CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-1223

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder control processing halt) by sending "data unexpectedly through the port".

    Published: 2 Mar 2007
    4.3
    Medium

    CVE-2007-1229

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.

    Published: 2 Mar 2007
    10
    Critical

    CVE-2007-1225

    Last Modified: 23 Apr 2026

    The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in a URL, which might allow remote attackers to conduct unauthorized activities and avoid detection.

    Published: 2 Mar 2007
    7.2
    High

    CVE-2007-1221

    Last Modified: 23 Apr 2026

    The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection.

    Published: 2 Mar 2007
    7.2
    High

    CVE-2007-1222

    Last Modified: 23 Apr 2026

    Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.

    Published: 2 Mar 2007
    6.2
    Medium

    CVE-2007-1220

    Last Modified: 23 Apr 2026

    The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code.

    Published: 2 Mar 2007
    7.5
    High

    CVE-2007-1219

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Published: 2 Mar 2007
    6.6
    Medium

    CVE-2007-1227

    Last Modified: 23 Apr 2026

    VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands.

    Published: 2 Mar 2007
    4.4
    Medium

    CVE-2007-1228

    Last Modified: 23 Apr 2026

    IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to access certain unauthorized directories.

    Published: 2 Mar 2007
    5.8
    Medium

    CVE-2007-1230

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow remote attackers to inject arbitrary web script or HTML via (1) the Referer HTTP header or (2) the URI, a different vulnerability than CVE-2007-1049.

    Published: 2 Mar 2007
    4.1
    Medium

    CVE-2007-1226

    Last Modified: 23 Apr 2026

    McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/VShieldExclude.txt, which allows local users to reconfigure Virex to skip scanning of arbitrary files.

    Published: 2 Mar 2007
    5
    Medium

    CVE-2007-1224

    Last Modified: 23 Apr 2026

    Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from the URL and specifies the destination port (:80).

    Published: 2 Mar 2007
    7.8
    High

    CVE-2007-1005

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion Detection 3.0.5.57 and earlier allows remote attackers to cause a denial of service (application crash) via a long key length value to the remote administration port (9191/tcp).

    Published: 2 Mar 2007
    4.3
    Medium

    CVE-2007-1198

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in TaskFreak! before 0.5.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a variant of CVE-2007-0982.

    Published: 2 Mar 2007
    10
    Critical

    CVE-2006-7097

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in TaskFreak! before 0.1.4 have unknown impact and attack vectors.

    Published: 2 Mar 2007
    10
    Critical

    CVE-2006-3892

    Last Modified: 23 Apr 2026

    The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands.

    Published: 2 Mar 2007
    10
    Critical

    CVE-2006-7095

    Last Modified: 23 Apr 2026

    Integer signedness error in the network_receive_packet function in socket.c in dimension 3 engine (dim3) 1.5 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large data_len value, which is cast to a signed short and results in a buffer overflow.

    Published: 2 Mar 2007
    10
    Critical

    CVE-2006-7096

    Last Modified: 23 Apr 2026

    Buffer overflow in the network_host_handle_join function in host.c in dimension 3 engine (dim3) 1.5 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.

    Published: 2 Mar 2007
    5
    Medium

    CVE-2007-1192

    Last Modified: 23 Apr 2026

    Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.

    Published: 2 Mar 2007
    9.3
    Critical

    CVE-2007-1193

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vectors.

    Published: 2 Mar 2007
    2.1
    Low

    CVE-2007-1194

    Last Modified: 23 Apr 2026

    Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze.

    Published: 2 Mar 2007
    6.9
    Medium

    CVE-2007-1217

    Last Modified: 23 Apr 2026

    Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.

    Published: 2 Mar 2007
    2.1
    Low

    CVE-2007-1191

    Last Modified: 23 Apr 2026

    The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.

    Published: 2 Mar 2007
    7.5
    High

    CVE-2007-1195

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.

    Published: 2 Mar 2007
    7.2
    High

    CVE-2007-1189

    Last Modified: 23 Apr 2026

    Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite certain memory addresses with kernel memory via a large n argument, as demonstrated by (1) modifying the iseve function to gain privileges and (2) making the devpermcheck function grant unrestricted device permissions.

    Published: 2 Mar 2007
    6.8
    Medium

    CVE-2007-1190

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Mar 2007
    9.3
    Critical

    CVE-2007-1196

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execute arbitrary code via unspecified vectors, related to the implementation of ICA connectivity through proxy servers.

    Published: 2 Mar 2007
    9.3
    Critical

    CVE-2007-1197

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Epiware before 4.7.5 have unknown impact and attack vectors, possibly related to cross-site scripting (XSS) and other unspecified issues.

    Published: 2 Mar 2007
    6.8
    Medium

    CVE-2007-1286

    Last Modified: 23 Apr 2026

    Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.

    Published: 2 Mar 2007
    7.8
    High

    CVE-2008-6621

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.

    Published: 1 Mar 2007
    5
    Medium

    CVE-2008-6072

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images.

    Published: 1 Mar 2007
    9.3
    Critical

    CVE-2008-6070

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are obtained from third party information.

    Published: 1 Mar 2007
    10
    Critical

    CVE-2008-6071

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. NOTE: some of these details are obtained from third party information.

    Published: 1 Mar 2007
    6.8
    Medium

    CVE-2007-1218

    Last Modified: 23 Apr 2026

    Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted 802.11 frame. NOTE: this was originally referred to as heap-based, but it might be stack-based.

    Published: 1 Mar 2007
    7.5
    High

    CVE-2007-1285

    Last Modified: 23 Apr 2026

    The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.

    Published: 1 Mar 2007
    4.3
    Medium

    CVE-2007-2721

    Last Modified: 23 Apr 2026

    The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.

    Published: 1 Mar 2007
    4.3
    Medium

    CVE-2007-1176

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 0.9.9.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) Gallery Comments pages, (2) Feedback pages, (3) Search Results pages, and (4) the Statistics Log viewer.

    Published: 28 Feb 2007
    5.8
    Medium

    CVE-2007-1177

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 does not properly filter certain characters in contexts related to (1) the query string, (2) Profiles, (3) the Forum Post icon field, (4) the Edit Profile, and (5) the Gallery, which has unknown impact and remote attack vectors, possibly related to cross-site scripting (XSS).

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1178

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1179

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 does not properly manage e-mail addresses in certain contexts related to (1) the Recommend feature, Email Article (2) senders and (3) recipients, (4) New User Approval, (5) Edit Profiles, (6) the Newsletter Subscription form, (7) the Recommend form, and (8) sending of articles, which has unknown impact, and remote attack vectors related to spam attacks and possibly other attacks.

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2007-1180

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 does not check referrers in certain forms, which might facilitate remote cross-site request forgery (CSRF) attacks or have other unknown impact.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1184

    Last Modified: 23 Apr 2026

    The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated programs to submit false data.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1185

    Last Modified: 23 Apr 2026

    The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs, which has unknown impact and remote attack vectors.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1186

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.

    Published: 28 Feb 2007
    6.4
    Medium

    CVE-2007-1182

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2007-1174

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebAPP before 20070214 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to unspecified fields in user Profiles. NOTE: some of these details are obtained from third party information.

    Published: 28 Feb 2007
    5
    Medium

    CVE-2007-1181

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown impact and attack vectors.

    Published: 28 Feb 2007
    4.3
    Medium

    CVE-2007-1175

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in an admin feature in WebAPP before 20070209 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Feb 2007
    7.5
    High

    CVE-2007-1183

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors.

    Published: 28 Feb 2007
    5.5
    Medium

    CVE-2007-1187

    Last Modified: 23 Apr 2026

    WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (1) the Forum Archive feature and (2) Recent Searches.

    Published: 28 Feb 2007