CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-1482

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd.

    Published: 16 Mar 2007
    4.6
    Medium

    CVE-2007-1484

    Last Modified: 23 Apr 2026

    The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, which triggers memory corruption and allows local users to bypass safe_mode and execute arbitrary code via a certain unset operation after array_user_key_compare has been called.

    Published: 16 Mar 2007
    6.8
    Medium

    CVE-2007-1470

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in LIBFtp 5.0 allow user-assisted remote attackers to execute arbitrary code via certain long arguments to the (1) FtpArchie, (2) FtpDebugDebug, (3) FtpOpenDir, (4) FtpSize, or (5) FtpChmod function.

    Published: 16 Mar 2007
    4.3
    Medium

    CVE-2007-1468

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Rational ClearQuest (CQ) Web 7.0.0.0 allows remote attackers to inject arbitrary web script or HTML via an attachment to a defect log entry.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.

    Published: 16 Mar 2007
    6.8
    Medium

    CVE-2007-1474

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Framework 3.1.4 allows local users to delete arbitrary files and possibly gain privileges via multiple space-delimited pathnames.

    Published: 16 Mar 2007
    5.4
    Medium

    CVE-2007-1475

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.4.6 and earlier allow context-dependent attackers to execute arbitrary code via a long argument.

    Published: 16 Mar 2007
    1.9
    Low

    CVE-2007-1476

    Last Modified: 23 Apr 2026

    The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's \Device file, which triggers invalid memory access, a different vulnerability than CVE-2006-4855.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1477

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cfg_language parameter. NOTE: this issue has been disputed by CVE, since the cfg_language variable is configured upon proper product installation

    Published: 16 Mar 2007
    5
    Medium

    CVE-2007-1478

    Last Modified: 23 Apr 2026

    download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the filename parameter.

    Published: 16 Mar 2007
    4.3
    Medium

    CVE-2007-1479

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Guestbook.php in Creative Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

    Published: 16 Mar 2007
    10
    Critical

    CVE-2007-1485

    Last Modified: 23 Apr 2026

    Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments

    Published: 16 Mar 2007
    10
    Critical

    CVE-2007-1486

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability.

    Published: 16 Mar 2007
    5
    Medium

    CVE-2007-1487

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a showarticles action.

    Published: 16 Mar 2007
    7.5
    High

    CVE-2007-1488

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.

    Published: 16 Mar 2007
    6.8
    Medium

    CVE-2007-1489

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery (CSRF) vulnerability.

    Published: 16 Mar 2007
    4.3
    Medium

    CVE-2007-1278

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root.

    Published: 16 Mar 2007
    4.9
    Medium

    CVE-2007-6712

    Last Modified: 23 Apr 2026

    Integer overflow in the hrtimer_forward function (hrtimer.c) in Linux kernel 2.6.21-rc4, when running on 64-bit systems, allows local users to cause a denial of service (infinite loop) via a timer with a large expiry value, which causes the timer to always be expired.

    Published: 16 Mar 2007
    9.3
    Critical

    CVE-2007-0002

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions. NOTE: the integer overflow has been split into CVE-2007-1466.

    Published: 16 Mar 2007
    4.9
    Medium

    CVE-2007-1592

    Last Modified: 23 Apr 2026

    net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, attaching a flow label, and connecting to that socket.

    Published: 16 Mar 2007
    6.8
    Medium

    CVE-2007-1466

    Last Modified: 23 Apr 2026

    Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than CVE-2007-0002.

    Published: 16 Mar 2007
    6.4
    Medium

    CVE-2007-1451

    Last Modified: 23 Apr 2026

    GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression des fichiers d'installation" (delete.php).

    Published: 14 Mar 2007
    7.5
    High

    CVE-2007-1456

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in PHP Photo Album allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability, because versions 0.3.2.6 and 0.4.1beta do not contain this file. However, it is possible that the original researcher was referring to a different product

    Published: 14 Mar 2007
    10
    Critical

    CVE-2007-1457

    Last Modified: 23 Apr 2026

    Buffer overflow in the urarlib_get function in Christian Scheurer UniquE RAR File Library (unrarlib, aka URARFileLib) 0.4 allows context-dependent attackers to execute arbitrary code via a long (1) filename, (2) rarfile, or (3) libpassword argument.

    Published: 14 Mar 2007
    6.8
    Medium

    CVE-2007-1458

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6) inc_diagnostics_report_fx.php, (7) inc_environment_global.php, (8) inc_front_chain_lang.php, (9) inc_init_crypt.php, (10) inc_load_copyrite.php, or (11) inc_news_save.php in include/; (12) diagnostics-report-index.php, (13) config_options_mascot.php, (14) barcode-labels.php, (15) chg-color.php, or (16) config_options_gui_template.php in main/; or unspecified other files.

    Published: 14 Mar 2007
    4.3
    Medium

    CVE-2007-1449

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Published: 14 Mar 2007
    7.5
    High

    CVE-2007-1450

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.

    Published: 14 Mar 2007
    5
    Medium

    CVE-2007-1452

    Last Modified: 23 Apr 2026

    The FDF support (ext/fdf) in PHP 5.2.0 and earlier does not implement the input filtering hooks for ext/filter, which allows remote attackers to bypass web site filters via an application/vnd.fdf formatted POST.

    Published: 14 Mar 2007
    7.5
    High

    CVE-2007-1453

    Last Modified: 23 Apr 2026

    Buffer underflow in the PHP_FILTER_TRIM_DEFAULT macro in the filtering extension (ext/filter) in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by calling filter_var with certain modes such as FILTER_VALIDATE_INT, which causes filter to write a null byte in whitespace that precedes the buffer.

    Published: 14 Mar 2007
    4.3
    Medium

    CVE-2007-1454

    Last Modified: 23 Apr 2026

    ext/filter in PHP 5.2.0, when FILTER_SANITIZE_STRING is used with the FILTER_FLAG_STRIP_LOW flag, does not properly strip HTML tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML with a '<' character followed by certain whitespace characters, which passes one filter but is collapsed into a valid tag, as demonstrated using %0b.

    Published: 14 Mar 2007
    9
    Critical

    CVE-2007-1455

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes/mysqlconfig.php and certain other files.

    Published: 14 Mar 2007
    6.8
    Medium

    CVE-2007-1459

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.

    Published: 14 Mar 2007
    5
    Medium

    CVE-2007-1460

    Last Modified: 23 Apr 2026

    The zip:// URL wrapper provided by the PECL zip extension in PHP before 4.4.7, and 5.2.0 and 5.2.1, does not implement safemode or open_basedir checks, which allows remote attackers to read ZIP archives located outside of the intended directories.

    Published: 14 Mar 2007
    7.8
    High

    CVE-2007-1461

    Last Modified: 23 Apr 2026

    The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.

    Published: 14 Mar 2007
    4.3
    Medium

    CVE-2007-0998

    Last Modified: 23 Apr 2026

    The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device. NOTE: some of these details are obtained from third party information.

    Published: 14 Mar 2007
    4.3
    Medium

    CVE-2007-1441

    Last Modified: 23 Apr 2026

    The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page.

    Published: 14 Mar 2007
    5
    Medium

    CVE-2007-0450

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

    Published: 14 Mar 2007
    7.2
    High

    CVE-2007-1442

    Last Modified: 23 Apr 2026

    Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.

    Published: 14 Mar 2007
    4.3
    Medium

    CVE-2007-1443

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_password, (4) r_confirmpassword, (5) r_homepage, (6) r_icq, (7) r_aim, (8) r_yim, (9) r_msn, (10) r_year, (11) r_month, (12) r_day, (13) r_gender, (14) r_signature, (15) r_usertext, (16) r_invisible, (17) r_usecookies, (18) r_admincanemail, (19) r_emailnotify, (20) r_notificationperpm, (21) r_receivepm, (22) r_emailonpm, (23) r_pmpopup, (24) r_showsignatures, (25) r_showavatars, (26) r_showimages, (27) r_daysprune, (28) r_umaxposts, (29) r_dateformat, (30) r_timeformat, (31) r_startweek, (32) r_timezoneoffset, (33) r_usewysiwyg, (34) r_styleid, (35) r_langid, (36) key_string, (37) key_number, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters. NOTE: a third-party researcher has disputed some of these vectors, stating that only the r_dateformat and r_timeformat parameters in Burning Board 2.3.6 are affected.

    Published: 14 Mar 2007
    7.5
    High

    CVE-2007-1445

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the heme preview feature for default.asp in BP Blog 7.0 through 7.0.2 allows remote attackers to execute arbitrary SQL commands via the layout parameter.

    Published: 14 Mar 2007
    4.4
    Medium

    CVE-2007-1444

    Last Modified: 23 Apr 2026

    netserver in netperf 2.4.3 allows local users to overwrite arbitrary files via a symlink attack on /tmp/netperf.debug.

    Published: 14 Mar 2007
    7.5
    High

    CVE-2007-1446

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) lib-account.inc.php, (2) lib-file.inc.php, (3) lib-group.inc.php, (4) lib-log.inc.php, (5) lib-mydb.inc.php, (6) lib-template-mod.inc.php, and (7) lib-themes.inc.php in includes/.

    Published: 14 Mar 2007
    7.5
    High

    CVE-2007-1440

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands via the author parameter.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1438

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 Mar 2007
    9.3
    Critical

    CVE-2007-1439

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ressourcen/dbopen.php in bitesser MySQL Commander 2.7 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.

    Published: 13 Mar 2007
    6.8
    Medium

    CVE-2007-0722

    Last Modified: 23 Apr 2026

    Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.

    Published: 13 Mar 2007
    6.9
    Medium

    CVE-2007-0724

    Last Modified: 23 Apr 2026

    The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.

    Published: 13 Mar 2007
    6.8
    Medium

    CVE-2007-0730

    Last Modified: 23 Apr 2026

    Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.

    Published: 13 Mar 2007
    9.3
    Critical

    CVE-2007-0731

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.

    Published: 13 Mar 2007
    8.5
    High

    CVE-2007-0723

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.

    Published: 13 Mar 2007