CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2007-1534

    Last Modified: 23 Apr 2026

    DFSR.exe in Windows Meeting Space in Microsoft Windows Vista remains available for remote connections on TCP port 5722 for 2 minutes after Windows Meeting Space is closed, which allows remote attackers to have an unknown impact by connecting to this port during the time window.

    Published: 20 Mar 2007
    4.3
    Medium

    CVE-2006-7164

    Last Modified: 23 Apr 2026

    SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

    Published: 20 Mar 2007
    4.3
    Medium

    CVE-2006-7165

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 5.0 through 5.1.1.0 allows remote attackers to obtain JSP source code and other sensitive information via certain "special URIs."

    Published: 20 Mar 2007
    7.5
    High

    CVE-2006-7170

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.

    Published: 20 Mar 2007
    5
    Medium

    CVE-2006-7171

    Last Modified: 23 Apr 2026

    product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with an empty value of the x[] parameter.

    Published: 20 Mar 2007
    7.5
    High

    CVE-2006-7168

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 20 Mar 2007
    7.5
    High

    CVE-2007-1507

    Last Modified: 23 Apr 2026

    The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.

    Published: 20 Mar 2007
    6.8
    Medium

    CVE-2007-1514

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the modpath parameter.

    Published: 20 Mar 2007
    6.8
    Medium

    CVE-2007-1516

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter.

    Published: 20 Mar 2007
    7.5
    High

    CVE-2006-7167

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ProRat Server 1.9 Fix2 allows remote attackers to bypass the authentication mechanism for remote login via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Mar 2007
    6.8
    Medium

    CVE-2006-7169

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter.

    Published: 20 Mar 2007
    4.3
    Medium

    CVE-2007-1509

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter.

    Published: 20 Mar 2007
    10
    Critical

    CVE-2007-1512

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP1, and Visual Studio .NET 2002 Gold and SP1, and 2003 Gold and SP1 allows user-assisted remote attackers to have an unknown impact (probably crash) via an RTF file with a malformed OLE object, which results in writing two 0x00 characters past the end of szBuffer, aka the "MFC42u.dll Off-by-Two Overflow." NOTE: this issue is due to an incomplete patch (MS07-012) for CVE-2007-0025.

    Published: 20 Mar 2007
    5
    Medium

    CVE-2006-7166

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 5.1.1.9 and earlier allows remote attackers to obtain JSP source code and other sensitive information via "a specific JSP URL."

    Published: 20 Mar 2007
    7.5
    High

    CVE-2007-1510

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Published: 20 Mar 2007
    7.1
    High

    CVE-2007-1511

    Last Modified: 23 Apr 2026

    Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.

    Published: 20 Mar 2007
    6.8
    Medium

    CVE-2007-1513

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.

    Published: 20 Mar 2007
    4.3
    Medium

    CVE-2007-1515

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via (1) the email Subject header in thread.php, (2) the edit_query parameter in search.php, or other unspecified parameters in search.php. NOTE: some of these details are obtained from third party information.

    Published: 20 Mar 2007
    4.3
    Medium

    CVE-2007-1508

    Last Modified: 16 Dec 2025

    Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary web script or HTML via the RESULT parameter, a different vector than CVE-2006-5983.

    Published: 20 Mar 2007
    9.3
    Critical

    CVE-2007-0238

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in filter\starcalc\scflt.cxx in the StarCalc parser in OpenOffice.org (OOo) Office Suite before 2.2, and 1.x before 1.1.5 Patch, allows user-assisted remote attackers to execute arbitrary code via a document with a long Note.

    Published: 20 Mar 2007
    9.3
    Critical

    CVE-2007-0239

    Last Modified: 23 Apr 2026

    OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.

    Published: 20 Mar 2007
    4.3
    Medium

    CVE-2007-0240

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.

    Published: 20 Mar 2007
    6.8
    Medium

    CVE-2007-1583

    Last Modified: 23 Apr 2026

    The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and does not disable it in certain cases when a script terminates, which allows remote attackers to invoke available PHP scripts with register_globals functionality that is not detectable by these scripts, as demonstrated by forcing a memory_limit violation.

    Published: 20 Mar 2007
    5
    Medium

    CVE-2007-1560

    Last Modified: 23 Apr 2026

    The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.

    Published: 20 Mar 2007
    10
    Critical

    CVE-2007-1319

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IOPCServer::RemoveGroup function in the OPCDA interface in Takebishi Electric DeviceXPlorer OLE for Process Control (OPC) Server before 3.12 Build3 allows remote attackers to execute arbitrary code via unspecified vectors involving access to arbitrary memory. NOTE: this issue affects the (1) HIDIC, (2) MELSEC, (3) FA-M3, (4) MODBUS, and (5) SYSMAC OPC Servers.

    Published: 19 Mar 2007
    4.3
    Medium

    CVE-2007-1500

    Last Modified: 23 Apr 2026

    The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.

    Published: 19 Mar 2007
    9.3
    Critical

    CVE-2007-1501

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Type HTTP header.

    Published: 19 Mar 2007
    6.8
    Medium

    CVE-2007-1502

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via a (1) long command, (2) long server argument to the (a) connect or (b) server commands, (3) long nick argument to the (c) nick command, or a long (4) nick or (5) message argument to the (d) ctcp, (e) chat, (f) notice, (g) message (msg), or (h) query commands.

    Published: 19 Mar 2007
    7.5
    High

    CVE-2007-1503

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in comm.c in Rhapsody IRC 0.28b allow remote attackers to execute arbitrary code via format string specifiers to the create_ctcp_message function using the message argument to the (1) me or (2) ctcp commands, and possibly related vectors involving the (3) whois, (4) mode, and (5) topic commands.

    Published: 19 Mar 2007
    4.3
    Medium

    CVE-2007-1504

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Servlet Service in Fujitsu Interstage Application Server (IJServer) 8.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving web.xml and HTTP 404 and 500 status codes.

    Published: 19 Mar 2007
    2.1
    Low

    CVE-2007-1505

    Last Modified: 23 Apr 2026

    Fujitsu FENCE-Pro before V5L01, and Systemwalker Desktop Encryption V12.0L10, V12.0L10A, V12.0L10B, V12.0L20 and V13.0.0 allows local users to obtain sensitive information by extracting the decoding password from certain "self-decoding" file types.

    Published: 19 Mar 2007
    4.3
    Medium

    CVE-2007-1506

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (1) p_oldurl and (2) p_newurl parameters.

    Published: 19 Mar 2007
    4.6
    Medium

    CVE-2007-0237

    Last Modified: 23 Apr 2026

    The ndeb-binary feature in Lookup (lookup-el) allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 19 Mar 2007
    4.3
    Medium

    CVE-2007-1499

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."

    Published: 17 Mar 2007
    2.1
    Low

    CVE-2007-1448

    Last Modified: 23 Apr 2026

    The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service (disabled interface) by calling an unspecified RPC function.

    Published: 16 Mar 2007
    10
    Critical

    CVE-2007-1447

    Last Modified: 23 Apr 2026

    The Tape Engine in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC procedure arguments, which result in memory corruption, a different vulnerability than CVE-2006-6076.

    Published: 16 Mar 2007
    5.2
    Medium

    CVE-2007-1491

    Last Modified: 23 Apr 2026

    Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.

    Published: 16 Mar 2007
    9.3
    Critical

    CVE-2007-1498

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.

    Published: 16 Mar 2007
    7.1
    High

    CVE-2007-1492

    Last Modified: 23 Apr 2026

    winmm.dll in Microsoft Windows XP allows user-assisted remote attackers to cause a denial of service (infinite loop) via a large cch argument value to the mmioRead function, as demonstrated by a crafted WAV file.

    Published: 16 Mar 2007
    6
    Medium

    CVE-2007-1490

    Last Modified: 23 Apr 2026

    Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1493

    Last Modified: 23 Apr 2026

    nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172.

    Published: 16 Mar 2007
    6.8
    Medium

    CVE-2007-1494

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in NukeSentinel before 2.5.06 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "filters for https:// and http://".

    Published: 16 Mar 2007
    4.9
    Medium

    CVE-2007-1495

    Last Modified: 23 Apr 2026

    The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.

    Published: 16 Mar 2007
    6.8
    Medium

    CVE-2007-1472

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in groupit/base/groupit.start.inc in Groupit 2.00b5 allows remote attackers to conduct remote file inclusion attacks and execute arbitrary PHP code via arguments that are written to $_GLOBALS, as demonstrated using a URL in the c_basepath parameter to (1) content.php, (2) userprofile.php, (3) password.php, (4) dispatch.php, and (5) deliver.php in html/, and possibly (6) load.inc.php and related files.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1481

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1483

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebCalendar 0.9.45 allow remote attackers to execute arbitrary PHP code via a URL in the includedir parameter to (1) login.php, (2) get_reminders.php, or (3) get_events.php.

    Published: 16 Mar 2007
    3.5
    Low

    CVE-2007-1467

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified Videoconferencing 35xx products, Unified Videoconferencing Manager, WAN Manager, Security Device Manager, Network Analysis Module (NAM), CiscoWorks and related products, Wireless LAN Solution Engine (WLSE), 2006 Wireless LAN Controllers (WLC), and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via the text field of the search form.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1471

    Last Modified: 23 Apr 2026

    admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.

    Published: 16 Mar 2007
    4.3
    Medium

    CVE-2007-1473

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login page contains a language selection box, allows remote attackers to inject arbitrary web script or HTML via the new_lang parameter to login.php.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1480

    Last Modified: 23 Apr 2026

    Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php with Name, Email, and PASSWORD parameters set.

    Published: 16 Mar 2007