CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2007-1882

    Last Modified: 23 Apr 2026

    qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method.

    Published: 6 Apr 2007
    7.5
    High

    CVE-2007-1885

    Last Modified: 23 Apr 2026

    Integer overflow in the str_replace function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via a single character search string in conjunction with a long replacement string, which overflows a 32 bit length counter. NOTE: this is probably the same issue as CVE-2007-0906.6.

    Published: 6 Apr 2007
    6.8
    Medium

    CVE-2007-1886

    Last Modified: 23 Apr 2026

    Integer overflow in the str_replace function in PHP 4.4.5 and PHP 5.2.1 allows context-dependent attackers to have an unknown impact via a single character search string in conjunction with a single character replacement string, which causes an "off by one overflow."

    Published: 6 Apr 2007
    7.5
    High

    CVE-2007-1887

    Last Modified: 23 Apr 2026

    Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by calling the sqlite_udf_decode_binary function with a 0x01 character.

    Published: 6 Apr 2007
    7.5
    High

    CVE-2007-1888

    Last Modified: 23 Apr 2026

    Buffer overflow in the sqlite_decode_binary function in src/encode.c in SQLite 2, as used by PHP 4.x through 5.x and other applications, allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter. NOTE: some PHP installations use a bundled version of sqlite without this vulnerability. The SQLite developer has argued that this issue could be due to a misuse of the sqlite_decode_binary() API.

    Published: 6 Apr 2007
    7.5
    High

    CVE-2007-1889

    Last Modified: 23 Apr 2026

    Integer signedness error in the _zend_mm_alloc_int function in the Zend Memory Manager in PHP 5.2.0 allows remote attackers to execute arbitrary code via a large emalloc request, related to an incorrect signed long cast, as demonstrated via the HTTP SOAP client in PHP, and via a call to msg_receive with the largest positive integer value of maxsize.

    Published: 6 Apr 2007
    10
    Critical

    CVE-2007-1112

    Last Modified: 23 Apr 2026

    Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods.

    Published: 6 Apr 2007
    10
    Critical

    CVE-2007-0445

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.

    Published: 6 Apr 2007
    6.6
    Medium

    CVE-2007-1271

    Last Modified: 23 Apr 2026

    Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors.

    Published: 6 Apr 2007
    4.3
    Medium

    CVE-2007-1841

    Last Modified: 23 Apr 2026

    The isakmp_info_recv function in src/racoon/isakmp_inf.c in racoon in Ipsec-tools before 0.6.7 allows remote attackers to cause a denial of service (tunnel crash) via crafted (1) DELETE (ISAKMP_NPTYPE_D) and (2) NOTIFY (ISAKMP_NPTYPE_N) messages.

    Published: 6 Apr 2007
    5
    Medium

    CVE-2007-1270

    Last Modified: 23 Apr 2026

    Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, or possibly execute arbitrary code via unspecified vectors.

    Published: 6 Apr 2007
    6.8
    Medium

    CVE-2007-1878

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.

    Published: 6 Apr 2007
    9.3
    Critical

    CVE-2007-1879

    Last Modified: 23 Apr 2026

    The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command. NOTE: this issue might be related to CVE-2007-1112.

    Published: 6 Apr 2007
    6.6
    Medium

    CVE-2007-1880

    Last Modified: 23 Apr 2026

    Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument," which results in a heap overflow.

    Published: 6 Apr 2007
    6.8
    Medium

    CVE-2007-1881

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in KLIF (klif.sys) in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows local users to gain Ring-0 privileges via unspecified vectors.

    Published: 6 Apr 2007
    7.2
    High

    CVE-2006-5586

    Last Modified: 23 Apr 2026

    The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."

    Published: 4 Apr 2007
    7.2
    High

    CVE-2007-1213

    Last Modified: 23 Apr 2026

    The TrueType Fonts rasterizer in Microsoft Windows 2000 SP4 allows local users to gain privileges via crafted TrueType fonts, which result in an uninitialized function pointer.

    Published: 4 Apr 2007
    7.1
    High

    CVE-2007-1211

    Last Modified: 23 Apr 2026

    Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to cause a denial of service (possibly persistent restart) via a crafted Windows Metafile (WMF) image that causes an invalid dereference of an offset in a kernel structure, a related issue to CVE-2005-4560.

    Published: 4 Apr 2007
    6.6
    Medium

    CVE-2007-1212

    Last Modified: 23 Apr 2026

    Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file.

    Published: 4 Apr 2007
    7.2
    High

    CVE-2007-1215

    Last Modified: 23 Apr 2026

    Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.

    Published: 4 Apr 2007
    10
    Critical

    CVE-2007-1866

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.

    Published: 4 Apr 2007
    10
    Critical

    CVE-2007-1867

    Last Modified: 23 Apr 2026

    Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.

    Published: 4 Apr 2007
    10
    Critical

    CVE-2007-1868

    Last Modified: 23 Apr 2026

    The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

    Published: 4 Apr 2007
    4.4
    Medium

    CVE-2007-2027

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks.

    Published: 4 Apr 2007
    5
    Medium

    CVE-2008-4683

    Last Modified: 23 Apr 2026

    The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.

    Published: 4 Apr 2007
    7.5
    High

    CVE-2007-1842

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the table parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, a related issue to CVE-2006-2019.

    Published: 3 Apr 2007
    6.8
    Medium

    CVE-2007-1843

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gszAppPath parameter.

    Published: 3 Apr 2007
    5
    Medium

    CVE-2007-1850

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1851

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php.

    Published: 3 Apr 2007
    5
    Medium

    CVE-2007-1854

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi Cosminexus Component Container 07-00 through 07-00-10, and 07-10 through 07-10-03, as used in uCosminexus Application Server Enterprise and Standard; uCosminexus Service Platform; uCosminexus Developer Standard and Professional; uCosminexus Service Architect; Electronic Form Workflow Standard Set, Professional Library Set, and Developer Client Set; and uCosminexus ERP Integrator, does not properly manage session information, which has an unspecified impact related to "unintended other requests."

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1844

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Aardvark Topsites PHP 5 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) button/settings_sql.php, (2) settings_sql.php, and (3) sources/misc/new_day.php.

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1845

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the m_month parameter.

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1846

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter, different vectors than CVE-2006-3341.

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1847

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the Repository module for Xoops allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 3 Apr 2007
    4.3
    Medium

    CVE-2007-1848

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/classes/ui.dta.php in Drake CMS allows remote attackers to inject arbitrary web script or HTML via the desc[][title] field. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1849

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter. NOTE: some of these details are obtained from third party information. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."

    Published: 3 Apr 2007
    6.8
    Medium

    CVE-2007-1852

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in 2BGal 3.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the lang_filename parameter to (1) index.php or (2) backupdb.inc.php in admin/, or other unspecified files, different vectors than CVE-2006-5505. NOTE: this issue has been disputed by CVE, since the lang_filename variable is defined before it is used

    Published: 3 Apr 2007
    5
    Medium

    CVE-2007-1853

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi JP1/HiCommand DeviceManager, Global Link Availability Manager, Replication Monitor, Tiered Storage Manager, and Tuning Manager allows local users to obtain authentication information via unspecified vectors.

    Published: 3 Apr 2007
    7.5
    High

    CVE-2007-1855

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) smarty_compile_path, (3) get_plugin_filepath, (4) smarty_dir, and (5) filename parameters. NOTE: this issue might be related to CVE-2006-7105.

    Published: 3 Apr 2007
    1.9
    Low

    CVE-2007-3850

    Last Modified: 23 Apr 2026

    The eHCA driver in Linux kernel 2.6 before 2.6.22, when running on PowerPC, does not properly map userspace resources, which allows local users to read portions of physical address space.

    Published: 3 Apr 2007
    5
    Medium

    CVE-2006-7186

    Last Modified: 23 Apr 2026

    cgi-lib/subs.pl in web-app.net WebAPP before 0.9.9.3.5 allows attackers to open list files in "profile and other functions," a different vulnerability than CVE-2005-0927.

    Published: 3 Apr 2007
    4.3
    Medium

    CVE-2006-7187

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the show_recent_searches function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to inject arbitrary web script or HTML via the srch variable.

    Published: 3 Apr 2007
    5
    Medium

    CVE-2006-7188

    Last Modified: 23 Apr 2026

    The search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via certain requests, possibly related to the $info{'forum'} variable.

    Published: 3 Apr 2007
    7.2
    High

    CVE-2006-7191

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in lamdaemon.pl in LDAP Account Manager (LAM) before 1.0.0 allows local users to gain privileges via a modified PATH that points to a malicious rm program.

    Published: 3 Apr 2007
    4.3
    Medium

    CVE-2006-7190

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc.

    Published: 3 Apr 2007
    5
    Medium

    CVE-2007-1833

    Last Modified: 23 Apr 2026

    The Skinny Call Control Protocol (SCCP) implementation in Cisco Unified CallManager (CUCM) 3.3 before 3.3(5)SR2a, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3)SR1, and 5.0 before 5.0(4a)SU1 allows remote attackers to cause a denial of service (loss of voice services) by sending crafted packets to the (1) SCCP (2000/tcp) or (2) SCCPS (2443/tcp) port.

    Published: 3 Apr 2007
    7.8
    High

    CVE-2007-1834

    Last Modified: 23 Apr 2026

    Cisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a denial of service (loss of voice services) via a flood of ICMP echo requests, aka bug ID CSCsf12698.

    Published: 3 Apr 2007
    4.3
    Medium

    CVE-2006-7189

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the Statistics Log Viewer.

    Published: 3 Apr 2007
    10
    Critical

    CVE-2007-0956

    Last Modified: 23 Apr 2026

    The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.

    Published: 3 Apr 2007
    9
    Critical

    CVE-2007-0957

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitrary code and modify the Kerberos key database via crafted arguments, possibly involving certain format string specifiers.

    Published: 3 Apr 2007