CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-2489

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in LiveData Protocol Server 5.00.045, and other versions before update 500062 (5.00.062), allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request for a WSDL file that causes a negative length to be used in a strncpy call.

    Published: 3 May 2007
    7.8
    High

    CVE-2007-2490

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in LiveData Server before 5.00.62 allows remote attackers to cause a denial of service (exit) via crafted Connection-Oriented Transport Protocol (COTP) packets.

    Published: 3 May 2007
    4.6
    Medium

    CVE-2007-2480

    Last Modified: 23 Apr 2026

    The _udp_lib_get_port function in net/ipv4/udp.c in Linux kernel 2.6.21 and earlier does not prevent a bind to a port with a local address when there is already a bind to that port with a wildcard local address, which might allow local users to intercept local traffic for daemons or other applications.

    Published: 3 May 2007
    6.8
    Medium

    CVE-2007-2481

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

    Published: 3 May 2007
    6.8
    Medium

    CVE-2007-2482

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the wpPATH parameter.

    Published: 3 May 2007
    6.8
    Medium

    CVE-2007-2483

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.

    Published: 3 May 2007
    6.8
    Medium

    CVE-2007-2484

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

    Published: 3 May 2007
    7.5
    High

    CVE-2007-2487

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287.

    Published: 3 May 2007
    5
    Medium

    CVE-2007-2486

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter.

    Published: 3 May 2007
    7.5
    High

    CVE-2007-2485

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in myflash-button.php in the myflash 1.00 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the wpPATH parameter.

    Published: 3 May 2007
    2.6
    Low

    CVE-2007-2509

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.

    Published: 3 May 2007
    5.1
    Medium

    CVE-2007-2510

    Last Modified: 23 Apr 2026

    Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters.

    Published: 3 May 2007
    7.5
    High

    CVE-2007-2477

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in phpMyChat.php3 in phpMyChat 0.14.5 allows remote attackers to execute arbitrary PHP code via a URL in the {ChatPath} parameter. NOTE: this has been disputed by multiple third parties and CVE because $ChatPath is set to a constant value

    Published: 3 May 2007
    9.3
    Critical

    CVE-2007-2478

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the IRC component in Cerulean Studios Trillian Pro before 3.1.5.1 allow remote attackers to corrupt memory and possibly execute arbitrary code via (1) a URL with a long UTF-8 string, which triggers the overflow when the user highlights it, or (2) a font HTML tag with a face attribute containing a long UTF-8 string.

    Published: 3 May 2007
    5.9
    Medium

    CVE-2007-2479

    Last Modified: 23 Apr 2026

    Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via long CTCP PING messages that contain UTF-8 characters, which generates a malformed response that is not truncated by a newline, which can cause portions of a server message to be sent to the attacker.

    Published: 3 May 2007
    7.2
    High

    CVE-2007-2511

    Last Modified: 23 Apr 2026

    Buffer overflow in the user_filter_factory_create function in PHP before 5.2.2 has unknown impact and local attack vectors.

    Published: 3 May 2007
    7.5
    High

    CVE-2007-1864

    Last Modified: 23 Apr 2026

    Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.

    Published: 3 May 2007
    6.5
    Medium

    CVE-2007-2475

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ADSCHEMA utility in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to granting "users excess permissions to their own attributes."

    Published: 2 May 2007
    10
    Critical

    CVE-2007-2476

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to Active Directory (AD) password changes.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2473

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.

    Published: 2 May 2007
    5
    Medium

    CVE-2007-2471

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrary files via a full pathname in the form parameter.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2474

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) include/payment/payflow_pro.php, (2) global.php, or (3) libsecure.php, different vectors than CVE-2007-2070.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.

    Published: 2 May 2007
    5.8
    Medium

    CVE-2007-2470

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.

    Published: 2 May 2007
    4.3
    Medium

    CVE-2007-2472

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 May 2007
    7.1
    High

    CVE-2007-2464

    Last Modified: 23 Apr 2026

    Race condition in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)19, when using "clientless SSL VPNs," allows remote attackers to cause a denial of service (device reload) via "non-standard SSL sessions."

    Published: 2 May 2007
    4.7
    Medium

    CVE-2007-2465

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-2466

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the LDAP Software Development Kit (SDK) for C, as used in Sun Java System Directory Server 5.2 up to Patch 4 and Sun ONE Directory Server 5.1, allows remote attackers to cause a denial of service (crash) via certain BER encodings.

    Published: 2 May 2007
    4.9
    Medium

    CVE-2007-2467

    Last Modified: 23 Apr 2026

    ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.

    Published: 2 May 2007
    4.9
    Medium

    CVE-2007-2468

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP OpenVMS for Integrity Servers 8.2-1 and 8.3 allows local users to cause a denial of service (crash) via "Program actions relating to exceptions."

    Published: 2 May 2007
    10
    Critical

    CVE-2007-2462

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 before 7.2(2)8, when using Layer 2 Tunneling Protocol (L2TP) or Remote Management Access, allows remote attackers to bypass LDAP authentication and gain privileges via unknown vectors.

    Published: 2 May 2007
    10
    Critical

    CVE-2007-2418

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that triggers the overflow from expansion that occurs during encoding.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-2463

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) and PIX 7.1 before 7.1(2)49 and 7.2 before 7.2(2)17 allows remote attackers to cause a denial of service (device reload) via unknown vectors related to VPN connection termination and password expiry.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-2461

    Last Modified: 23 Apr 2026

    The DHCP relay agent in Cisco Adaptive Security Appliance (ASA) and PIX 7.2 allows remote attackers to cause a denial of service (dropped packets) via a DHCPREQUEST or DHCPINFORM message that causes multiple DHCPACK messages to be sent from DHCP servers to the agent, which consumes the memory allocated for a local buffer. NOTE: this issue only occurs when multiple DHCP servers are used.

    Published: 2 May 2007
    7.1
    High

    CVE-2007-0745

    Last Modified: 23 Apr 2026

    The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories.

    Published: 2 May 2007
    4.6
    Medium

    CVE-2007-1859

    Last Modified: 23 Apr 2026

    XScreenSaver 4.10, when using a remote directory service for credentials, does not properly handle the results from the getpwuid function in drivers/lock.c when there is no network connectivity, which causes XScreenSaver to crash and unlock the screen and allows local users to bypass authentication.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-1069

    Last Modified: 23 Apr 2026

    The memory management in VMware Workstation before 5.5.4 allows attackers to cause a denial of service (Windows virtual machine crash) by triggering certain general protection faults (GPF).

    Published: 2 May 2007
    7.8
    High

    CVE-2007-1337

    Last Modified: 23 Apr 2026

    The virtual machine process (VMX) in VMware Workstation before 5.5.4 does not properly read state information when moving from the ACPI sleep state to the run state, which allows attackers to cause a denial of service (virtual machine reboot) via unknown vectors.

    Published: 2 May 2007
    6.3
    Medium

    CVE-2007-1744

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Shared Folders feature for VMware Workstation before 5.5.4, when a folder is shared, allows users on the guest system to write to arbitrary files on the host system via the "Backdoor I/O Port" interface.

    Published: 2 May 2007
    7.2
    High

    CVE-2007-1876

    Last Modified: 23 Apr 2026

    VMware Workstation before 5.5.4, when running a 64-bit Windows guest on a 64-bit host, allows local users to "corrupt the virtual machine's register context" by debugging a local program and stepping into a "syscall instruction."

    Published: 2 May 2007
    7.8
    High

    CVE-2007-1877

    Last Modified: 23 Apr 2026

    VMware Workstation before 5.5.4 allows attackers to cause a denial of service against the guest OS by causing the virtual machine process (VMX) to store malformed configuration information.

    Published: 2 May 2007
    10
    Critical

    CVE-2007-0655

    Last Modified: 23 Apr 2026

    The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2457

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2460

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/admin/include/config.php in FireFly 1.1.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2458

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Pixaria Gallery before 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in the cfg[sys][base_path] parameter to psg.smarty.lib.php and certain include and library scripts, a different vector than CVE-2007-2457.

    Published: 2 May 2007
    7.8
    High

    CVE-2007-2459

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the BMP reader (bmp.c) in Imager perl module (libimager-perl) 0.45 through 0.56 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted 8-bit/pixel compressed BMP files.

    Published: 2 May 2007
    7.5
    High

    CVE-2007-2456

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP code via a URL in the doc_root parameter to (1) localize.php or (2) config.php in modules/admin/include/.

    Published: 2 May 2007
    6.8
    Medium

    CVE-2007-2454

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the VGA device in Parallels allows local users, with root access to the guest operating system, to terminate the virtual machine and possibly execute arbitrary code in the host operating system via unspecified vectors related to bitblt operations.

    Published: 2 May 2007
    6.1
    Medium

    CVE-2007-2455

    Last Modified: 23 Apr 2026

    Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a write operation to (4) SEGR6 or (5) SEGR7.

    Published: 2 May 2007
    5.5
    Medium

    CVE-2007-2437

    Last Modified: 23 Apr 2026

    The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remote authenticated users to cause a denial of service (daemon crash) via crafted values to the (1) XRenderCompositeTrapezoids and (2) XRenderAddTraps functions, which trigger a divide-by-zero error.

    Published: 2 May 2007