CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-0908

    Last Modified: 23 Apr 2026

    The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize the key_length variable for a numerical key, which allows context-dependent attackers to read stack memory via a wddxPacket element that contains a variable with a string name before a numerical variable.

    Published: 13 Feb 2007
    10
    Critical

    CVE-2007-0910

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PHP before 5.2.1 allows attackers to "clobber" certain super-global variables via unspecified vectors.

    Published: 13 Feb 2007
    7.8
    High

    CVE-2007-0911

    Last Modified: 23 Apr 2026

    Off-by-one error in the str_ireplace function in PHP 5.2.1 might allow context-dependent attackers to cause a denial of service (crash).

    Published: 13 Feb 2007
    10
    Critical

    CVE-2007-0217

    Last Modified: 23 Apr 2026

    The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2006-4697

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2007-0208

    Last Modified: 23 Apr 2026

    Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2007-0209

    Last Modified: 23 Apr 2026

    Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.

    Published: 13 Feb 2007
    7.2
    High

    CVE-2007-0210

    Last Modified: 23 Apr 2026

    The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2006-5270

    Last Modified: 23 Apr 2026

    Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 13 Feb 2007
    10
    Critical

    CVE-2007-0903

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the mod_roster_odbc module in ejabberd before 1.1.3 has unknown impact and attack vectors.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2006-1311

    Last Modified: 23 Apr 2026

    The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2006-3448

    Last Modified: 23 Apr 2026

    Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2007-0025

    Last Modified: 23 Apr 2026

    The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the AfxOleSetEditMenu function in MFC42u.dll.

    Published: 13 Feb 2007
    7.6
    High

    CVE-2007-0026

    Last Modified: 23 Apr 2026

    The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.

    Published: 13 Feb 2007
    9.3
    Critical

    CVE-2007-0214

    Last Modified: 23 Apr 2026

    The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.

    Published: 13 Feb 2007
    7.5
    High

    CVE-2007-0900

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in TagIt! Tagboard 2.1.B Build 2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) configpath parameter to (a) tagviewer.php, (b) tag_process.php, and (c) CONFIG/errmsg.inc.php; and (d) addTagmin.php, (e) ban_watch.php, (f) delTagmin.php, (g) delTag.php, (h) editTagmin.php, (i) editTag.php, (j) manageTagmins.php, and (k) verify.php in tagmin/; the (2) adminpath parameter to (l) tagviewer.php, (m) tag_process.php, and (n) tagmin/index.php; and the (3) admin parameter to (o) readconf.php, (p) updateconf.php, (q) updatefilter.php, and (r) wordfilter.php in tagmin/; different vectors than CVE-2006-5249.

    Published: 13 Feb 2007
    4.3
    Medium

    CVE-2007-0901

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Feb 2007
    5
    Medium

    CVE-2007-0902

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Feb 2007
    7.5
    High

    CVE-2007-0904

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter to index.php.

    Published: 13 Feb 2007
    7.2
    High

    CVE-2007-0211

    Last Modified: 23 Apr 2026

    The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."

    Published: 13 Feb 2007
    4.3
    Medium

    CVE-2007-0896

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

    Published: 13 Feb 2007
    5
    Medium

    CVE-2007-0842

    Last Modified: 23 Apr 2026

    The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, (4) gmtime_s, (5) ctime, (6) ctime_s, (7) wctime, (8) wctime_s, and (9) fstat, trigger an assertion error instead of a NULL pointer or EINVAL when processing a time argument later than Jan 1, 3000, which might allow context-dependent attackers to cause a denial of service (application exit) via large time values. NOTE: it could be argued that this is a design limitation of the functions, and the vulnerability lies with any application that does not validate arguments to these functions. However, this behavior is inconsistent with documentation, which does not list assertions as a possible result of an error condition.

    Published: 13 Feb 2007
    2.6
    Low

    CVE-2007-0895

    Last Modified: 23 Apr 2026

    Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.

    Published: 13 Feb 2007
    4.3
    Medium

    CVE-2007-1462

    Last Modified: 23 Apr 2026

    The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.

    Published: 13 Feb 2007
    10
    Critical

    CVE-2007-1006

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.

    Published: 13 Feb 2007
    4.3
    Medium

    CVE-2007-0451

    Last Modified: 23 Apr 2026

    Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

    Published: 13 Feb 2007
    10
    Critical

    CVE-2007-1007

    Last Modified: 23 Apr 2026

    Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function.

    Published: 13 Feb 2007
    7.8
    High

    CVE-2006-7007

    Last Modified: 23 Apr 2026

    Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long USER command, a different vector than CVE-2000-0133.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-7008

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg from misuse." NOTE: it is possible that this issue overlaps CVE-2006-1029.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-7009

    Last Modified: 23 Apr 2026

    Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attack vectors.

    Published: 12 Feb 2007
    10
    Critical

    CVE-2007-0886

    Last Modified: 23 Apr 2026

    Heap-based buffer underflow in axigen 1.2.6 through 2.0.0b1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.

    Published: 12 Feb 2007
    7.8
    High

    CVE-2007-0887

    Last Modified: 23 Apr 2026

    axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).

    Published: 12 Feb 2007
    4.3
    Medium

    CVE-2007-0890

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in scripts/passwdmysql in cPanel WebHost Manager (WHM) 11.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the password parameter.

    Published: 12 Feb 2007
    4.3
    Medium

    CVE-2007-0891

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the GetCurrentCompletePath function in phpmyvisites.php in phpMyVisites before 2.2 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2007-0892

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the url parameter, when the pagename parameter begins with "FILE:".

    Published: 12 Feb 2007
    5
    Medium

    CVE-2007-0893

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in phpMyVisites before 2.2 allows remote attackers to include arbitrary files via leading ".." sequences on the pmv_ck_view COOKIE parameter, which bypasses the protection scheme.

    Published: 12 Feb 2007
    5
    Medium

    CVE-2007-0894

    Last Modified: 23 Apr 2026

    MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.

    Published: 12 Feb 2007
    4.6
    Medium

    CVE-2007-0889

    Last Modified: 23 Apr 2026

    Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-7003

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote attackers to execute arbitrary PHP code via a URL in the xtrphome parameter.

    Published: 12 Feb 2007
    6.8
    Medium

    CVE-2006-7004

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-7005

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-7006

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in upload/admin/team.php in Robin de Graff Somery 0.4.4 allows remote attackers to execute arbitrary PHP code via a URL in the checkauth parameter. NOTE: CVE disputes this vulnerability because the checkauth parameter is only used in conditionals

    Published: 12 Feb 2007
    10
    Critical

    CVE-2007-0888

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2006-7010

    Last Modified: 23 Apr 2026

    The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variable's default value is numeric, which has unspecified impact and attack vectors, which may permit SQL injection attacks.

    Published: 12 Feb 2007
    7.8
    High

    CVE-2007-0878

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser and other device functionality) via a malformed WML page, related to an "overflow state." NOTE: it is possible that this issue is related to CVE-2007-0685.

    Published: 12 Feb 2007
    9.3
    Critical

    CVE-2007-0879

    Last Modified: 23 Apr 2026

    Buffer overflow in SmidgeonSoft PEBrowse Professional 8.2.1.0 allows user-assisted remote attackers to execute arbitrary code via certain executable files in PE format. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2007
    5
    Medium

    CVE-2007-0883

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 12 Feb 2007
    7.5
    High

    CVE-2007-0884

    Last Modified: 23 Apr 2026

    Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 12 Feb 2007
    6.8
    Medium

    CVE-2007-0885

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in jira/secure/BrowseProject.jspa in Rainbow with the Zen (Rainbow.Zen) extension allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 12 Feb 2007
    6.8
    Medium

    CVE-2007-0881

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php. NOTE: vector 2 might be the same as CVE-2006-4750.

    Published: 12 Feb 2007