CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-2897

    Last Modified: 23 Apr 2026

    Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests.

    Published: 30 May 2007
    4.9
    Medium

    CVE-2007-2907

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the forwardTo parameter to redirect.do. NOTE: the impact might be cross-site scripting (XSS) or HTTP request smuggling.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2908

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action.

    Published: 30 May 2007
    6.8
    Medium

    CVE-2007-2900

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/.

    Published: 30 May 2007
    5
    Medium

    CVE-2007-2906

    Last Modified: 23 Apr 2026

    Java Embedding Plugin 0.9.6.1 allows remote attackers to cause a denial of service (browser crash) via a Thread subclass that calls super.run from its run method.

    Published: 30 May 2007
    5
    Medium

    CVE-2007-2912

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to see the infraction "red flag" for a deleted user.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2914

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats 3.0.6b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) awards.php, (2) login.php, (3) register.php, (4) weapons.php, and possibly other unspecified files.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2915

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email.

    Published: 30 May 2007
    9.3
    Critical

    CVE-2007-2884

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2885

    Last Modified: 23 Apr 2026

    The NotSafe function in the MSVDTDatabaseDesigner7 ActiveX control in VDT70.DLL in Microsoft Visual Database Tools (MSVDT) Database Designer 7.0 allows remote attackers to cause a denial of service (Internet Explorer 6 crash) via a long argument.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2889

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2890

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2891

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2892

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 May 2007
    7.6
    High

    CVE-2007-2888

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.

    Published: 30 May 2007
    4.6
    Medium

    CVE-2007-2883

    Last Modified: 23 Apr 2026

    Credant Mobile Guardian Shield for Windows 5.2.1.105 and earlier stores account names and passwords in plaintext in memory, which allows local users to obtain sensitive information by (1) reading the paging file or (2) dumping and searching the memory image. NOTE: This issue crosses privilege boundaries because the product is intended to protect the data on a stolen computer.

    Published: 30 May 2007
    7.5
    High

    CVE-2007-2895

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbitrary code via a long Directory property value.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2887

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.

    Published: 30 May 2007
    4.3
    Medium

    CVE-2007-2896

    Last Modified: 23 Apr 2026

    Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.

    Published: 30 May 2007
    5
    Medium

    CVE-2007-2882

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.

    Published: 30 May 2007
    5
    Medium

    CVE-2007-2886

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Nortel CS 1000 M media card in Enterprise VoIP-Core-CS 1000E, 1000M, and 1000S 04.50W before 20070523 in Meridian/CS 1000 allows remote attackers to cause a denial of service (card hang) via unspecified vectors.

    Published: 30 May 2007
    2.1
    Low

    CVE-2007-2894

    Last Modified: 23 Apr 2026

    The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error.

    Published: 30 May 2007
    1.2
    Low

    CVE-2007-2453

    Last Modified: 23 Apr 2026

    The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.

    Published: 30 May 2007
    6.8
    Medium

    CVE-2007-0246

    Last Modified: 23 Apr 2026

    plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.

    Published: 29 May 2007
    7.1
    High

    CVE-2007-2389

    Last Modified: 23 Apr 2026

    Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets.

    Published: 29 May 2007
    9.3
    Critical

    CVE-2007-2388

    Last Modified: 23 Apr 2026

    Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.

    Published: 29 May 2007
    5
    Medium

    CVE-2007-2451

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in drivers/crypto/geode-aes.c in GEODE-AES in the Linux kernel before 2.6.21.3 allows attackers to obtain sensitive information via unspecified vectors.

    Published: 29 May 2007
    7.2
    High

    CVE-2007-2877

    Last Modified: 23 Apr 2026

    Buffer overflow in tcl/win/tclWinReg.c in Tcl (Tcl/Tk) before 8.5a6 allows local users to gain privileges via long registry key paths.

    Published: 29 May 2007
    4.3
    Medium

    CVE-2007-2879

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter.

    Published: 29 May 2007
    4.3
    Medium

    CVE-2007-2880

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp.

    Published: 29 May 2007
    10
    Critical

    CVE-2007-2881

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.

    Published: 29 May 2007
    5
    Medium

    CVE-2007-3393

    Last Modified: 23 Apr 2026

    Off-by-one error in the DHCP/BOOTP dissector in Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via crafted DHCP-over-DOCSIS packets.

    Published: 26 May 2007
    9.3
    Critical

    CVE-2007-2865

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.

    Published: 25 May 2007
    7.5
    High

    CVE-2007-2866

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in modules/admin/modules/gallery.php in PHPEcho CMS 2.0-rc1 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter and possibly other parameters. NOTE: some of these details are obtained from third party information.

    Published: 25 May 2007
    6.8
    Medium

    CVE-2007-0740

    Last Modified: 23 Apr 2026

    Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which might allow user-assisted attackers to trick a user into executing malicious files.

    Published: 24 May 2007
    7.2
    High

    CVE-2007-0753

    Last Modified: 23 Apr 2026

    Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.

    Published: 24 May 2007
    9.3
    Critical

    CVE-2007-0750

    Last Modified: 23 Apr 2026

    Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.

    Published: 24 May 2007
    7.2
    High

    CVE-2007-0752

    Last Modified: 23 Apr 2026

    The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.

    Published: 24 May 2007
    10
    Critical

    CVE-2007-2390

    Last Modified: 23 Apr 2026

    Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.

    Published: 24 May 2007
    2.1
    Low

    CVE-2007-0751

    Last Modified: 23 Apr 2026

    A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.

    Published: 24 May 2007
    9.4
    Critical

    CVE-2007-2386

    Last Modified: 23 Apr 2026

    Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.

    Published: 24 May 2007
    9.3
    Critical

    CVE-2007-2855

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2856.

    Published: 24 May 2007
    7.5
    High

    CVE-2007-2857

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter.

    Published: 24 May 2007
    6.5
    Medium

    CVE-2007-2858

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the IP-Search functionality in the IP-Tracking Mod for phpBB 2.0.x allows remote authenticated administrators to execute arbitrary SQL commands via the Search Query field.

    Published: 24 May 2007
    7.5
    High

    CVE-2007-2859

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SimpGB 1.46.0 allow remote attackers to execute arbitrary PHP code via a URL in the path_simpgb parameter to (1) guestbook.php, (2) search.php, (3) mailer.php, (4) avatars.php, (5) ccode.php, (6) comments.php, (7) emoticons.php, (8) gbdownload.php, and possibly other PHP scripts.

    Published: 24 May 2007
    10
    Critical

    CVE-2007-2853

    Last Modified: 23 Apr 2026

    The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function.

    Published: 24 May 2007
    9.3
    Critical

    CVE-2007-2856

    Last Modified: 23 Apr 2026

    Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.

    Published: 24 May 2007
    7.5
    High

    CVE-2007-2861

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Simple Accessible XHTML Online News (SAXON) 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the template parameter to (1) news.php, (2) preview.php, or (3) archive-display.php.

    Published: 24 May 2007
    7.5
    High

    CVE-2007-2854

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.

    Published: 24 May 2007
    9.3
    Critical

    CVE-2007-2852

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name.

    Published: 24 May 2007