CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-2791

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Secure Shell (SSH) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows remote attackers to identify valid users via unspecified vectors, probably related to timing attacks and AuthInteractiveFailureRandomTimeout.

    Published: 22 May 2007
    7.5
    High

    CVE-2007-2793

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.

    Published: 22 May 2007
    Unknown

    CVE-2007-5968

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6313. Reason: this candidate's description and references were inconsistent and described unrelated, non-security issues. The original intended issue is covered by CVE-2007-6313. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 May 2007
    7.5
    High

    CVE-2007-2792

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 22 May 2007
    6.8
    Medium

    CVE-2007-2790

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in shopcontent.asp in VP-ASP Shopping Cart 6.50, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the type parameter.

    Published: 22 May 2007
    7.5
    High

    CVE-2007-2773

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to execute arbitrary SQL commands via the speler parameter.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2779

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter.

    Published: 21 May 2007
    5
    Medium

    CVE-2007-2780

    Last Modified: 23 Apr 2026

    PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.

    Published: 21 May 2007
    6.8
    Medium

    CVE-2007-2781

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in include/sessionRegister.php in WikyBlog before 1.4.13 allows remote attackers to inject arbitrary web script or HTML, probably via vectors related to a certain data2 array element.

    Published: 21 May 2007
    6.8
    Medium

    CVE-2007-2785

    Last Modified: 23 Apr 2026

    manage-admins.php in eSyndiCat Pro 1.x allows remote attackers to create additional administrative accounts, and have other unspecified impact, via modified username, new_pass, new_pass2, status, super, and certain other parameters in an add action.

    Published: 21 May 2007
    5
    Medium

    CVE-2007-2786

    Last Modified: 23 Apr 2026

    Ratbox IRC Daemon (aka ircd-ratbox) 2.2.5 and earlier allows remote attackers to cause a denial of service (resource exhaustion) by making many requests from a single client.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2787

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in LeadTools Raster Thumbnail Object Library 14.5.0.44 allows remote attackers to execute arbitrary code via a long argument.

    Published: 21 May 2007
    10
    Critical

    CVE-2007-2776

    Last Modified: 23 Apr 2026

    AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.

    Published: 21 May 2007
    10
    Critical

    CVE-2007-2783

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Rational Soft Hidden Administrator 1.7 and earlier allows remote attackers to bypass authentication and execute arbitrary code via unspecified vectors. NOTE: this issue has no actionable information, and perhaps should not be included in CVE.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2774

    Last Modified: 6 Feb 2026

    Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) _connect.php or (2) modules/startup.php.

    Published: 21 May 2007
    7.8
    High

    CVE-2007-2778

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MolyX BOARD 2.5.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to index.php and other unspecified PHP scripts.

    Published: 21 May 2007
    7.8
    High

    CVE-2007-2784

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in globus-job-manager in Globus Toolkit 4.1.1 and earlier (globus_nexus-6.6 and earlier) allows remote attackers to cause a denial of service (resource exhaustion and system crash) via certain requests to temporary TCP ports for a GRAM2 job or its MPICH-G2 applications.

    Published: 21 May 2007
    10
    Critical

    CVE-2007-2775

    Last Modified: 23 Apr 2026

    AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request to admin/managesettings.php.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2777

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2782

    Last Modified: 23 Apr 2026

    Packeteer PacketShaper uses fixed increments in TCP initial sequence number (ISN) values, which allows remote attackers to predict the ISN value, and perform session hijacking or disruption.

    Published: 21 May 2007
    9.3
    Critical

    CVE-2007-2771

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property.

    Published: 21 May 2007
    7.8
    High

    CVE-2007-2772

    Last Modified: 23 Apr 2026

    (1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted RPC packet.

    Published: 21 May 2007
    9.3
    Critical

    CVE-2007-2770

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning about a possible buffer overflow exploit to trigger this issue.

    Published: 21 May 2007
    5
    Medium

    CVE-2007-2684

    Last Modified: 23 Apr 2026

    Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and (c) outputs.php; (2) a malformed view parameter to index.php, as demonstrated with an SQL injection manipulation; or (3) the id[] parameter to admin/cms/opentree.php, which reveals the installation path in the resulting error message.

    Published: 21 May 2007
    7.8
    High

    CVE-2007-2767

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 allows remote attackers to list filesystem contents and obtain sensitive information via unknown vectors.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2769

    Last Modified: 23 Apr 2026

    BES before 3.5.0 in OPeNDAP 4 (Hydrax) before 1.2.1 does not properly handle compressed files, which allows remote attackers to upload arbitrary files or execute arbitrary commands via a crafted compressed file.

    Published: 21 May 2007
    4.3
    Medium

    CVE-2007-2768

    Last Modified: 23 Apr 2026

    OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

    Published: 21 May 2007
    7.5
    High

    CVE-2007-2685

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.

    Published: 21 May 2007
    5
    Medium

    CVE-2007-1860

    Last Modified: 23 Apr 2026

    mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

    Published: 21 May 2007
    6.8
    Medium

    CVE-2007-2788

    Last Modified: 23 Apr 2026

    Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_20 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (JVM crash) via a crafted JPEG or BMP file that triggers a buffer overflow.

    Published: 21 May 2007
    4.3
    Medium

    CVE-2007-2789

    Last Modified: 23 Apr 2026

    The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.

    Published: 21 May 2007
    4.3
    Medium

    CVE-2007-1355

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.

    Published: 19 May 2007
    7.5
    High

    CVE-2007-2759

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the insert function in the ValuePreference class (grid/ed/ValuePreference.java) in Adempiere before 3.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) m_Attribute or (2) m_Value parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 May 2007
    9
    Critical

    CVE-2007-2760

    Last Modified: 23 Apr 2026

    The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.

    Published: 18 May 2007
    7.5
    High

    CVE-2007-2761

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file.

    Published: 18 May 2007
    7.2
    High

    CVE-2007-2766

    Last Modified: 23 Apr 2026

    lib/backup-methods.sh in Backup Manager before 0.7.6 provides the MySQL password as a plaintext command line argument, which allows local users to obtain this password by listing the process and its arguments, related to lib/backup-methods.sh.

    Published: 18 May 2007
    9.3
    Critical

    CVE-2007-2758

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow during extraction, or (2) a heap-based buffer overflow during traversal.

    Published: 18 May 2007
    10
    Critical

    CVE-2007-2763

    Last Modified: 23 Apr 2026

    Buffer overflow in the UnlockSupport function in the LockModules subsystem in a certain ActiveX control in ltmm15.dll in Sienzo Digital Music Mentor (DMM) 2.6.0.4 allows remote attackers to execute arbitrary code via a long string in the second argument, a different issue than CVE-2007-2564.

    Published: 18 May 2007
    6.8
    Medium

    CVE-2007-2757

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Redoable 1.2 allow remote attackers to inject arbitrary web script or HTML via the s parameter to (1) wp-content/themes/redoable/searchloop.php or (2) wp-content/themes/redoable/header.php.

    Published: 18 May 2007
    7.8
    High

    CVE-2007-2764

    Last Modified: 23 Apr 2026

    The embedded Linux kernel in certain Sun-Brocade SilkWorm switches before 20070516 does not properly handle a situation in which a non-root user creates a kernel process, which allows attackers to cause a denial of service (oops and device reboot) via unspecified vectors.

    Published: 18 May 2007
    6.8
    Medium

    CVE-2007-2765

    Last Modified: 23 Apr 2026

    blockhosts.py in BlockHosts before 2.0.3 does not properly parse daemon log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by logging in through ssh using a login name containing certain strings with an IP address, which is not properly handled by a regular expression, a related issue to CVE-2006-6301.

    Published: 18 May 2007
    7.5
    High

    CVE-2007-2762

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbitrary PHP code via a URL in (1) the pear_dir parameter to Base/Application.php, or the (2) sys_dir parameter to (a) Footer.php, (b) widget.BifContainer.php, (c) widget.BifRoot.php, (d) widget.BifRoot2.php, (e) widget.BifRoot3.php, or (f) widget.BifWarning.php in Widgets/Base/.

    Published: 18 May 2007
    7.5
    High

    CVE-2007-2682

    Last Modified: 23 Apr 2026

    The installer for Adobe Version Cue CS3 Server on Apple Mac OS X, as used in Adobe Creative Suite 3 (CS3), does not re-enable the personal firewall after completing the product installation, which allows remote attackers to bypass intended firewall rules.

    Published: 18 May 2007
    10
    Critical

    CVE-2007-2755

    Last Modified: 23 Apr 2026

    The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote attackers to overwrite arbitrary files via a full pathname to the SaveToFile function, a different vulnerability than CVE-2007-2744.

    Published: 17 May 2007
    4.3
    Medium

    CVE-2007-2745

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in printcal.pl in vDesk Webmail 4.03 allows remote attackers to inject arbitrary web script or HTML via the type parameter.

    Published: 17 May 2007
    5
    Medium

    CVE-2007-2749

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrary SQL commands via the questionref parameter in a display action.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in SimpNews 2.40.01 and earlier allows remote attackers to execute arbitrary SQL commands via the newsnr parameter.

    Published: 17 May 2007
    6.4
    Medium

    CVE-2007-2752

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 May 2007
    5
    Medium

    CVE-2007-2753

    Last Modified: 23 Apr 2026

    RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb.

    Published: 17 May 2007
    5
    Medium

    CVE-2007-2747

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.

    Published: 17 May 2007