CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-1978

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action.

    Published: 12 Apr 2007
    6.9
    Medium

    CVE-2007-1973

    Last Modified: 23 Apr 2026

    Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary \Device\PhysicalMemory section handle, a related issue to CVE-2007-1206.

    Published: 11 Apr 2007
    7.2
    High

    CVE-2007-1279

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the installer for Adobe Bridge 1.0.3 update for Apple OS X, when patching with desktop management tools, allows local users to gain privileges via unspecified vectors during installation of the update by a different user who has administrative privileges.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1363

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.

    Published: 11 Apr 2007
    6.4
    Medium

    CVE-2007-1364

    Last Modified: 23 Apr 2026

    DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.

    Published: 11 Apr 2007
    9.3
    Critical

    CVE-2007-1559

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via (1) unspecified long property values to SonicMediaPlayer.dll or (2) long arguments to unspecified methods in SonicMediaPlayer.dll.

    Published: 11 Apr 2007
    7.2
    High

    CVE-2007-1874

    Last Modified: 23 Apr 2026

    Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.

    Published: 11 Apr 2007
    4.3
    Medium

    CVE-2007-1965

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php.

    Published: 11 Apr 2007
    5
    Medium

    CVE-2007-1958

    Last Modified: 23 Apr 2026

    Buffer overflow in TinyMUX before 2.4 allows attackers to cause a denial of service via unspecified vectors related to "too many substring matches in a regexp $-command." NOTE: some of these details are obtained from third party information.

    Published: 11 Apr 2007
    9.1
    Critical

    CVE-2007-1966

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.

    Published: 11 Apr 2007
    10
    Critical

    CVE-2007-1959

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the process_cmdent function in command.cpp in TinyMUX before 2.4 has unknown impact and attack vectors, related to lack of the "'other half' of buffer overflow protection."

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1960

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1961

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1962

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1963

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, as utilized by index.php, a related issue to CVE-2006-3775.

    Published: 11 Apr 2007
    6
    Medium

    CVE-2007-1964

    Last Modified: 23 Apr 2026

    member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a do_lostpw action, which prints the change password verification code in the debug output.

    Published: 11 Apr 2007
    6.8
    Medium

    CVE-2007-1967

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in stat12 allows remote attackers to execute arbitrary PHP code via a URL in the langpath parameter. NOTE: this issue was published by an unreliable researcher, and there is little information to determine which product is actually affected. This is probably an invalid report based on analysis by CVE and a third party

    Published: 11 Apr 2007
    6.8
    Medium

    CVE-2007-1968

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter.

    Published: 11 Apr 2007
    4.3
    Medium

    CVE-2007-1969

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 11 Apr 2007
    5
    Medium

    CVE-2007-1970

    Last Modified: 23 Apr 2026

    Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1971

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQL commands via the query string.

    Published: 11 Apr 2007
    4.9
    Medium

    CVE-2007-1940

    Last Modified: 23 Apr 2026

    IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log.

    Published: 11 Apr 2007
    9.3
    Critical

    CVE-2007-1948

    Last Modified: 23 Apr 2026

    Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.

    Published: 11 Apr 2007
    6.8
    Medium

    CVE-2007-1957

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) allow remote attackers to execute arbitrary PHP code via a URL in the pageAll parameter to index.php in (1) template/Vert/, or (2) template/Noir/.

    Published: 11 Apr 2007
    4.3
    Medium

    CVE-2007-1941

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1945

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors.

    Published: 11 Apr 2007
    9.3
    Critical

    CVE-2007-1942

    Last Modified: 23 Apr 2026

    Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.

    Published: 11 Apr 2007
    9.3
    Critical

    CVE-2007-1943

    Last Modified: 23 Apr 2026

    Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.

    Published: 11 Apr 2007
    5
    Medium

    CVE-2007-1944

    Last Modified: 23 Apr 2026

    The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.

    Published: 11 Apr 2007
    10
    Critical

    CVE-2007-1946

    Last Modified: 23 Apr 2026

    Integer overflow in Windows Explorer in Microsoft Windows XP SP1 might allow user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large width dimension in a crafted BMP image, as demonstrated by w4intof.bmp.

    Published: 11 Apr 2007
    3.5
    Low

    CVE-2007-1947

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome by overwriting the toString function via a certain function declaration, related to incorrect identification of anonymous JavaScript functions, a different issue than CVE-2007-1878.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1949

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

    Published: 11 Apr 2007
    4.3
    Medium

    CVE-2007-1950

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1951

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in onelook obo Shop allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1952

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in onelook onebyone CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1953

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in onelook courts on-line allows remote attackers to hijack web sessions by setting a PHPSESSID cookie.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1954

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file.

    Published: 11 Apr 2007
    10
    Critical

    CVE-2007-1955

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions, a different module and vectors than CVE-2007-1722. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Apr 2007
    7.5
    High

    CVE-2007-1956

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.

    Published: 11 Apr 2007
    7.8
    High

    CVE-2007-1357

    Last Modified: 23 Apr 2026

    The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.

    Published: 11 Apr 2007
    4
    Medium

    CVE-2007-6698

    Last Modified: 23 Apr 2026

    The BDB backend for slapd in OpenLDAP before 2.3.36 allows remote authenticated users to cause a denial of service (crash) via a potentially-successful modify operation with the NOOP control set to critical, possibly due to a double free vulnerability.

    Published: 11 Apr 2007
    5
    Medium

    CVE-2007-1913

    Last Modified: 23 Apr 2026

    The TRUSTED_SYSTEM_SECURITY function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to verify the existence of users and groups on systems and domains via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 10 Apr 2007
    7.8
    High

    CVE-2007-1914

    Last Modified: 23 Apr 2026

    The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 10 Apr 2007
    9.3
    Critical

    CVE-2007-1921

    Last Modified: 23 Apr 2026

    LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT file that contains a value that is used as an offset, which triggers memory corruption.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1924

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) contact_business.php or (2) contact_person.php. NOTE: this issue is disputed by CVE and a reliable third party, because include_path is initialized to a fixed value before use

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1935

    Last Modified: 23 Apr 2026

    PHP file inclusion vulnerability in admin/index.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the site parameter, which is accessed by the file_exists function.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1937

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1939

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the embedded webserver in Daniel Naber LanguageTool before 0.8.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message, possibly the demultiplex method in HTTPServer.java.

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2007-1904

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1906

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in richedit/keyboard.php in eCardMAX HotEditor (Hot Editor) 4.0, and the HotEditor plugin for MyBB, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the first parameter.

    Published: 10 Apr 2007