CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2007-1558

    Last Modified: 23 Apr 2026

    The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.

    Published: 2 Apr 2007
    6.8
    Medium

    CVE-2007-1786

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Hitachi Collaboration - Online Community Management 01-00 through 01-30, as used in Groupmax Collaboration Portal, Groupmax Collaboration Web Client, uCosminexus Collaboration Portal, Cosminexus Collaboration Portal, and uCosminexus Content Manager, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 31 Mar 2007
    6.8
    Medium

    CVE-2007-1790

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to execute arbitrary PHP code via a URL in the install_root parameter to (1) support.inc.php, (2) function.inc.php, (3) rdal_object.inc.php, (4) rdal_editor.inc.php. (5) login.inc.php, (6) request.inc.php, and (7) categories.inc.php in include/core/; (8) save.inc.php, (9) preview.inc.php, (10) edit_item.inc.php, (11) new_item.inc.php, and (12) item_info.inc.php in include/display/item/; (13) search.inc.php, (14) item_edit.inc.php, (15) register_succsess.inc.php, (16) context_menu.inc.php, (17) item_repost.inc.php, (18) balance.inc.php, (19) featured.inc.php, (20) user.inc.php, (21) buynow.inc.php, (22) install_complete.inc.php, (23) fees_info.inc.php, (24) user_feedback.inc.php, (25) admin_balance.inc.php, (26) activate.inc.php, (27) user_info.inc.php, (28) member.inc.php, (29) add_bid.inc.php, (30) items_filter.inc.php, (31) my_info.inc.php, (32) register.inc.php, (33) leave_feedback.inc.php, and (34) user_auctions.inc.php in include/display/; and (35) design/form.inc.php, (36) processor.inc.php, (37) interfaces.inc.php (38) left_menu.inc.php, (39) login.inc.php, and (40) categories.inc.php in include/.

    Published: 31 Mar 2007
    9.3
    Critical

    CVE-2007-1787

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir parameter.

    Published: 31 Mar 2007
    6.8
    Medium

    CVE-2007-1789

    Last Modified: 23 Apr 2026

    Flyspray 0.9.9 allows remote attackers to obtain sensitive information (private project summaries) via direct requests.

    Published: 31 Mar 2007
    7.5
    High

    CVE-2007-1791

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 31 Mar 2007
    6.8
    Medium

    CVE-2007-1788

    Last Modified: 23 Apr 2026

    Flyspray 0.9.9, when output_buffering is disabled or "set to a low value," allows remote attackers to bypass authentication via a crafted post request.

    Published: 31 Mar 2007
    7.1
    High

    CVE-2007-1785

    Last Modified: 23 Apr 2026

    The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute arbitrary code via crafted xdr_handle_t data in RPC packets, which is used in calculating an address for a function call, as demonstrated using the 191 (0xbf) RPC request.

    Published: 31 Mar 2007
    9.3
    Critical

    CVE-2007-1784

    Last Modified: 23 Apr 2026

    The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.

    Published: 31 Mar 2007
    6.8
    Medium

    CVE-2007-1797

    Last Modified: 23 Apr 2026

    Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results in a heap-based overflow in the ReadDCMImage function, or (2) the (a) colors or (b) comments field in a crafted XWD image, which results in a heap-based overflow in the ReadXWDImage function, different issues than CVE-2007-1667.

    Published: 31 Mar 2007
    9.3
    Critical

    CVE-2006-7185

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a URL in the relative_root parameter.

    Published: 30 Mar 2007
    10
    Critical

    CVE-2006-7183

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.

    Published: 30 Mar 2007
    6.8
    Medium

    CVE-2006-7184

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Mar 2007
    9.3
    Critical

    CVE-2007-0038

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.

    Published: 30 Mar 2007
    10
    Critical

    CVE-2006-7182

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in noticias.php in MNews 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.

    Published: 30 Mar 2007
    10
    Critical

    CVE-2006-7181

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Morcego CMS 0.9.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) fichero parameter to morcegoCMS.php or the (2) path parameter to adodb/adodb.inc.php. NOTE: vector 1 has been disputed by a third party who shows that $fichero can not be controlled by an attacker

    Published: 30 Mar 2007
    4.3
    Medium

    CVE-2007-1780

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the DHT shell (owdhtshell) in Overlay Weaver 0.5.9 to 0.5.11, when invoked with the -x option, allows remote attackers to inject arbitrary web script or HTML via fields in certain input forms.

    Published: 30 Mar 2007
    4.6
    Medium

    CVE-2007-1781

    Last Modified: 23 Apr 2026

    Minna De Office 1.x and 2.x does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact. NOTE: some of these details are obtained from third party information.

    Published: 30 Mar 2007
    4.6
    Medium

    CVE-2007-1782

    Last Modified: 23 Apr 2026

    CruiseWorks 1.09e and earlier does not properly restrict user access to certain privileged actions, which allows local users to change the configuration or have other unspecified impact. NOTE: some of these details are obtained from third party information.

    Published: 30 Mar 2007
    6.8
    Medium

    CVE-2007-1776

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the DesignForJoomla.com D4J eZine (com_ezine) 2.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the article parameter in a read action.

    Published: 30 Mar 2007
    4.3
    Medium

    CVE-2007-1774

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in aBitWhizzy allow remote attackers to inject arbitrary web script or HTML via the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php.

    Published: 30 Mar 2007
    2.6
    Low

    CVE-2007-1773

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a .. (dot dot) in the d parameter to (1) whizzery/whizzypic.php or (2) whizzery/whizzylink.php, different vectors than CVE-2006-6384.

    Published: 30 Mar 2007
    7.1
    High

    CVE-2007-1772

    Last Modified: 23 Apr 2026

    The FTP service in HP JetDirect print servers allows remote attackers to cause a denial of service (engine crash) via a RETR command with a long pathname.

    Published: 30 Mar 2007
    9.3
    Critical

    CVE-2007-1771

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter.

    Published: 30 Mar 2007
    7.8
    High

    CVE-2006-7178

    Last Modified: 23 Apr 2026

    MadWifi before 0.9.3 does not properly handle reception of an AUTH frame by an IBSS node, which allows remote attackers to cause a denial of service (system crash) via a certain AUTH frame.

    Published: 30 Mar 2007
    7.8
    High

    CVE-2006-7179

    Last Modified: 23 Apr 2026

    ieee80211_input.c in MadWifi before 0.9.3 does not properly process Channel Switch Announcement Information Elements (CSA IEs), which allows remote attackers to cause a denial of service (loss of communication) via a Channel Switch Count less than or equal to one, triggering a channel change.

    Published: 30 Mar 2007
    6.8
    Medium

    CVE-2006-7180

    Last Modified: 23 Apr 2026

    ieee80211_output.c in MadWifi before 0.9.3 sends unencrypted packets before WPA authentication succeeds, which allows remote attackers to obtain sensitive information (related to network structure), and possibly cause a denial of service (disrupted authentication) and conduct spoofing attacks.

    Published: 30 Mar 2007
    6.8
    Medium

    CVE-2007-1775

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php3 in JBrowser 2.4 and earlier allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Mar 2007
    7.5
    High

    CVE-2007-1777

    Last Modified: 23 Apr 2026

    Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code via a ZIP archive that contains an entry with a length value of 0xffffffff, which is incremented before use in an emalloc call, triggering a heap overflow.

    Published: 30 Mar 2007
    7.8
    High

    CVE-2006-7177

    Last Modified: 23 Apr 2026

    MadWifi, when Ad-Hoc mode is used, allows remote attackers to cause a denial of service (system crash) via unspecified vectors that lead to a kernel panic in the ieee80211_input function, related to "packets coming from a 'malicious' WinXP system."

    Published: 30 Mar 2007
    4.3
    Medium

    CVE-2007-1768

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in app/helpers/application_helper.rb in Mephisto 0.7.3 and Mephisto Edge 20070325 allows remote attackers to inject arbitrary web script or HTML via the author name field in a comment.

    Published: 30 Mar 2007
    10
    Critical

    CVE-2007-1770

    Last Modified: 23 Apr 2026

    Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.

    Published: 30 Mar 2007
    10
    Critical

    CVE-2007-1778

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 30 Mar 2007
    7.5
    High

    CVE-2007-1779

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.

    Published: 30 Mar 2007
    Unknown

    CVE-2007-1769

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-1873. Reason: This candidate is a duplicate of CVE-2007-1873. Notes: All CVE users should reference CVE-2007-1873 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Mar 2007
    6
    Medium

    CVE-2007-1764

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in FastStone Image Viewer 2.8 allows user-assisted remote attackers to execute arbitrary code via a crafted JPG image.

    Published: 30 Mar 2007
    7.1
    High

    CVE-2007-1763

    Last Modified: 23 Apr 2026

    The ATI kernel driver (atikmdag.sys) in Microsoft Windows Vista allows user-assisted remote attackers to cause a denial of service (crash) via a crafted JPG image, as demonstrated by a slideshow, possibly due to a buffer overflow.

    Published: 30 Mar 2007
    7.8
    High

    CVE-2007-1767

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in (1) Deskbar.dll and (2) Toolbar.dll in AOL 9.0 before February 2007 allows remote attackers to cause a denial of service (browser crash) via unknown vectors.

    Published: 30 Mar 2007
    6.6
    Medium

    CVE-2007-1677

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the ISO network protocol support in the NetBSD kernel 2.0 through 4.0_BETA2, and NetBSD-current before 20070329, allow local users to execute arbitrary code via long parameters to certain functions, as demonstrated by a long sockaddr structure argument to the clnp_route function.

    Published: 30 Mar 2007
    5
    Medium

    CVE-2007-1762

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.

    Published: 30 Mar 2007
    9.3
    Critical

    CVE-2007-1765

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.

    Published: 30 Mar 2007
    10
    Critical

    CVE-2007-1766

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Published: 30 Mar 2007
    4.3
    Medium

    CVE-2006-4843

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protection scheme.

    Published: 29 Mar 2007
    4.3
    Medium

    CVE-2007-0242

    Last Modified: 23 Apr 2026

    The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

    Published: 29 Mar 2007
    4
    Medium

    CVE-2007-2583

    Last Modified: 23 Apr 2026

    The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.

    Published: 29 Mar 2007
    Unknown

    CVE-2007-1740

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4843. Reason: This candidate is a duplicate of CVE-2006-4843. Notes: All CVE users should reference CVE-2006-4843 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Mar 2007
    7.5
    High

    CVE-2007-1737

    Last Modified: 23 Apr 2026

    Opera 9.10 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.

    Published: 28 Mar 2007
    7.5
    High

    CVE-2007-1736

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.

    Published: 28 Mar 2007
    9.3
    Critical

    CVE-2007-1735

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.

    Published: 28 Mar 2007
    7.2
    High

    CVE-2007-1734

    Last Modified: 23 Apr 2026

    The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.

    Published: 28 Mar 2007