CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-2053

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path. NOTE: the aimage vector (3c) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2054

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls in (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/aimage.cpp, (f) aimage/imager.cpp, and (g) tools/afxml.cpp. NOTE: the aimage.cpp vector (e) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.

    Published: 30 Apr 2007
    5.8
    Medium

    CVE-2007-2349

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2355

    Last Modified: 23 Apr 2026

    The get_url function in DODS_Dispatch.pm for the CGI_server in OPeNDAP 3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2358

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3) control_path parameters to blogs/admin.php; and the (4) skins_path parameter to (h) blogs/contact.php and (i) blogs/multiblogs.php. NOTE: this issue is disputed by CVE, since the inc_path, view_path, control_path, and skins_path variables are all initialized in conf/_advanced.php before they are used

    Published: 30 Apr 2007
    7.2
    High

    CVE-2007-2359

    Last Modified: 23 Apr 2026

    Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.

    Published: 30 Apr 2007
    6.8
    Medium

    CVE-2007-2360

    Last Modified: 23 Apr 2026

    Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating the key.

    Published: 30 Apr 2007
    4.9
    Medium

    CVE-2007-2361

    Last Modified: 23 Apr 2026

    Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the credentials by reading the file.

    Published: 30 Apr 2007
    8.5
    High

    CVE-2007-2363

    Last Modified: 23 Apr 2026

    Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.

    Published: 30 Apr 2007
    9.3
    Critical

    CVE-2007-2365

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

    Published: 30 Apr 2007
    7.8
    High

    CVE-2007-2029

    Last Modified: 23 Apr 2026

    File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.

    Published: 30 Apr 2007
    Unknown

    CVE-2007-2056

    Last Modified: 7 Nov 2023

    The getlock function in aimage/aimage.cpp in AFFLIB 2.2.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary lock files (aka "time-of-check-time-of-use file race"). NOTE: the researcher has retracted the original advisory, stating that "the portion of vulnerable code is not called in any current version of AFFLIB and is therefore not exploitable.

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2055

    Last Modified: 23 Apr 2026

    AFFLIB 2.2.8 and earlier allows attackers to execute arbitrary commands via shell metacharacters involving (1) certain command line parameters in tools/afconvert.cpp and (2) arguments to the get_parameter function in aimage/ident.cpp. NOTE: it is unknown if the get_parameter vector (2) is ever called.

    Published: 30 Apr 2007
    6.5
    Medium

    CVE-2007-2350

    Last Modified: 23 Apr 2026

    admin/config.php in the music-on-hold module in freePBX 2.2.x allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the del parameter.

    Published: 30 Apr 2007
    7.2
    High

    CVE-2007-2351

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2352

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in AFFLIB 2.2.6 allow remote attackers to execute arbitrary code via certain command line parameters, which are used in (1) warn and (2) err calls, possibly involving (a) lib/s3.cpp, (b) tools/afconvert.cpp, (c) tools/afcopy.cpp, (d) tools/afinfo.cpp, (e) aimage/imager.cpp, and (f) tools/afxml.cpp. NOTE: this identifier is intended to address the vectors that were not fixed in CVE-2007-2054, but the unfixed vectors were not explicitly listed.

    Published: 30 Apr 2007
    5
    Medium

    CVE-2007-2353

    Last Modified: 23 Apr 2026

    Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.

    Published: 30 Apr 2007
    7.8
    High

    CVE-2007-2354

    Last Modified: 23 Apr 2026

    Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", which reveals the operating system and product information.

    Published: 30 Apr 2007
    9
    Critical

    CVE-2007-2362

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2364

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) mysql.class.php or (2) postgres.class.php in lib/db/; or (3) authuser.php, (4) misc.php, or (5) connect.php in lib/.

    Published: 30 Apr 2007
    7.4
    High

    CVE-2007-2366

    Last Modified: 23 Apr 2026

    Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.

    Published: 30 Apr 2007
    10
    Critical

    CVE-2007-2435

    Last Modified: 23 Apr 2026

    Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perform unauthorized actions via an application that grants privileges to itself, related to "Incorrect Use of System Classes" and probably related to support for JNLP files.

    Published: 30 Apr 2007
    7.1
    High

    CVE-2007-2241

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in query.c in ISC BIND 9.4.0, and 9.5.0a1 through 9.5.0a3, when recursion is enabled, allows remote attackers to cause a denial of service (daemon exit) via a sequence of queries processed by the query_addsoa function.

    Published: 30 Apr 2007
    7.5
    High

    CVE-2007-2343

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2346

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary PHP code via a URL in the _APP_RELATIVE_PATH parameter to (1) include.php, (2) dbcommon/include.php, and (3) exception/include.php.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2347

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.

    Published: 27 Apr 2007
    7.8
    High

    CVE-2007-2344

    Last Modified: 23 Apr 2026

    The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2345

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Published: 27 Apr 2007
    9
    Critical

    CVE-2007-2332

    Last Modified: 23 Apr 2026

    Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 6_05.140 uses a fixed DES key to encrypt passwords, which allows remote authenticated users to obtain a password via a brute force attack on a hash from the LDAP store.

    Published: 27 Apr 2007
    10
    Critical

    CVE-2007-2333

    Last Modified: 23 Apr 2026

    Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2334

    Last Modified: 23 Apr 2026

    Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 has two template HTML files lacking certain verification tags, which allows remote attackers to access the administration interface and change the device configuration via certain requests.

    Published: 27 Apr 2007
    4.3
    Medium

    CVE-2007-2337

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS 0.96.6 Alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (b) magpie_simple.php in external/magpierss/scripts/, the (2) rss_url parameter to (c) magpie_slashbox.php in external/magpierss/scripts/, and the (3) body parameter to the (d) weblogmodule (aka Weblog Comments) module.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2339

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Phorum before 5.1.22 allow remote attackers to execute arbitrary SQL commands via (1) a modified recipients parameter name in (a) pm.php; (2) the curr parameter to the (b) badwords (aka censorlist) or (c) banlist module in admin.php; or (3) the "Edit groups / Add group" field in the (d) groups module in admin.php.

    Published: 27 Apr 2007
    6.8
    Medium

    CVE-2007-2340

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to execute arbitrary PHP code via a URL in the (1) page_dir or (2) inc_dir parameters.

    Published: 27 Apr 2007
    4.3
    Medium

    CVE-2007-2335

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the RSS feed reader functionality in Lunascape 4.1.3 build2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Apr 2007
    7.8
    High

    CVE-2007-2336

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in InterVations NaviCOPA Web Server 2.01 20070323 allows remote attackers to cause a denial of service (daemon crash) via crafted HTTP requests, as demonstrated by long requests containing '\A' characters, probably a different issue than CVE-2006-5112 and CVE-2007-1733. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2338

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in include/admin/banlist.php in Phorum before 5.1.22 allows remote attackers to perform unauthorized banlist deletions as an administrator via the delete parameter.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2341

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-6083.

    Published: 27 Apr 2007
    6.8
    Medium

    CVE-2007-2356

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.

    Published: 27 Apr 2007
    10
    Critical

    CVE-2007-2325

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2331

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cart.php in Shop-Script 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang_list parameter.

    Published: 27 Apr 2007
    7.8
    High

    CVE-2007-2322

    Last Modified: 23 Apr 2026

    NMMediaServer.exe in Nero MediaHome 2.5.5.0 and CE 1.3.0.4 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted packet that contains two CRLF sequences. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Apr 2007
    7.8
    High

    CVE-2007-2324

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in file.php in JulmaCMS 1.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2330

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes_handler.php in DynaTracker 151 allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.

    Published: 27 Apr 2007
    6.8
    Medium

    CVE-2007-2754

    Last Modified: 23 Apr 2026

    Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

    Published: 27 Apr 2007
    10
    Critical

    CVE-2007-2321

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the search functionality in SilverStripe 2.0.0 has unknown impact and attack vectors.

    Published: 27 Apr 2007
    10
    Critical

    CVE-2007-2323

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the WinDVDX ActiveX control in InterVideo Home Theater 2.1.13.0 and 2.5.13.58 allow remote attackers to execute arbitrary code via a long string argument to the (1) GetDiscType or (2) AddFileList method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2326

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro allow remote attackers to execute arbitrary PHP code via a URL in the plugin_file parameter to (1) Smarty.class.php and (2) Smarty_Compiler.class.php in inc/libs/; (3) core.display_debug_console.php, (4) core.load_plugins.php, (5) core.load_resource_plugin.php, (6) core.process_cached_inserts.php, (7) core.process_compiled_include.php, and (8) core.read_cache_file.php in inc/libs/core/; and other unspecified files. NOTE: (1) and (2) might be incorrectly reported vectors in Smarty.

    Published: 27 Apr 2007
    7.5
    High

    CVE-2007-2327

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter.

    Published: 27 Apr 2007