CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2007-0744

    Last Modified: 23 Apr 2026

    SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.

    Published: 24 Apr 2007
    7.8
    High

    CVE-2007-2179

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving the (1) CalculateCrc, (2) Compress, and (3) Uncompress functions, which result in a NULL pointer dereference.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2185

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP code via a URL in the supa[db_path] parameter to (1) common_functions.php, (2) admin_auth_cookies.php, (3) admin_mods.php, (4) admin_news.php, (5) admin_topics.php, (6) admin_users.php, (7) admin_utilities.php, (8) site_comment.php, or (9) site_news.php; or the supa[include_path] parameter to (10) admin_settings.php or (11) backend_site.php.

    Published: 24 Apr 2007
    9.3
    Critical

    CVE-2007-2192

    Last Modified: 23 Apr 2026

    Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2194

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.

    Published: 24 Apr 2007
    5
    Medium

    CVE-2007-2195

    Last Modified: 23 Apr 2026

    aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP port 31337.

    Published: 24 Apr 2007
    7.5
    High

    CVE-2007-0741

    Last Modified: 23 Apr 2026

    Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute arbitrary code via malformed RTSP packets.

    Published: 24 Apr 2007
    4.9
    Medium

    CVE-2007-0743

    Last Modified: 23 Apr 2026

    URLMount in Apple Mac OS X 10.3.9 through 10.4.9 passes the username and password credentials for mounting filesystems on SMB servers as command line arguments to the mount_sub command, which may allow local users to obtain sensitive information by listing the process.

    Published: 24 Apr 2007
    7.8
    High

    CVE-2007-2178

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Objective Development Sharity before 3.3 allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 24 Apr 2007
    7.1
    High

    CVE-2007-2180

    Last Modified: 23 Apr 2026

    Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2181

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2182

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.

    Published: 24 Apr 2007
    7.5
    High

    CVE-2007-2183

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers to execute arbitrary SQL commands via the ring parameter.

    Published: 24 Apr 2007
    5
    Medium

    CVE-2007-2184

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the acc parameter.

    Published: 24 Apr 2007
    5
    Medium

    CVE-2007-2186

    Last Modified: 23 Apr 2026

    Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2187

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2188

    Last Modified: 23 Apr 2026

    eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2189

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2190

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/public/webpages.php in Eba News 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2191

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.

    Published: 24 Apr 2007
    9.3
    Critical

    CVE-2007-2193

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2196

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in jambook.php in the Jambook (com_Jambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by a reliable third party because the jambook.php protects against direct request

    Published: 24 Apr 2007
    5
    Medium

    CVE-2007-2197

    Last Modified: 23 Apr 2026

    Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request.

    Published: 24 Apr 2007
    7.2
    High

    CVE-2007-0732

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via unspecified vectors involving "obtaining a send right to [the] Mach task port."

    Published: 24 Apr 2007
    9.3
    Critical

    CVE-2007-0443

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters.

    Published: 24 Apr 2007
    7.2
    High

    CVE-2007-0725

    Last Modified: 23 Apr 2026

    Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort wireless card, allows local users to execute arbitrary code by "sending malformed control commands."

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2176

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175.

    Published: 24 Apr 2007
    7.2
    High

    CVE-2007-0729

    Last Modified: 23 Apr 2026

    Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.

    Published: 24 Apr 2007
    10
    Critical

    CVE-2007-2173

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.

    Published: 24 Apr 2007
    7.2
    High

    CVE-2007-2174

    Last Modified: 23 Apr 2026

    The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.

    Published: 24 Apr 2007
    7.6
    High

    CVE-2007-2175

    Last Modified: 23 Apr 2026

    Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.

    Published: 24 Apr 2007
    6.8
    Medium

    CVE-2007-2177

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Microgaming Download Helper ActiveX control (dlhelper.dll) before 7.2.0.19, and the WebHandler Class control, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 24 Apr 2007
    6
    Medium

    CVE-2007-2138

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings."

    Published: 23 Apr 2007
    7.8
    High

    CVE-2007-2162

    Last Modified: 23 Apr 2026

    (1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

    Published: 22 Apr 2007
    5.1
    Medium

    CVE-2007-2165

    Last Modified: 23 Apr 2026

    The Auth API in ProFTPD before 20070417, when multiple simultaneous authentication modules are configured, does not require that the module that checks authentication is the same as the module that retrieves authentication data, which might allow remote attackers to bypass authentication, as demonstrated by use of SQLAuthTypes Plaintext in mod_sql, with data retrieved from /etc/passwd.

    Published: 22 Apr 2007
    7.5
    High

    CVE-2007-2136

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.

    Published: 22 Apr 2007
    4.3
    Medium

    CVE-2007-2159

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors relating to (1) direct display of data from the database and (2) other portions of the user interface.

    Published: 22 Apr 2007
    7.5
    High

    CVE-2007-2160

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Database Administration (dba) module 4.6.x-*, and before 4.7.x-1.2 in the 4.7.x-1.* series, for Drupal allow remote attackers to perform unauthorized actions as an arbitrary user, a related issue to CVE-2006-5476.

    Published: 22 Apr 2007
    7.5
    High

    CVE-2007-2168

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Apr 2007
    7.5
    High

    CVE-2007-1972

    Last Modified: 23 Apr 2026

    PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured

    Published: 22 Apr 2007
    10
    Critical

    CVE-2007-2137

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a long string to a certain TCP port.

    Published: 22 Apr 2007
    4.3
    Medium

    CVE-2007-2161

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (browser hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

    Published: 22 Apr 2007
    5
    Medium

    CVE-2007-2163

    Last Modified: 23 Apr 2026

    Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

    Published: 22 Apr 2007
    5
    Medium

    CVE-2007-2164

    Last Modified: 23 Apr 2026

    Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

    Published: 22 Apr 2007
    6.8
    Medium

    CVE-2007-2166

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter.

    Published: 22 Apr 2007
    7.5
    High

    CVE-2007-2167

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action.

    Published: 22 Apr 2007
    7.5
    High

    CVE-2007-2169

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in add.php in Mozzers SubSystem 1.0 allows remote attackers to inject PHP code into subs.php via the (1) Sub-name or (2) Sub-url field. NOTE: an earlier report indicated that the add action can be reached through a request to index.php.

    Published: 22 Apr 2007
    7.2
    High

    CVE-2007-1320

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.

    Published: 20 Apr 2007
    7.2
    High

    CVE-2007-1321

    Last Modified: 23 Apr 2026

    Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.

    Published: 20 Apr 2007
    2.1
    Low

    CVE-2007-1322

    Last Modified: 23 Apr 2026

    QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.

    Published: 20 Apr 2007