CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2007-1328

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in formulaire.php in Bernard JOLY BJ Webring allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter related to the add link menu.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2007-1329

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and collapse into .. (dot dot) sequences.

    Published: 7 Mar 2007
    4.4
    Medium

    CVE-2007-1330

    Last Modified: 23 Apr 2026

    Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.

    Published: 7 Mar 2007
    9.3
    Critical

    CVE-2007-1332

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme.

    Published: 7 Mar 2007
    5
    Medium

    CVE-2007-1324

    Last Modified: 23 Apr 2026

    SnapGear 560, 585, 580, 640, 710, and 720 appliances before the 3.1.4u5 firmware allow remote attackers to cause a denial of service (complete packet loss) via a packet flood, a different vulnerability than CVE-2006-4613.

    Published: 7 Mar 2007
    7.1
    High

    CVE-2007-1325

    Last Modified: 23 Apr 2026

    The PMA_ArrayWalkRecursive function in libraries/common.lib.php in phpMyAdmin before 2.10.0.2 does not limit recursion on arrays provided by users, which allows context-dependent attackers to cause a denial of service (web server crash) via an array with many dimensions. NOTE: it could be argued that this vulnerability is caused by a problem in PHP (CVE-2006-1549) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpMyAdmin.

    Published: 7 Mar 2007
    4.3
    Medium

    CVE-2007-1331

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program. NOTE: some of these details are obtained from third party information.

    Published: 7 Mar 2007
    6
    Medium

    CVE-2006-7138

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wwv_flow_utilities.gen_popup_list in the WWV_FLOW_UTILITIES package for Oracle APEX/HTMLDB before 2.2 allows remote authenticated users to execute arbitrary SQL by modifying the P_LOV parameter and calculating a matching MD5 checksum for the P_LOV_CHECKSUM parameter. NOTE: it is likely that this issue is subsumed by CVE-2006-5351, but due to lack of details from Oracle, this cannot be proven.

    Published: 7 Mar 2007
    2.6
    Low

    CVE-2006-7139

    Last Modified: 23 Apr 2026

    Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.

    Published: 7 Mar 2007
    5.8
    Medium

    CVE-2006-7140

    Last Modified: 23 Apr 2026

    The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents libike from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.

    Published: 7 Mar 2007
    5.8
    Medium

    CVE-2006-7143

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Call Center Software 0.93 and earlier allows remote attackers to inject arbitrary web script or HTML via the problem description field.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2006-7144

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Call Center Software 0.93 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the user name in the login page.

    Published: 7 Mar 2007
    5.5
    Medium

    CVE-2006-7145

    Last Modified: 23 Apr 2026

    edit_user.php in Call Center Software 0.93 and earlier allows remote attackers to obtain sensitive information such as account passwords via a modified user_id parameter.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2006-7148

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter. NOTE: this might be the same issues as CVE-2006-4893.

    Published: 7 Mar 2007
    8.5
    High

    CVE-2006-7152

    Last Modified: 23 Apr 2026

    default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo cookie values.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2006-7150

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.

    Published: 7 Mar 2007
    5
    Medium

    CVE-2006-7154

    Last Modified: 23 Apr 2026

    Iono allows remote attackers to obtain the full server path via certain requests to (1) templates/iono/admin/denied.tpl.php, (2) templates/iono/admin/index.tpl.php, and (a) other unspecified files in templates/.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2006-7155

    Last Modified: 23 Apr 2026

    Novell BorderManager 3.8 SP4 generates the same ISAKMP cookies for the same source IP and port number during the same day, which allows remote attackers to conduct denial of service and replay attacks. NOTE: this issue might be related to CVE-2006-5286.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2006-7156

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a module for miniBB, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

    Published: 7 Mar 2007
    7.1
    High

    CVE-2006-7157

    Last Modified: 23 Apr 2026

    Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2006-7161

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in giris_yap.asp in Hazir Site 2.0 allows remote attackers to bypass authentication via the (1) k_a class or (2) sifre parameter.

    Published: 7 Mar 2007
    6
    Medium

    CVE-2006-7141

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in Oracle Database Server, when utl_file_dir is set to a wildcard value or "CREATE ANY DIRECTORY to PUBLIC" privileges exist, allows remote authenticated users to read and modify arbitrary files via full filepaths to utl_file functions such as (1) utl_file.put_line and (2) utl_file.get_line, a related issue to CVE-2005-0701. NOTE: this issue is disputed by third parties who state that this is due to an insecure configuration instead of an inherent vulnerability

    Published: 7 Mar 2007
    7.5
    High

    CVE-2006-7146

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in communityPortals source distributions

    Published: 7 Mar 2007
    6.4
    Medium

    CVE-2006-7159

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/prune_torrents.php in BTI-Tracker 1.3.2 (aka btitracker) allows remote attackers to delete arbitrary files via ".." sequences in the TORRENTSDIR parameter in a prune action.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2006-7153

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter.

    Published: 7 Mar 2007
    7.8
    High

    CVE-2006-7142

    Last Modified: 23 Apr 2026

    The centralized management feature for Utimaco Safeguard stores hard-coded cryptographic keys in executable programs for encrypted configuration files, which allows attackers to recover the keys from the configuration files and decrypt the disk drive.

    Published: 7 Mar 2007
    6.8
    Medium

    CVE-2006-7147

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 7 Mar 2007
    6.6
    Medium

    CVE-2006-7151

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the libtool-ltdl library (libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute arbitrary code via a malicious library in the (1) hwcap, (2) 0, and (3) nosegneg subdirectories.

    Published: 7 Mar 2007
    4.9
    Medium

    CVE-2006-7160

    Last Modified: 23 Apr 2026

    The Sandbox.sys driver in Outpost Firewall PRO 4.0, and possibly earlier versions, does not validate arguments to hooked SSDT functions, which allows local users to cause a denial of service (crash) via invalid arguments to the (1) NtAssignProcessToJobObject,, (2) NtCreateKey, (3) NtCreateThread, (4) NtDeleteFile, (5) NtLoadDriver, (6) NtOpenProcess, (7) NtProtectVirtualMemory, (8) NtReplaceKey, (9) NtTerminateProcess, (10) NtTerminateThread, (11) NtUnloadDriver, and (12) NtWriteVirtualMemory functions.

    Published: 7 Mar 2007
    4.3
    Medium

    CVE-2006-7149

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcname parameter to (b) moscomment.php and (c) com_comment.php.

    Published: 7 Mar 2007
    4.3
    Medium

    CVE-2006-7158

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Oracle Application Express (APEX) before 2.2.1, aka Oracle HTML DB, allows remote attackers to inject arbitrary web script or HTML via the NOTIFICATION_MSG parameter. NOTE: it is likely that this issue overlaps one of the identifiers in CVE-2006-5351.

    Published: 7 Mar 2007
    5
    Medium

    CVE-2007-1497

    Last Modified: 23 Apr 2026

    nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments.

    Published: 7 Mar 2007
    4.9
    Medium

    CVE-2007-1496

    Last Modified: 23 Apr 2026

    nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference.

    Published: 7 Mar 2007
    7.8
    High

    CVE-2007-1306

    Last Modified: 23 Apr 2026

    Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.

    Published: 7 Mar 2007
    6.8
    Medium

    CVE-2007-1304

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in add2.php in Sava's Guestbook 23.11.2006, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) country, (3) email, (4) website, and (5) message parameters.

    Published: 7 Mar 2007
    7.8
    High

    CVE-2007-1300

    Last Modified: 23 Apr 2026

    DOURAN Software Technologies ISPUtil 3.32.84.1, and possibly earlier versions, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and reseller data via a direct request for scripts/activesessions.ini. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Mar 2007
    5.8
    Medium

    CVE-2007-1293

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categoria parameter to the top-level URI (index.php), possibly related to ver_descarga.php.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2006-7135

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Mar 2007
    6.8
    Medium

    CVE-2007-1305

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in add2.php in Sava's Guestbook 23.11.2006 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) country, (3) email, and (4) website parameters.

    Published: 7 Mar 2007
    7.8
    High

    CVE-2007-1303

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 7 Mar 2007
    6.8
    Medium

    CVE-2007-1302

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in guestbook.php in LI-Guestbook 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter. NOTE: it was later reported that 1.2 is also affected.

    Published: 7 Mar 2007
    9
    Critical

    CVE-2007-1301

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command. NOTE: this is probably different than CVE-2006-6423.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1296

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.

    Published: 7 Mar 2007
    7.8
    High

    CVE-2007-1294

    Last Modified: 23 Apr 2026

    A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.

    Published: 7 Mar 2007
    4.3
    Medium

    CVE-2006-7137

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in TinyPortal before 0.8.6 allows remote attackers to inject arbitrary web script or HTML via the shoutbox.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2006-7136

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.

    Published: 7 Mar 2007
    9
    Critical

    CVE-2007-1309

    Last Modified: 23 Apr 2026

    Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, then manually modifying policy.txt.

    Published: 7 Mar 2007
    10
    Critical

    CVE-2007-1288

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Webmobo WB News 1.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) comment.php, (2) themes.php, (3) directory.php, and (4) sendmsg.php in admin/.

    Published: 7 Mar 2007
    6.4
    Medium

    CVE-2007-1289

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ViewBugs.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Published: 7 Mar 2007
    7.5
    High

    CVE-2007-1290

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ViewReport.php in Tyger Bug Tracking System (TygerBT) 1.1.3 allows remote attackers to execute arbitrary SQL commands via the bug parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Mar 2007