CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-0721

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.

    Published: 13 Mar 2007
    5
    Medium

    CVE-2007-0726

    Last Modified: 23 Apr 2026

    The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.

    Published: 13 Mar 2007
    4.4
    Medium

    CVE-2007-0728

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.

    Published: 13 Mar 2007
    9.3
    Critical

    CVE-2007-0733

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memory corruption.

    Published: 13 Mar 2007
    6.8
    Medium

    CVE-2007-0719

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.

    Published: 13 Mar 2007
    6.8
    Medium

    CVE-2007-1387

    Last Modified: 23 Apr 2026

    The DirectShow loader (loader/dshow/DS_VideoDecoder.c) in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allows user-assisted remote attackers to cause a buffer overflow and possibly execute arbitrary code, a different vulnerability than CVE-2007-1246.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1432

    Last Modified: 23 Apr 2026

    Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with modified arguments in (1) the user_permissions parameter to add_users.php, and unspecified parameters to (2) addblog.php, (3) editblog.php, (4) editlinks.php, (5) edit_users.php, and (6) add_links.php.

    Published: 13 Mar 2007
    4.3
    Medium

    CVE-2007-1433

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.

    Published: 13 Mar 2007
    7.8
    High

    CVE-2007-1431

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in PennMUSH 1.8.3 before 1.8.3p1 and 1.8.2 before 1.8.2p3 allow attackers to cause a denial of service (crash) related to the (1) speak and (2) buy functions.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1434

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) userdetail.php, id and (2) url parameter to (b) jump.php, and id variable to (c) detail.php.

    Published: 13 Mar 2007
    10
    Critical

    CVE-2007-1435

    Last Modified: 23 Apr 2026

    Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1436

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring.

    Published: 13 Mar 2007
    9
    Critical

    CVE-2007-1437

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution.

    Published: 13 Mar 2007
    9.3
    Critical

    CVE-2007-1423

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the g_include parameter to include/include_top.php and certain other PHP scripts.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1424

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Softnews Media Group DataLife Engine allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) init.php and (2) Ajax/editnews.php. NOTE: some of these details are obtained from third party information.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1422

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in goster.asp in fystyq Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-0688.

    Published: 13 Mar 2007
    10
    Critical

    CVE-2007-1421

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Premod SubDog 2 allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) functions_kb.php, (2) themen_portal_mitte.php, or (3) logger_engine.php in includes/.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action.

    Published: 13 Mar 2007
    7.8
    High

    CVE-2007-1426

    Last Modified: 23 Apr 2026

    The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue."

    Published: 13 Mar 2007
    5
    Medium

    CVE-2007-1427

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the pdf_file parameter.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1428

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in PHP Labs JobSitePro 1.0 allows remote attackers to execute arbitrary SQL commands via the salary parameter.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1429

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1430

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/adodb-connection.inc.php in ClipShare 1.5.3 allows remote attackers to execute arbitrary PHP code via a URL in the cmd parameter.

    Published: 13 Mar 2007
    7.5
    High

    CVE-2007-1413

    Last Modified: 23 Apr 2026

    Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id).

    Published: 12 Mar 2007
    10
    Critical

    CVE-2007-1414

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a) image_processor.php or (b) picmgmt.inc.php, or the (2) path parameter to (c) include/functions.php, (d) include/plugin_api.inc.php, (e) index.php, or (f) pluginmgr.php.

    Published: 12 Mar 2007
    7.5
    High

    CVE-2007-1415

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path parameter to (a) includes/resa_func.inc.php (b) admin/notices/perso.inc.php, or (c) admin/quotas/main.inc.php; the (2) base_path parameter to (d) opac_css/rec_panier.php or (e) opac_css/includes/author_see.inc.php; or the (3) include_path parameter to (f) bull_info.inc.php or (g) misc.inc.php in includes/; (h) options_date_box.php, (i) options_file_box.php, (j) options_list.php, (k) options_query_list.php, or (l) options_text.php in includes/options/; (m) options.php, (n) options_comment.php, (o) options_date_box.php, (p) options_list.php, (q) options_query_list.php, or (r) options_text.php in includes/options_empr/; or (s) admin/import/iimport_expl.php, (t) admin/netbase/clean.php, (u) admin/param/param_func.inc.php, (v) admin/sauvegarde/lieux.inc.php, (w) autorites.php, (x) account.php, (y) cart.php, or (z) edit.php.

    Published: 12 Mar 2007
    10
    Critical

    CVE-2007-1416

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers to execute arbitrary PHP code via a URL in the formurl parameter.

    Published: 12 Mar 2007
    7.8
    High

    CVE-2007-1412

    Last Modified: 23 Apr 2026

    The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.

    Published: 12 Mar 2007
    7.5
    High

    CVE-2007-1417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in HC NEWSSYSTEM 1.0-4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a komm aktion.

    Published: 12 Mar 2007
    4.3
    Medium

    CVE-2007-1418

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before Gooseberry++ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 12 Mar 2007
    4.3
    Medium

    CVE-2007-1419

    Last Modified: 23 Apr 2026

    The Java Management Extensions Remote API Remote Method Invocation over Internet Inter-ORB Protocol (JMX RMI-IIOP) API in Java Dynamic Management Kit 5.1 before 20070309 does not properly enforce the java.policy, which allows local users to obtain certain MBeans data access by operating a server application accessed by a privileged remote authenticated user.

    Published: 12 Mar 2007
    6.8
    Medium

    CVE-2008-1096

    Last Modified: 23 Apr 2026

    The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.

    Published: 11 Mar 2007
    6.8
    Medium

    CVE-2008-1097

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the ReadPCXImage function in the PCX coder in coders/pcx.c in (1) ImageMagick 6.2.4-5 and 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption.

    Published: 11 Mar 2007
    7.5
    High

    CVE-2007-1389

    Last Modified: 23 Apr 2026

    dynaliens 2.0 and 2.1 allows remote attackers to bypass authentication and perform certain privileged actions via a direct request for (1) validlien.php3 (2) supprlien.php3 (3) supprub.php3 (4) validlien.php3 (5) confsuppr.php3 (6) modiflien.php3, or (7) confmodif.php3 in admin/.

    Published: 10 Mar 2007
    10
    Critical

    CVE-2007-1397

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings.

    Published: 10 Mar 2007
    10
    Critical

    CVE-2007-1393

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Published: 10 Mar 2007
    9.8
    Critical

    CVE-2007-1399

    Last Modified: 11 Dec 2025

    Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

    Published: 10 Mar 2007
    5
    Medium

    CVE-2007-1392

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a .. (dot dot) in the file_to_download parameter.

    Published: 10 Mar 2007
    10
    Critical

    CVE-2007-1408

    Last Modified: 23 Apr 2026

    Multiple vulnerabilities in (1) bank.php, (2) landfill.php, (3) outposts.php, (4) tribes.php, (5) house.php, (6) tribearmor.php, (7) tribeastral.php, (8) tribeware.php, and (9) includes/head.php in Bartek Jasicki Vallheru before 1.3 beta have unknown impact and remote attack vectors, probably related to large integer values containing more than 15 digits. NOTE: the original vendor report is for integer overflows, but this is probably an incorrect usage of the term.

    Published: 10 Mar 2007
    4.3
    Medium

    CVE-2007-1390

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in dynaliens 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) recherche.php3 or (2) ajouter.php3.

    Published: 10 Mar 2007
    4.3
    Medium

    CVE-2007-1395

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in index.php in phpMyAdmin 2.8.0 through 2.9.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by injecting arbitrary JavaScript or HTML in a (1) db or (2) table parameter value followed by an uppercase </SCRIPT> end tag, which bypasses the protection against lowercase </script>.

    Published: 10 Mar 2007
    6.8
    Medium

    CVE-2007-1396

    Last Modified: 23 Apr 2026

    The import_request_variables function in PHP 4.0.7 through 4.4.6, and 5.x before 5.2.2, when called without a prefix, does not prevent the (1) GET, (2) POST, (3) COOKIE, (4) FILES, (5) SERVER, (6) SESSION, and other superglobals from being overwritten, which allows remote attackers to spoof source IP address and Referer data, and have other unspecified impact. NOTE: it could be argued that this is a design limitation of PHP and that only the misuse of this feature, i.e. implementation bugs in applications, should be included in CVE. However, it has been fixed by the vendor.

    Published: 10 Mar 2007
    6.9
    Medium

    CVE-2007-1400

    Last Modified: 23 Apr 2026

    Plash permits sandboxed processes to open /dev/tty, which allows local users to escape sandbox restrictions and execute arbitrary commands by sending characters to a shell process on the same termimal via the TIOCSTI ioctl.

    Published: 10 Mar 2007
    6.9
    Medium

    CVE-2007-1401

    Last Modified: 23 Apr 2026

    Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.

    Published: 10 Mar 2007
    7.5
    High

    CVE-2007-1403

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885.

    Published: 10 Mar 2007
    10
    Critical

    CVE-2007-1406

    Last Modified: 23 Apr 2026

    Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

    Published: 10 Mar 2007
    5
    Medium

    CVE-2007-1409

    Last Modified: 23 Apr 2026

    WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.

    Published: 10 Mar 2007
    6.8
    Medium

    CVE-2007-1411

    Last Modified: 23 Apr 2026

    Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

    Published: 10 Mar 2007
    10
    Critical

    CVE-2007-1391

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

    Published: 10 Mar 2007
    10
    Critical

    CVE-2007-1394

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php. NOTE: some of these details are obtained from third party information.

    Published: 10 Mar 2007