CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2006-6100

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2006. Notes: none

    Published: 24 Mar 2007
    10
    Critical

    CVE-2007-1666

    Last Modified: 23 Apr 2026

    The processor_request function in the debugger server for DataRescue IDA Pro 5.0 and 5.1 does not verify that authentication has taken place before invoking the perform_request function, which allows remote attackers to perform unauthorized actions.

    Published: 24 Mar 2007
    10
    Critical

    CVE-2007-1465

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53.

    Published: 24 Mar 2007
    9.3
    Critical

    CVE-2007-1658

    Last Modified: 23 Apr 2026

    Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).

    Published: 24 Mar 2007
    7.5
    High

    CVE-2007-1657

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-dependent attackers to execute arbitrary code via a long file argument.

    Published: 24 Mar 2007
    7.5
    High

    CVE-2007-1656

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Katalog Plyt Audio 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fraza and (2) litera parameters, different vectors than CVE-2007-1612. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2007
    10
    Critical

    CVE-2007-1655

    Last Modified: 23 Apr 2026

    Buffer overflow in the fun_ladd function in funmath.cpp in TinyMUX before 20070126 might allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors related to lists of numbers.

    Published: 24 Mar 2007
    9.3
    Critical

    CVE-2007-1654

    Last Modified: 23 Apr 2026

    Buffer overflow in the Ne7sshSftp::addOpenHandle function in ne7ssh_sftp.cpp in NetSieben SSH Library (ne7ssh) before 1.2.1 allows user-assisted remote SFTP servers to cause a denial of service (crash) or possibly execute arbitrary code via multiple file transfers, related to multiple open file handles in SFTP (1) put and (2) get operations.

    Published: 24 Mar 2007
    7.5
    High

    CVE-2007-1652

    Last Modified: 23 Apr 2026

    OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.

    Published: 24 Mar 2007
    10
    Critical

    CVE-2007-1644

    Last Modified: 23 Apr 2026

    The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).

    Published: 24 Mar 2007
    10
    Critical

    CVE-2007-1645

    Last Modified: 23 Apr 2026

    Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.

    Published: 24 Mar 2007
    7.8
    High

    CVE-2007-1653

    Last Modified: 23 Apr 2026

    GlowWorm FW before 1.5.3b4 allows remote attackers to cause a denial of service (kernel panic) via certain DNS responses that trigger infinite recursion in TrueDNS packet parsing, as originally observed with certain login.yahoo.com responses.

    Published: 24 Mar 2007
    4
    Medium

    CVE-2007-1642

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ManageEngine Firewall Analyzer allows remote authenticated users to "access any common file" via a direct URL request.

    Published: 24 Mar 2007
    10
    Critical

    CVE-2007-1643

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG[directories][userpanel_dir] parameter to userpanel.php or the (2) _LIB_DIR parameter to welcome.php.

    Published: 24 Mar 2007
    4.3
    Medium

    CVE-2007-1646

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SubHub 2.3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the searchtext parameter to (a) /search, or the (2) message parameter to (b) /calendar or (c) /subscribe.

    Published: 24 Mar 2007
    7.8
    High

    CVE-2007-1647

    Last Modified: 23 Apr 2026

    Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

    Published: 24 Mar 2007
    7.8
    High

    CVE-2007-1648

    Last Modified: 23 Apr 2026

    0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC server that sends a long string to a client, which triggers a NULL pointer dereference.

    Published: 24 Mar 2007
    7.8
    High

    CVE-2007-1649

    Last Modified: 23 Apr 2026

    PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a serialized data input string beginning with S:, which does not properly track the number of input bytes being processed.

    Published: 24 Mar 2007
    7.8
    High

    CVE-2007-1650

    Last Modified: 23 Apr 2026

    pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via a malformed SIP packet, which results in a NULL pointer dereference.

    Published: 24 Mar 2007
    6.8
    Medium

    CVE-2007-1651

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enabled site via unspecified vectors related to an arbitrary remote web site and cached tokens, after the user has signed into an OpenID server, logged into the OpenID enabled site, and then logged out of the OpenID enabled site.

    Published: 24 Mar 2007
    6.8
    Medium

    CVE-2007-1638

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote attackers to perform unauthorized actions as an arbitrary user via the (1) Projects, (2) Contacts, (3) Helpdesk, (4) Notes, (5) Search, (6) Mail, or (7) Filemanager module; the (9) summary page; or unspecified other files.

    Published: 23 Mar 2007
    4.6
    Medium

    CVE-2007-1639

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file with an executable extension, which is then accessed by the (1) calendar or (2) file management module, or possibly unspecified other files.

    Published: 23 Mar 2007
    10
    Critical

    CVE-2007-1640

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the BASE parameter to (1) language.php and (2) phpadmin/survey.php.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1641

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the idnews parameter.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1636

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the op parameter, as demonstrated by injecting PHP code into Apache log files via the URL and User-Agent HTTP header.

    Published: 23 Mar 2007
    9.3
    Critical

    CVE-2007-1637

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the (5) SetReplyTo member in the (c) IMailUserCollection control.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1634

    Last Modified: 23 Apr 2026

    Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to conduct SQL injection attacks via the _FILES[DB][tmp_name] parameter to print.php, which overwrites the $DB variable with dynamic variable evaluation.

    Published: 23 Mar 2007
    9
    Critical

    CVE-2007-1635

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote authenticated users to inject arbitrary PHP code via the xtop parameter in a "ConfigSave" op to admin.php, which can later be accessed via a "Configure" op to admin.php.

    Published: 23 Mar 2007
    4.3
    Medium

    CVE-2007-1623

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in realGuestbook 5.01, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) bg_color_1, (2) fs_menu, (3) fc_menu, (4) ff_menu, (5) bg_color_2, (6) fs_normal, (7) fc_normal, and (8) ff_normal parameters to welcome_admin.php; and possibly unspecified other parameters and files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Mar 2007
    9.3
    Critical

    CVE-2007-1628

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.inc.php or (2) settings.ses.php in inc/; (3) db/mysql/db.inc.php; (4) integration/shortstat/configuration.php; (5) ali.class.php or (6) cat.class.php in methodology/traditional/class/; (7) cat_browse.inc.php, (8) chr_browse.inc.php, (9) chr_display.inc.php, or (10) dash_browse.inc.php in methodology/traditional/ui/inc/; (11) spl.webservice.php or (12) konfabulator/gateway_admin.php in ws/; or other unspecified files.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1629

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 23 Mar 2007
    Unknown

    CVE-2007-1627

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4606. Reason: This candidate is a duplicate of CVE-2006-4606. Notes: All CVE users should reference CVE-2006-4606 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1624

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in realGuestbook 5.01 allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, and (4) text parameters to save_entry.php, as reachable through add_entry.php; and possibly other unspecified parameters and files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Mar 2007
    4.3
    Medium

    CVE-2007-1625

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in save_entry.php in realGuestbook 5.01 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter, as reachable through add_entry.php. NOTE: the original report stated that the vulnerability was in add_entry.php, which does not receive the input data.

    Published: 23 Mar 2007
    9.3
    Critical

    CVE-2007-1626

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1630

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 23 Mar 2007
    10
    Critical

    CVE-2007-1631

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in signup.php in CLBOX 1.01 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: this issue has been disputed by a reliable third party, stating that header is defined through an include file before use

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1632

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in TYPOlight webCMS before 2.2 Build 5 has unknown impact and attack vectors related to a "major security hole."

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1633

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by bbcode_ref.php.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1617

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1618

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix FAQ Builder 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1619

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the phid parameter.

    Published: 23 Mar 2007
    10
    Critical

    CVE-2007-1620

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SITE_PATH] parameter to (a) wind/help.php or (b) wind/about.php, or the (2) _SESSION[DRIVER] parameter to (c) db/session.php.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1616

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the recid parameter.

    Published: 23 Mar 2007
    10
    Critical

    CVE-2007-1621

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter. NOTE: this issue might be related to CVE-2003-1254.

    Published: 23 Mar 2007
    9.3
    Critical

    CVE-2007-1614

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1612

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Katalog Plyt Audio 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the kolumna parameter.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1613

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the logi parameter.

    Published: 23 Mar 2007
    7.5
    High

    CVE-2007-1615

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 23 Mar 2007
    4.3
    Medium

    CVE-2007-1622

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in the 2.1 series, allows remote authenticated users with theme privileges to inject arbitrary web script or HTML via the PATH_INFO in the administration interface, related to loose regular expression processing of PHP_SELF.

    Published: 23 Mar 2007