CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2007-1010

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/.

    Published: 21 Feb 2007
    10
    Critical

    CVE-2007-1014

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.

    Published: 21 Feb 2007
    7.8
    High

    CVE-2007-0772

    Last Modified: 23 Apr 2026

    The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS request that triggers a free of an incorrect pointer.

    Published: 20 Feb 2007
    9.3
    Critical

    CVE-2007-0325

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.

    Published: 20 Feb 2007
    10
    Critical

    CVE-2006-5276

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

    Published: 20 Feb 2007
    2.6
    Low

    CVE-2007-1008

    Last Modified: 23 Apr 2026

    Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requires an attacker to perform DNS spoofing or man-in-the-middle attacks for exploitation.

    Published: 20 Feb 2007
    4.7
    Medium

    CVE-2007-0001

    Last Modified: 23 Apr 2026

    The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9 allows local users to cause a denial of service (kernel panic) by replacing a watched file, which does not cause the watch on the old inode to be dropped.

    Published: 20 Feb 2007
    4.3
    Medium

    CVE-2007-1004

    Last Modified: 23 Apr 2026

    Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

    Published: 19 Feb 2007
    3.6
    Low

    CVE-2007-0007

    Last Modified: 23 Apr 2026

    gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.

    Published: 19 Feb 2007
    7.5
    High

    CVE-2007-6725

    Last Modified: 23 Apr 2026

    The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.

    Published: 19 Feb 2007
    5
    Medium

    CVE-2007-3392

    Last Modified: 23 Apr 2026

    Wireshark before 0.99.6 allows remote attackers to cause a denial of service via malformed (1) SSL or (2) MMS packets that trigger an infinite loop.

    Published: 17 Feb 2007
    6.4
    Medium

    CVE-2007-0898

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in clamd in Clam AntiVirus ClamAV before 0.90 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the id MIME header parameter in a multi-part message.

    Published: 16 Feb 2007
    2.1
    Low

    CVE-2007-0710

    Last Modified: 23 Apr 2026

    The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0897

    Last Modified: 23 Apr 2026

    Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0985

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary SQL commands via the npid parameter in a sign_gb action.

    Published: 16 Feb 2007
    5.1
    Medium

    CVE-2007-0986

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remote attackers to execute arbitrary PHP code via an ftp URL in the n parameter.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0987

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot), or an absolute pathname, in the n parameter.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0984

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to pollmentorres.asp.

    Published: 16 Feb 2007
    6.8
    Medium

    CVE-2007-0983

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the Root_To_Script parameter.

    Published: 16 Feb 2007
    4.3
    Medium

    CVE-2007-0982

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.php in TaskFreak! 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the tznMessage parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Feb 2007
    6.8
    Medium

    CVE-2007-0969

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0970

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0971

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts. NOTE: the attack vector might involve _SERVER.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0972

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an image content type, and to omit is_guest and is_user parameters. NOTE: this issue might be related to CVE-2006-4875.

    Published: 16 Feb 2007
    6.8
    Medium

    CVE-2007-0973

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Jupiter CMS 1.1.5 allow remote attackers to inject arbitrary web script or HTML via the Referer HTTP header and certain other HTTP headers, which are displayed without proper sanitization when an administrator performs a Logged Guest action.

    Published: 16 Feb 2007
    7.1
    High

    CVE-2007-0977

    Last Modified: 23 Apr 2026

    IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.

    Published: 16 Feb 2007
    7.2
    High

    CVE-2007-0978

    Last Modified: 23 Apr 2026

    Buffer overflow in swcons in IBM AIX 5.3 allows local users to gain privileges via long input data.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0981

    Last Modified: 23 Apr 2026

    Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

    Published: 16 Feb 2007
    10
    Critical

    CVE-2007-0976

    Last Modified: 23 Apr 2026

    Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary code via a long DVD_TOOLS.OpenDVD property value.

    Published: 16 Feb 2007
    5
    Medium

    CVE-2007-0975

    Last Modified: 23 Apr 2026

    Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.

    Published: 16 Feb 2007
    10
    Critical

    CVE-2007-0980

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Serviceguard for Linux; packaged for SuSE SLES8 and United Linux 1.0 before SG A.11.15.07, SuSE SLES9 and SLES10 before SG A.11.16.10, and Red Hat Enterprise Linux (RHEL) before SG A.11.16.10; allows remote attackers to obtain unauthorized access via unspecified vectors.

    Published: 16 Feb 2007
    7.5
    High

    CVE-2007-0974

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.

    Published: 16 Feb 2007
    5
    Medium

    CVE-2007-0979

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in LifeType before 1.1.6, and 1.2 before 1.2-beta2, allows remote attackers to obtain sensitive information (file contents) via a "crafted URL."

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0961

    Last Modified: 23 Apr 2026

    Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed SIP packets.

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0962

    Last Modified: 23 Apr 2026

    Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP traffic.

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0963

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.3), when set to log at the "debug" level, allows remote attackers to cause a denial of service (device reboot) by sending packets that are not of a particular protocol such as TCP or UDP, which triggers the reboot during generation of Syslog message 710006.

    Published: 16 Feb 2007
    5.4
    Medium

    CVE-2007-0964

    Last Modified: 23 Apr 2026

    Cisco FWSM 3.x before 3.1(3.18), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a malformed HTTPS request.

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0965

    Last Modified: 23 Apr 2026

    Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0967

    Last Modified: 23 Apr 2026

    Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.

    Published: 16 Feb 2007
    2.1
    Low

    CVE-2007-0859

    Last Modified: 23 Apr 2026

    The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory contents) by doing (1) text searches or (2) paste operations after pressing certain keyboard shortcut keys.

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0959

    Last Modified: 23 Apr 2026

    Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.

    Published: 16 Feb 2007
    9
    Critical

    CVE-2007-0960

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 16 Feb 2007
    7.8
    High

    CVE-2007-0966

    Last Modified: 23 Apr 2026

    Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.

    Published: 16 Feb 2007
    9
    Critical

    CVE-2007-0968

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.

    Published: 16 Feb 2007
    5.1
    Medium

    CVE-2007-0652

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.

    Published: 15 Feb 2007
    4.3
    Medium

    CVE-2007-0651

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.

    Published: 15 Feb 2007
    7.5
    High

    CVE-2007-0324

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the LizardTech DjVu Browser Plug-in before 6.1.1 allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 15 Feb 2007
    7.5
    High

    CVE-2006-7016

    Last Modified: 23 Apr 2026

    phpjobboard allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin.php with adminop=job-edit.

    Published: 15 Feb 2007
    7.5
    High

    CVE-2006-7014

    Last Modified: 23 Apr 2026

    admin.php in BloggIT 1.01 and earlier does not properly establish a user session, which allows remote attackers to gain privileges via a direct request.

    Published: 15 Feb 2007
    7.5
    High

    CVE-2006-7021

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter.

    Published: 15 Feb 2007