or (2) requests for records in a class other than Internet (IN), a different set of affected versions than CVE-2007-3114 and CVE-2007-3116.

    Published: 7 Jun 2007
    5
    Medium

    CVE-2007-3116

    Last Modified: 23 Apr 2026

    Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3114 and CVE-2007-3115.

    Published: 7 Jun 2007
    4.3
    Medium

    CVE-2007-3117

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the SEO module in ADPLAN 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to HTTP headers.

    Published: 7 Jun 2007
    5
    Medium

    CVE-2007-3123

    Last Modified: 23 Apr 2026

    unrar.c in libclamav in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to cause a denial of service (core dump) via a crafted RAR file with a modified vm_codesize value, which triggers a heap-based buffer overflow.

    Published: 7 Jun 2007
    4.3
    Medium

    CVE-2007-3120

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in public/code/cp_dpage.php in All In One Control Panel (AIOCP) before 1.3.017 allows remote attackers to inject arbitrary web script or HTML via the aiocp_dp parameter. NOTE: some of these details are obtained from third party information.

    Published: 7 Jun 2007
    4.3
    Medium

    CVE-2007-3110

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Andy Frank Beatnik 1.0 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via an RSS feed. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Jun 2007
    10
    Critical

    CVE-2007-3111

    Last Modified: 23 Apr 2026

    Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.

    Published: 7 Jun 2007
    7.8
    High

    CVE-2007-3112

    Last Modified: 23 Apr 2026

    graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.

    Published: 7 Jun 2007
    6.8
    Medium

    CVE-2007-3113

    Last Modified: 23 Apr 2026

    Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.

    Published: 7 Jun 2007
    7.5
    High

    CVE-2007-3121

    Last Modified: 23 Apr 2026

    Buffer overflow in the CCdecode function in contrib/ntsc-cc.c in the zvbi-ntsc-cc tool in Zapping VBI Library (ZVBI) before 0.2.25 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code via long data during a reception error. NOTE: some of these details are obtained from third party information.

    Published: 7 Jun 2007
    7.5
    High

    CVE-2007-2512

    Last Modified: 23 Apr 2026

    Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.

    Published: 7 Jun 2007
    7.5
    High

    CVE-2007-3118

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the scdir parameter to (1) action.php, (2) subs.php, or (3) unsubs.php.

    Published: 7 Jun 2007
    7.5
    High

    CVE-2007-3119

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Published: 7 Jun 2007
    5
    Medium

    CVE-2007-3122

    Last Modified: 23 Apr 2026

    The parsing engine in ClamAV before 0.90.3 and 0.91 before 0.91rc1 allows remote attackers to bypass scanning via a RAR file with a header flag value of 10, which can be processed by WinRAR.

    Published: 7 Jun 2007
    2.1
    Low

    CVE-2007-2875

    Last Modified: 23 Apr 2026

    Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.

    Published: 7 Jun 2007
    6.1
    Medium

    CVE-2007-2876

    Last Modified: 23 Apr 2026

    The sctp_new function in (1) ip_conntrack_proto_sctp.c and (2) nf_conntrack_proto_sctp.c in Netfilter in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, allows remote attackers to cause a denial of service by causing certain invalid states that trigger a NULL pointer dereference.

    Published: 7 Jun 2007
    9.3
    Critical

    CVE-2007-2919

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3) PAGENO, (4) LaunchMode, (5) SubID, (6) BookID, (7) LibraryID, (8) SubURL, and (9) LoadOpf properties.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3097

    Last Modified: 23 Apr 2026

    my.activation.php3 in F5 FirePass 4100 SSL VPN allows remote attackers to execute arbitrary shell commands via shell metacharacters in the username parameter.

    Published: 6 Jun 2007
    5
    Medium

    CVE-2007-3098

    Last Modified: 23 Apr 2026

    The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.

    Published: 6 Jun 2007
    9
    Critical

    CVE-2007-3095

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown vectors.

    Published: 6 Jun 2007
    6.8
    Medium

    CVE-2007-3096

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 6 Jun 2007
    10
    Critical

    CVE-2007-3093

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.

    Published: 6 Jun 2007
    9
    Critical

    CVE-2007-3094

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to execute arbitrary code via unspecified vectors, related to the WBEM server.

    Published: 6 Jun 2007
    Unknown

    CVE-2007-3090

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-0591. Reason: This candidate is a duplicate of CVE-2008-0591. Notes: All CVE users should reference CVE-2008-0591 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Jun 2007
    9.3
    Critical

    CVE-2007-0068

    Last Modified: 23 Apr 2026

    IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.

    Published: 6 Jun 2007
    10
    Critical

    CVE-2007-2863

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a long filename in a .CAB file.

    Published: 6 Jun 2007
    9.3
    Critical

    CVE-2007-2864

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

    Published: 6 Jun 2007
    7.1
    High

    CVE-2007-3091

    Last Modified: 23 Apr 2026

    Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a page transition, with the permissions of the old page and the content of the new page, as demonstrated by setInterval functions that set location.href within a try/catch expression, aka the "bait & switch vulnerability" or "Race Condition Cross-Domain Information Disclosure Vulnerability."

    Published: 6 Jun 2007
    9.3
    Critical

    CVE-2007-3092

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 allows remote attackers to spoof the URL bar, and page properties including SSL certificates, by interrupting page loading through certain use of location DOM objects and setTimeout calls. NOTE: this issue can be leveraged for phishing and other attacks.

    Published: 6 Jun 2007
    5.5
    Medium

    CVE-2007-2237

    Last Modified: 23 Apr 2026

    Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.

    Published: 6 Jun 2007
    4.6
    Medium

    CVE-2007-3069

    Last Modified: 23 Apr 2026

    xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3070

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BDigital Web Solutions WebStudio allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.

    Published: 6 Jun 2007
    9.3
    Critical

    CVE-2007-3071

    Last Modified: 23 Apr 2026

    Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3074

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

    Published: 6 Jun 2007