CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2007-3075

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Microsoft Internet Explorer allows remote attackers to read arbitrary files via directory traversal sequences in a URI with a certain scheme, possibly related to "..%5C" (encoded backslash) sequences.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-3076

    Last Modified: 23 Apr 2026

    A certain ActiveX control in sasatl.dll in Zenturi ProgramChecker allows remote attackers to download arbitrary files to the client system via the DownloadFile function.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3077

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listmembers.php in EQdkp 1.3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the rank parameter.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3078

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Aigaion before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter (Authors and Publication titles) to (1) authoractions.php or (2) publicationactions.php.

    Published: 6 Jun 2007
    7.1
    High

    CVE-2007-3079

    Last Modified: 23 Apr 2026

    listmembers.php in EQdkp 1.3.2c and earlier allows remote attackers to obtain sensitive information via an invalid compare parameter, which reveals the path.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3084

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter, a different vector than CVE-2006-5441.

    Published: 6 Jun 2007
    4.9
    Medium

    CVE-2007-3086

    Last Modified: 23 Apr 2026

    Unrestricted critical resource lock in Agnitum Outpost Firewall PRO 4.0 1007.591.145 and earlier allows local users to cause a denial of service (system hang) by capturing the outpost_ipc_hdr mutex.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-3087

    Last Modified: 23 Apr 2026

    Peercast places a cleartext password in a query string, which might allow attackers to obtain sensitive information by sniffing the network, or obtaining Referer or browser history information.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3088

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Comicsense allows remote attackers to execute arbitrary SQL commands via the epi parameter.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-0067

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.

    Published: 6 Jun 2007
    9.3
    Critical

    CVE-2007-2514

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in XferWan.exe as used in multiple products including (1) Symantec Discovery 6.5, (2) Numara Asset Manager 8.0, and (3) Centennial UK Ltd Discovery 2006 Feature Pack, allows remote attackers to execute arbitrary code via a long request. NOTE: this might be a reservation duplicate of CVE-2007-1173.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-3082

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sc_language parameter.

    Published: 6 Jun 2007
    10
    Critical

    CVE-2007-2419

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-3073

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3080

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in haberoku.asp in Hunkaray Okul Portaly 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-3083

    Last Modified: 23 Apr 2026

    Z-Blog 1.7 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for zblog.mdb.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3085

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PBSite allow remote attackers to execute arbitrary PHP code via a URL in the (1) dbpath parameter to (a) useronline.php, (b) ucp.php, (c) setcookie.php, (d) sendpm.php, (e) search.php, (f) register.php, (g) profile.php, (h) post.php, (i) pmpshow.php, (j) pm.php, (k) ntopic.php, (l) nreply.php, (m) news.php, (n) memberslist.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (u) editpost.php, (v) delpost.php, (w) delpm.php, (x) confirm.php, (y) board.php, (z) admin2.php, (aa) admin.php, or (bb) templates/pb/css/formstyles.php; or the (2) temppath parameter to (a) useronline.php, (c) setcookie.php, (e) search.php, (f) register.php, (h) post.php, (l) nreply.php, (m) news.php, (o) logout.php, (p) login.php, (q) index.php, (r) help.php, (s) forum.php, (t) error.php, (w) delpm.php, (x) confirm.php, or (y) board.php.

    Published: 6 Jun 2007
    7.1
    High

    CVE-2007-3072

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3081

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sampleecommerce.php in Comdev eCommerce 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3049

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Buttercup web file manager (BWFM) May 2007 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3050

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3051

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to execute arbitrary SQL commands via the revokebb_user cookie.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3052

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the PNphpBB2 1.2i and earlier module for PostNuke allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3053

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Calimero.CMS 3.3.1232 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 6 Jun 2007
    5
    Medium

    CVE-2007-3059

    Last Modified: 23 Apr 2026

    SendCard 3.3.0 allows remote attackers to obtain sensitive information via an invalid sc_language parameter to sendcard.php, which reveals the path in an error message.

    Published: 6 Jun 2007
    7.8
    High

    CVE-2007-3061

    Last Modified: 23 Apr 2026

    Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3062

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3067

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Attunement and Key Tracker 0.95 and earlier plugin for EQdkp allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the (1) keyshow, (2) sortkey, and (3) show parameters to index.php.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3056

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in filedetails.php in WebSVN 2.0rc4, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the path parameter.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3054

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the kword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Jun 2007
    6.8
    Medium

    CVE-2007-3057

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/wysiwyg/spaw_control.class.php in the icontent 4.5 module for XOOPS allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: this issue is probably a duplicate of CVE-2006-4656.

    Published: 6 Jun 2007
    6.8
    Medium

    CVE-2007-3058

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Madirish Webmail 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter to (1) calendar.php, (2) compose.php, and (3) index.php, different vectors than CVE-2007-2826. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3060

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Live! 3.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to (a) chat.php, (2) LANG[DEFAULT_BRANDING] and (3) PHPLIVE_VERSION parameters to (b) help.php, the (4) admin[name] parameter to (c) admin/header.php, and the (5) BASE_URL parameter to (d) super/info.php, and in some cases, the LANG[DEFAULT_BRANDING], PHPLIVE_VERSION, and (6) nav_line parameters to setup/footer.php, different vectors than CVE-2006-6769.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3064

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in diary.php in My Databook allows remote attackers to inject arbitrary web script or HTML via the year parameter.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3066

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in php(Reactor) 1.2.7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter to (1) view.inc.php, (2) users.inc.php, (3) updatecms.inc.php, and (4) polls.inc.php in inc/; and other unspecified files, different vectors than CVE-2006-3983.

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3055

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Codelib Linker 2.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3063

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in diary.php in My Databook allows remote attackers to execute arbitrary SQL commands via the delete parameter.

    Published: 6 Jun 2007
    7.5
    High

    CVE-2007-3065

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the editcomment parameter, a different version and vector than CVE-2006-2862.

    Published: 6 Jun 2007
    6.8
    Medium

    CVE-2007-3068

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.

    Published: 6 Jun 2007
    6.4
    Medium

    CVE-2007-3143

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.

    Published: 6 Jun 2007
    7.2
    High

    CVE-2007-3149

    Last Modified: 23 Apr 2026

    sudo, when linked with MIT Kerberos 5 (krb5), does not properly check whether a user can currently authenticate to Kerberos, which allows local users to gain privileges, in a manner unintended by the sudo security model, via certain KRB5_ environment variable settings. NOTE: another researcher disputes this vulnerability, stating that the attacker must be "a user, who can already log into your system, and can already use sudo."

    Published: 6 Jun 2007
    4.3
    Medium

    CVE-2007-3042

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Meneame before 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2007
    5
    Medium

    CVE-2007-3044

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Map I/O Service (xpwmap) in Hitachi XP/W on HI-UX/WE2 before 20070319, and XP/W on HP-UX before 20070405, allows remote attackers to cause a denial of service via certain data to the service port.

    Published: 5 Jun 2007
    5
    Medium

    CVE-2007-3045

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi TP1/NET/OSI-TP-Extended on HI-UX/WE2 before 20070213, and on HP-UX before 20070314, allows remote attackers to cause a denial of service via certain data to a port.

    Published: 5 Jun 2007
    4.3
    Medium

    CVE-2007-3043

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Collaboration - File Sharing 01-20 up to 01-20-/B and 01-30 up to 01-30-/B in Hitachi Groupmax Collaboration Portal up to 07-30-/D, Groupmax Collaboration Web Client - Forum/File Sharing up to 07-30-/C, uCosminexus Collaboration Portal up to 06-30-/D, and uCosminexus Collaboration Portal - Forum/File Sharing up to 06-30-/C on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2007
    10
    Critical

    CVE-2007-3047

    Last Modified: 23 Apr 2026

    The Vonage VoIP Telephone Adapter has a default administrator username "user" and password "user," which allows remote attackers to obtain administrative access.

    Published: 5 Jun 2007
    5
    Medium

    CVE-2007-3046

    Last Modified: 23 Apr 2026

    Buffer overflow in Advanced Software Production Line Vortex Library before 1.0.3 allows remote attackers to cause a denial of service (listener crash) via unspecified vectors related to the select I/O implementation and the file set buffer. NOTE: some of these details are obtained from third party information.

    Published: 5 Jun 2007
    7.2
    High

    CVE-2007-3048

    Last Modified: 23 Apr 2026

    GNU screen 4.0.3 allows local users to unlock the screen via a CTRL-C sequence at the password prompt. NOTE: multiple third parties report inability to reproduce this issue

    Published: 5 Jun 2007
    Unknown

    CVE-2007-0993

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-0933. Reason: This candidate is a duplicate of CVE-2007-0933 due to a typo. Notes: All CVE users should reference CVE-2007-0933 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Jun 2007
    7.5
    High

    CVE-2007-3021

    Last Modified: 23 Apr 2026

    Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations of a file that is created during data export.

    Published: 5 Jun 2007