CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2007-1366

    Last Modified: 23 Apr 2026

    QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.

    Published: 20 Apr 2007
    7.2
    High

    CVE-2007-2893

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the bx_ne2k_c::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system via vectors that cause TXCNT register values to exceed the device memory size, aka "RX Frame heap overflow."

    Published: 20 Apr 2007
    7.5
    High

    CVE-2007-2158

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the G_JGALL[inc_path] parameter.

    Published: 19 Apr 2007
    7.8
    High

    CVE-2007-2157

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upload/force_download.php in Zomplog 3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 19 Apr 2007
    7.8
    High

    CVE-2007-2155

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in template.php in in phpFaber TopSites 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the modify parameter in a template action to admin/index.php.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2154

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in services/samples/inclusionService.php in Cabron Connector 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the CabronServiceFolder parameter.

    Published: 19 Apr 2007
    5
    Medium

    CVE-2007-2151

    Last Modified: 23 Apr 2026

    The administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (service crash) via a large length value in a malformed authentication packet, which triggers a heap over-read.

    Published: 19 Apr 2007
    7.8
    High

    CVE-2007-2150

    Last Modified: 23 Apr 2026

    BlueArc-FTPD in BlueArc Titan 2x00 devices with firmware 4.2.944b allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

    Published: 19 Apr 2007
    10
    Critical

    CVE-2007-2149

    Last Modified: 23 Apr 2026

    Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier stores usernames and unencrypted passwords in (1) classes/vars.php and (2) classes/varstuff.php, and recommends 0666 or 0777 permissions for these files, which allows local users to gain privileges by reading the files, and allows remote attackers to obtain credentials via a direct request for admin/options.php.

    Published: 19 Apr 2007
    10
    Critical

    CVE-2007-2147

    Last Modified: 23 Apr 2026

    admin/options.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier does not check for administrative credentials, which allows remote attackers to read and modify the classes/vars.php and classes/varstuff.php configuration files via direct requests.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2146

    Last Modified: 23 Apr 2026

    The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Apr 2007
    4.6
    Medium

    CVE-2007-1009

    Last Modified: 23 Apr 2026

    Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.

    Published: 19 Apr 2007
    6.8
    Medium

    CVE-2007-2144

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/CAltInstaller.php in the JoomlaPack (com_jpack) 1.0.4a2 RE component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 19 Apr 2007
    7.9
    High

    CVE-2007-2152

    Last Modified: 23 Apr 2026

    Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2156

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Rezervi Generic 0.9 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) datumVonDatumBis.inc.php, (2) footer.inc.php, (3) header.inc.php, and (4) stylesheets.php in templates/; and (5) wochenuebersicht.inc.php, (6) monatsuebersicht.inc.php, (7) jahresuebersicht.inc.php, and (8) tagesuebersicht.inc.php in belegungsplan/.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-1681

    Last Modified: 23 Apr 2026

    Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2145

    Last Modified: 23 Apr 2026

    The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter. NOTE: some of these details are obtained from third party information.

    Published: 19 Apr 2007
    6.5
    Medium

    CVE-2007-2148

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in admin/save.php in Stephen Craton (aka WiredPHP) Chatness 2.5.3 and earlier allows remote authenticated administrators to inject PHP code into .html files via the html parameter, as demonstrated by head.html and foot.html, which are included and executed upon a direct request for index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

    Published: 19 Apr 2007
    6.8
    Medium

    CVE-2007-2153

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in atmail.php in @Mail 5.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 19 Apr 2007
    6.8
    Medium

    CVE-2007-1690

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Second Sight Software ActiveGS ActiveX control (ActiveGS.ocx) allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 19 Apr 2007
    6.8
    Medium

    CVE-2007-1691

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Second Sight Software ActiveMod ActiveX control (ActiveMod.ocx) allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2142

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code via a URL in the PagePrefix parameter to (1) begin.inc.php, (2) connection.inc.php, (3) events.inc.php, (4) footer.inc.php, (5) header.inc.php, (6) menuleft.inc.php, or (7) pages.inc.php in includes/.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2140

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in everything.php in Franklin Huang Flip (aka Flip-search-add-on) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2141

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter.

    Published: 19 Apr 2007
    7.5
    High

    CVE-2007-2143

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 19 Apr 2007
    4.3
    Medium

    CVE-2006-7195

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.

    Published: 19 Apr 2007
    2.6
    Low

    CVE-2007-1858

    Last Modified: 23 Apr 2026

    The default SSL cipher configuration in Apache Tomcat 4.1.28 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.17 uses certain insecure ciphers, including the anonymous cipher, which allows remote attackers to obtain sensitive information or have other, unspecified impacts.

    Published: 19 Apr 2007
    7.2
    High

    CVE-2007-2134

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HTML Server in Oracle JD Edwards EnterpriseOne SP23_Q1 and 8.96.I1 has unknown impact and local attack vectors, aka JDE01.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2133

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise Human Capital Management component in Oracle PeopleSoft Enterprise 8.9 has unknown impact and attack vectors, aka PSEHCM01.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2132

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.47.12 and 8.48.08 has unknown impact and attack vectors, aka PSE02.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2129

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Agent component in Oracle Enterprise Manager 9.2.0.8 has unknown impact and remote attack vectors, aka EM01.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2125

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka OCS01.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2124

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.4.1.0 has unknown impact and remote attack vectors, aka AS05.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2123

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.3 up to 10.1.3.2.0, 10.1.2 up to 10.1.2.2.0, and 9.0.4.3 has unknown impact and attack vectors, aka AS04.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2122

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Wireless component in Oracle Application Server 9.0.4.3 has unknown impact and attack vectors, aka AS03.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2121

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the COREid Access component in Oracle Application Server 7.0.4.4 has unknown impact and attack vectors, aka AS02.

    Published: 18 Apr 2007
    7.8
    High

    CVE-2007-2120

    Last Modified: 23 Apr 2026

    The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Listener via a TNS STOP command in a request that uses the database/TNS alias, aka AS01.

    Published: 18 Apr 2007
    7.5
    High

    CVE-2007-2118

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Upgrade/Downgrade component of Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors, aka DB13. NOTE: as of 20070424, Oracle has not disputed reliable claims that this is a buffer overflow involving the "mig utility."

    Published: 18 Apr 2007
    9
    Critical

    CVE-2007-2116

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors, aka DB10. NOTE: as of 20070424, Oracle has not disputed claims that these are buffer overflows in kkzi.o for the SYS.DBMS_SNAP_INTERNAL package using the (1) SNAP_OWNER or (2) SNAP_NAME parameters.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2115

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and 10.2.0.2 has unknown impact and attack vectors, aka DB09. NOTE: as of 20070424, oracle has not disputed reliable claims that this issue involves multiple SQL injection vulnerabilities in the DBMS_CDC_PUBLISH with remote authenticated vectors involving the "java classes in CDC.jar."

    Published: 18 Apr 2007
    4.4
    Medium

    CVE-2007-2110

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component for Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.4 on Windows systems has unknown impact and attack vectors, aka DB03. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB03 occurs because RDBMS uses a NULL Discretionary Access Control List (DACL) for the Oracle process and certain shared memory sections, which allows local users to inject threads and execute arbitrary code via the OpenProcess, OpenThread, and SetThreadContext functions (DB03).

    Published: 18 Apr 2007
    6
    Medium

    CVE-2007-2112

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Authentication component for Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and attack vectors, aka DB05. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue allows remote authenticated users to bypass the AUTH_ALTER_SESSION security policies via a logon trigger ("AFTER LOGON ON DATABASE" trigger directive), a related issue to CVE-2006-0547.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2117

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Text component in Oracle Database 9.0.1.5+ and 9.2.0.5 has unknown impact and attack vectors, aka DB12. NOTE: as of 20070424, Oracle has not disputed reliable claims that this involves a buffer overflow in the ctxsrv server daemon.

    Published: 18 Apr 2007
    9
    Critical

    CVE-2007-2130

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2108

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this issue occurs because the NTLM SSPI AcceptSecurityContext function grants privileges based on the username provided even though all users are authenticated as Guest, which allows remote attackers to gain privileges.

    Published: 18 Apr 2007
    6
    Medium

    CVE-2007-2109

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) Rules Manager and Expression Filter components (DB02) and (2) Oracle Streams (DB06). Note: as of 20070424, Oracle has not disputed reliable claims that DB02 is for a race condition in the RLMGR_TRUNCATE_MAINT trigger in the Rules Manager and Expression Filter components changing the AUTHID of a package from DEFINER to CURRENT_USER after a TRUNCATE call, and DB06 is for SQL injection in the DBMS_APPLY_USER_AGENT.SET_REGISTRATION_HANDLER procedure, which is later passed to the DBMS_APPLY_ADM_INTERNAL.ALTER_APPLY procedure, aka "Oracle Streams".

    Published: 18 Apr 2007
    6.5
    Medium

    CVE-2007-2111

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the SYS.DBMS_AQADM_SYS package in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 allows remote authenticated users to inject arbitrary SQL commands via unknown vectors, aka DB04. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB04 is actually for multiple vulnerabilities.

    Published: 18 Apr 2007
    9
    Critical

    CVE-2007-2114

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.2 have unknown impact and remote authenticated attack vectors, related to (1) Change Data Capture (CDC), aka DB08, and (2) Oracle Instant Client, aka DB11. NOTE: as of 20070424, oracle has not disputed reliable claims that these issues are buffer overflows using a long CHANGE_TABLE_NAME parameter to the DBMS_CDC_IPUBLISH.CHGTAB_CACHE procedure (DB08) and Oracle Instant Client genezi utility (DB11).

    Published: 18 Apr 2007
    6.8
    Medium

    CVE-2007-2119

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.

    Published: 18 Apr 2007
    10
    Critical

    CVE-2007-2127

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library (APPS04), iStore (2) APPS05 and (3) APPS06, (4) iSupport (APPS07), (5) Trade Management (APPS09), (6) Applications Manager (APPS10), and (7) Oracle Report Manager (APPS03).

    Published: 18 Apr 2007