CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2007-2746

    Last Modified: 23 Apr 2026

    The viewList function in lib/WebGUI/Asset/Wobject/DataForm.pm in Plain Black WebGUI before 7.3.14 does not properly use data structures containing privilege information, which allows remote authenticated users to obtain sensitive information or possibly have other unspecified impact.

    Published: 17 May 2007
    4.3
    Medium

    CVE-2007-2748

    Last Modified: 23 Apr 2026

    The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2751

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter to (1) admin/inc/change_action.php or (2) admin/inc/add.php.

    Published: 17 May 2007
    7.8
    High

    CVE-2007-1693

    Last Modified: 23 Apr 2026

    The SIP channel module in Yet Another Telephony Engine (Yate) before 1.2.0 sets the caller_info_uri parameter using an incorrect variable that can be NULL, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a Call-Info header without a purpose parameter.

    Published: 17 May 2007
    6.8
    Medium

    CVE-2007-2740

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in xajax before 0.2.5 has unknown impact and attack vectors, not related to XSS.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2742

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in labs.beffa.org w2box 4.0.0 Beta4 allows remote attackers to upload arbitrary PHP code via a filename with a double extension such as .php.jpg.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2744

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote attackers to cause a denial of service (Internet Explorer 6 crash), and possibly execute arbitrary code, via a long argument to the SaveBarCode method. NOTE: this issue might overlap CVE-2007-2657.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2735

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id_reserv parameter.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2738

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the sid parameter in an ImprDef action.

    Published: 17 May 2007
    10
    Critical

    CVE-2007-2736

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter.

    Published: 17 May 2007
    4.3
    Medium

    CVE-2007-2739

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 May 2007
    9.3
    Critical

    CVE-2007-2741

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2743

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter.

    Published: 17 May 2007
    7.5
    High

    CVE-2007-2737

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 May 2007
    9.3
    Critical

    CVE-2007-2568

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via a long (1) tag or (2) track type in a CUE file.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2725

    Last Modified: 23 Apr 2026

    The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary files via the SaveToFile function.

    Published: 16 May 2007
    7.8
    High

    CVE-2007-2726

    Last Modified: 23 Apr 2026

    BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with certain invalid strings in a pubDate element, as demonstrated by repeated "../A" or "A/../" patterns.

    Published: 16 May 2007
    2.6
    Low

    CVE-2007-2727

    Last Modified: 23 Apr 2026

    The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

    Published: 16 May 2007
    7.2
    High

    CVE-2007-2729

    Last Modified: 23 Apr 2026

    Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2734

    Last Modified: 23 Apr 2026

    The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTTP POST request, which might allow remote attackers to evade detection of HTTP traffic.

    Published: 16 May 2007
    5.5
    Medium

    CVE-2007-2723

    Last Modified: 23 Apr 2026

    Media Player Classic 6.4.9.0 allows user-assisted remote attackers to cause a denial of service (web browser crash) via an "empty" .MPA file, which triggers a divide-by-zero error.

    Published: 16 May 2007
    4
    Medium

    CVE-2007-2731

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in formmail.php in Jetbox CMS 2.1 might allow remote attackers to inject arbitrary e-mail headers via LF (%0A) sequences in the subject parameter, a related issue to CVE-2007-1898.

    Published: 16 May 2007
    5.8
    Medium

    CVE-2007-1898

    Last Modified: 23 Apr 2026

    formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTINGS[allowed_email_hosts][], and subject parameters.

    Published: 16 May 2007
    4.3
    Medium

    CVE-2007-2724

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Published: 16 May 2007
    5
    Medium

    CVE-2007-2728

    Last Modified: 23 Apr 2026

    The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

    Published: 16 May 2007
    7.2
    High

    CVE-2007-2730

    Last Modified: 23 Apr 2026

    Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.

    Published: 16 May 2007
    6.8
    Medium

    CVE-2007-2732

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter to view/search/; or the (2) companyname, (3) country, (4) email, (5) firstname, (6) middlename, (7) required, (8) surname, or (9) title parameter to view/supplynews/.

    Published: 16 May 2007
    6
    Medium

    CVE-2007-2733

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload arbitrary scripts via unspecified vectors, which can be accessed in webfiles/. NOTE: this issue might be a duplicate of CVE-2004-1448.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-1173

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the CentennialIPTransferServer service (XFERWAN.EXE), as used by (1) Centennial Discovery 2006 Feature Pack 1, (2) Numara Asset Manager 8.0, and (3) Symantec Discovery 6.5, allow remote attackers to execute arbitrary code via long strings in a crafted TCP packet.

    Published: 16 May 2007
    7.8
    High

    CVE-2007-2722

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instability) via certain invalid strings in the URL attribute of an ENCLOSURE element, as demonstrated by a "%s" sequence, a "%Y" sequence, a "%%" sequence, and an "n," sequence.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-1689

    Last Modified: 23 Apr 2026

    Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.

    Published: 16 May 2007
    9.4
    Critical

    CVE-2007-2439

    Last Modified: 23 Apr 2026

    Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to cause a denial of service (device hang) and read data from a COM or LPT device via a DOS device name with an arbitrary extension.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2717

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shop/page.php in iGeneric (iG) Shop 1.4 allows remote attackers to execute arbitrary SQL commands via the type_id[] parameter, a different vector than CVE-2005-0537.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-2719

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in HP Systems Insight Manager (SIM) 4.2 and 5.0 SP4 and SP5 allows remote attackers to hijack web sessions by setting the JSESSIONID cookie.

    Published: 16 May 2007
    4.3
    Medium

    CVE-2007-2720

    Last Modified: 23 Apr 2026

    Group-Office before 2.16-13 does not properly validate user IDs, which allows remote attackers to obtain sensitive information via certain requests for (1) message.php and (2) messages.php in modules/email/. NOTE: some of these details are obtained from third party information.

    Published: 16 May 2007
    5
    Medium

    CVE-2007-2441

    Last Modified: 23 Apr 2026

    Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to obtain the system path via certain URLs associated with (1) deploying web applications or (2) displaying .xtp files.

    Published: 16 May 2007
    6.8
    Medium

    CVE-2007-2716

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EQdkp 1.3.2c and earlier allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) listmembers.php and (2) stats.php. NOTE: some of these details are obtained from third party information.

    Published: 16 May 2007
    4.3
    Medium

    CVE-2007-2718

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.

    Published: 16 May 2007
    5
    Medium

    CVE-2007-2440

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Caucho Resin Professional 3.1.0 and Caucho Resin 3.1.0 and earlier for Windows allows remote attackers to read certain files via a .. (dot dot) in a URI containing a "\web-inf" sequence.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2708

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the action parameter.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2709

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][physical] parameter.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2710

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2.00-P00 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SETS[path][IT] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-2711

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-2713

    Last Modified: 23 Apr 2026

    ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.

    Published: 16 May 2007
    7.5
    High

    CVE-2007-2706

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the _MG_CONF[path_html] parameter.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-2715

    Last Modified: 23 Apr 2026

    Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.

    Published: 16 May 2007
    6.8
    Medium

    CVE-2007-2707

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-2712

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in MH Software Connect Daily before 3.3.3 has unknown impact and attack vectors.

    Published: 16 May 2007
    10
    Critical

    CVE-2007-2714

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in akismet.php in Matt Mullenweg Akismet before 2.0.2, a WordPress plugin, has unknown impact and attack vectors.

    Published: 16 May 2007
    7.8
    High

    CVE-2007-2689

    Last Modified: 23 Apr 2026

    Check Point Web Intelligence does not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.

    Published: 16 May 2007