CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-1907

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1915

    Last Modified: 23 Apr 2026

    Buffer overflow in the RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 10 Apr 2007
    10
    Critical

    CVE-2007-1916

    Last Modified: 23 Apr 2026

    Buffer overflow in the RFC_START_GUI function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 10 Apr 2007
    5
    Medium

    CVE-2007-1918

    Last Modified: 23 Apr 2026

    The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 10 Apr 2007
    9.3
    Critical

    CVE-2007-1922

    Last Modified: 23 Apr 2026

    The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.

    Published: 10 Apr 2007
    5
    Medium

    CVE-2007-1929

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows remote attackers to read arbitrary files via a .. (dot dot) in the chemin parameter.

    Published: 10 Apr 2007
    7.8
    High

    CVE-2007-1930

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows remote attackers to read arbitrary files via a .. (dot dot) in the fn1 parameter.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1931

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ssid parameter.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1933

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to (1) index.php, (2) gb.php, or (3) faq.php.

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2007-1905

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1908

    Last Modified: 23 Apr 2026

    PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1909

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) pass parameter.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1910

    Last Modified: 23 Apr 2026

    Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted document, as demonstrated by file789-1.doc.

    Published: 10 Apr 2007
    7.1
    High

    CVE-2007-1911

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU consumption) via crafted documents, as demonstrated by (1) file798-1.doc and (2) file613-1.doc, possibly related to a buffer overflow.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1912

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a crafted .HLP file.

    Published: 10 Apr 2007
    10
    Critical

    CVE-2007-1917

    Last Modified: 23 Apr 2026

    Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2007-1919

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Arizona Dream Livre d'or (livor) 2.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1920

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the aktualnosci module in SmodBIP 1.06 and earlier allows remote attackers to execute arbitrary SQL commands via the zoom parameter, possibly related to home.php.

    Published: 10 Apr 2007
    6.5
    Medium

    CVE-2007-1925

    Last Modified: 23 Apr 2026

    The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticated users to delete arbitrary accounts via a modified cookie.

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2007-1927

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1928

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in witshare 0.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the menu parameter.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1932

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sn_admin_dir parameter.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1934

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[name] parameter.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1936

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in scaradcontrol.php in ScarAdControl (ScarAdController) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sac_config_dir parameter.

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2007-1938

    Last Modified: 23 Apr 2026

    Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1926

    Last Modified: 16 Dec 2025

    Cross-site scripting (XSS) vulnerability in JBMC Software DirectAdmin before 1.293 does not properly display log files, which allows remote authenticated users to inject arbitrary web script or HTML via (1) http or (2) ftp requests logged in /var/log/directadmin/security.log; (3) allows context-dependent attackers to inject arbitrary web script or HTML into /var/log/messages via a PHP script that invokes /usr/bin/logger; (4) allows local users to inject arbitrary web script or HTML into /var/log/messages by invoking /usr/bin/logger at the command line; and allows remote attackers to inject arbitrary web script or HTML via remote requests logged in the (5) /var/log/exim/rejectlog, (6) /var/log/exim/mainlog, (7) /var/log/proftpd/auth.log, (8) /var/log/httpd/error_log, (9) /var/log/httpd/access_log, (10) /var/log/directadmin/error.log, and (11) /var/log/directadmin/security.log files.

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2006-7192

    Last Modified: 23 Apr 2026

    Microsoft ASP .NET Framework 2.0.50727.42 does not properly handle comment (/* */) enclosures, which allows remote attackers to bypass request filtering and conduct cross-site scripting (XSS) attacks, or cause a denial of service, as demonstrated via an xss:expression STYLE attribute in a closing XSS HTML tag.

    Published: 10 Apr 2007
    5.4
    Medium

    CVE-2007-0734

    Last Modified: 23 Apr 2026

    fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 through 10.4.9, does not properly enforce password protection of a USB hard drive, which allows context-dependent attackers to list arbitrary directories or execute arbitrary code, resulting from memory corruption.

    Published: 10 Apr 2007
    7.2
    High

    CVE-2007-1206

    Last Modified: 23 Apr 2026

    The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.

    Published: 10 Apr 2007
    9.3
    Critical

    CVE-2007-1205

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.

    Published: 10 Apr 2007
    10
    Critical

    CVE-2007-0938

    Last Modified: 23 Apr 2026

    Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."

    Published: 10 Apr 2007
    4.3
    Medium

    CVE-2007-0939

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability."

    Published: 10 Apr 2007
    7.2
    High

    CVE-2007-1209

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.

    Published: 10 Apr 2007
    6.8
    Medium

    CVE-2007-1204

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in Microsoft Windows XP SP2 allows remote attackers on the same subnet to execute arbitrary code via crafted HTTP headers in request or notification messages, which trigger memory corruption.

    Published: 10 Apr 2007
    4.6
    Medium

    CVE-2006-4250

    Last Modified: 23 Apr 2026

    Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag.

    Published: 10 Apr 2007
    10
    Critical

    CVE-2007-1687

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll) allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 10 Apr 2007
    5
    Medium

    CVE-2007-1900

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.

    Published: 10 Apr 2007
    2.1
    Low

    CVE-2007-1856

    Last Modified: 23 Apr 2026

    Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.

    Published: 10 Apr 2007
    7.5
    High

    CVE-2007-1923

    Last Modified: 23 Apr 2026

    (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.

    Published: 10 Apr 2007
    4.9
    Medium

    CVE-2007-1893

    Last Modified: 23 Apr 2026

    xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."

    Published: 9 Apr 2007
    4.3
    Medium

    CVE-2007-1894

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-includes/general-template.php in WordPress before 20070309 allows remote attackers to inject arbitrary web script or HTML via the year parameter in the wp_title function.

    Published: 9 Apr 2007
    6.8
    Medium

    CVE-2007-1895

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, allows remote attackers to execute arbitrary PHP code via an ftp URL in a my_ms[root] cookie, a different vector than CVE-2007-0491 and CVE-2006-4630.

    Published: 9 Apr 2007
    5.8
    Medium

    CVE-2007-1896

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a my_ms[root] cookie.

    Published: 9 Apr 2007
    6.5
    Medium

    CVE-2007-1897

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users to execute arbitrary SQL commands via a string parameter value in an XML RPC mt.setPostCategories method call, related to the post_id variable.

    Published: 9 Apr 2007
    6.3
    Medium

    CVE-2007-1995

    Last Modified: 23 Apr 2026

    bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.

    Published: 8 Apr 2007
    7.8
    High

    CVE-2007-1883

    Last Modified: 23 Apr 2026

    PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convert_to_* functions with its input parameters.

    Published: 6 Apr 2007
    6.8
    Medium

    CVE-2007-1884

    Last Modified: 23 Apr 2026

    Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers that arise in the php_formatted_print function because of 64 to 32 bit truncation, and bypass a check for the maximum allowable value; and (2) a width and precision of -1, which make it possible for the php_sprintf_appendstring function to place an internal buffer at an arbitrary memory location.

    Published: 6 Apr 2007
    7.5
    High

    CVE-2007-1890

    Last Modified: 23 Apr 2026

    Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other platforms, allows context-dependent attackers to execute arbitrary code via certain maxsize values, as demonstrated by 0xffffffff.

    Published: 6 Apr 2007
    9.3
    Critical

    CVE-2007-1680

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.

    Published: 6 Apr 2007
    9.3
    Critical

    CVE-2007-1684

    Last Modified: 23 Apr 2026

    The Run function in SolidWorks sldimdownload ActiveX control in sldimdownload.dll before 16.0.0.6 allows remote attackers to execute arbitrary commands via the (1) installerpath and (2) applicationarguments arguments.

    Published: 6 Apr 2007