CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-0803

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in STLport before 5.0.3 allow remote attackers to execute arbitrary code via unspecified vectors relating to (1) "print floats" and (2) a missing null termination in the "rope constructor."

    Published: 7 Feb 2007
    6.8
    Medium

    CVE-2007-0807

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in info.php in flashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via a channel title (aka room name) that is not properly handled by the "who's online" feature.

    Published: 7 Feb 2007
    7.5
    High

    CVE-2007-0808

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Mina Ajans Script allows remote attackers to execute arbitrary PHP code via a URL in the syf parameter to an unspecified PHP script.

    Published: 7 Feb 2007
    7.5
    High

    CVE-2007-0810

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_libraries] parameter. NOTE: this might be a vulnerability in MVCnPHP rather than a vulnerability in GeekLog.

    Published: 7 Feb 2007
    4.3
    Medium

    CVE-2007-0811

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an HTML document containing a certain JavaScript for loop with an empty loop body, possibly involving getElementById.

    Published: 7 Feb 2007
    5
    Medium

    CVE-2007-0816

    Last Modified: 23 Apr 2026

    The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.

    Published: 7 Feb 2007
    4.3
    Medium

    CVE-2007-0817

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page.

    Published: 7 Feb 2007
    Unknown

    CVE-2007-0818

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-0396. Reason: This candidate is a duplicate of CVE-2007-0396. Notes: All CVE users should reference CVE-2007-0396 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Feb 2007
    4.3
    Medium

    CVE-2007-0813

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Home production MySearchEngine allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Feb 2007
    5
    Medium

    CVE-2006-6970

    Last Modified: 23 Apr 2026

    Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demonstrated by the "." and "/" characters, which is not caught by the blacklist filter.

    Published: 7 Feb 2007
    2.1
    Low

    CVE-2007-0805

    Last Modified: 23 Apr 2026

    The ps (/usr/ucb/ps) command on HP Tru64 UNIX 5.1 1885 allows local users to obtain sensitive information, including environment variables of arbitrary processes, via the "auxewww" argument, a similar issue to CVE-1999-1587.

    Published: 7 Feb 2007
    7.5
    High

    CVE-2007-0806

    Last Modified: 23 Apr 2026

    Les News 2.2 allows remote attackers to bypass authentication and gain administrative access via a direct request for adminews/index_fr.php3, and possibly the adminews index documents for other localizations.

    Published: 7 Feb 2007
    4.3
    Medium

    CVE-2007-0815

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in images_archive.asp in Uapplication Uphotogallery 1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the s parameter. NOTE: the thumbnails.asp vector is already covered by CVE-2006-3023.

    Published: 7 Feb 2007
    7.5
    High

    CVE-2007-0804

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject arbitrary PHP code into arbitrary files via ".." sequences in the subpageName parameter, as demonstrated by injecting PHP code into a template file.

    Published: 7 Feb 2007
    7.5
    High

    CVE-2007-0809

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2 in ptirhiikmods allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 7 Feb 2007
    7.5
    High

    CVE-2007-0812

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authenticated users to execute arbitrary SQL commands via the pmid[0] parameter.

    Published: 7 Feb 2007
    4.3
    Medium

    CVE-2007-0814

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Adrenalin's ASP Chat allow remote attackers to inject arbitrary web script or HTML (1) via the psuedo (pseudo) field or (2) during chat.

    Published: 7 Feb 2007
    1.2
    Low

    CVE-2006-1167

    Last Modified: 23 Apr 2026

    SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0785

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0786

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Feb 2007
    6.8
    Medium

    CVE-2007-0789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0790

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.

    Published: 6 Feb 2007
    4.3
    Medium

    CVE-2007-0791

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0792

    Last Modified: 23 Apr 2026

    The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0793

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0794

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0795

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0797

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pfad_z parameter.

    Published: 6 Feb 2007
    4.3
    Medium

    CVE-2007-0798

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) login.asp; and allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (2) badword.asp, (3) polls.asp, and (4) users.asp.

    Published: 6 Feb 2007
    6.8
    Medium

    CVE-2007-0787

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in controller.php in Simple Invoices before 20070202 allows remote attackers to execute arbitrary PHP code via a URL in the (1) module or (2) view parameter. NOTE: some of these details are obtained from third party information.

    Published: 6 Feb 2007
    4.3
    Medium

    CVE-2007-0788

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MediaWiki 1.9.x before 1.9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "sortable tables JavaScript."

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0799

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in badword.asp in Ublog Reload 1.0.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0796

    Last Modified: 23 Apr 2026

    Blue Coat Systems WinProxy 6.1a and 6.0 r1c, and possibly earlier, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long HTTP CONNECT request, which triggers heap corruption.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0784

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters.

    Published: 6 Feb 2007
    4.6
    Medium

    CVE-2007-0453

    Last Modified: 23 Apr 2026

    Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.

    Published: 6 Feb 2007
    7.8
    High

    CVE-2007-0756

    Last Modified: 23 Apr 2026

    Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0757

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0762

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 6 Feb 2007
    6.8
    Medium

    CVE-2007-0763

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the Autor field.

    Published: 6 Feb 2007
    6.5
    Medium

    CVE-2007-0764

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in F3Site 2.1 and earlier allows remote authenticated administrators to upload and execute arbitrary PHP scripts via GIF86 header in a file in the uplf parameter, which can be later accessed via a relative pathname in the dir parameter in adm.php.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0760

    Last Modified: 23 Apr 2026

    EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an admin/ URL, which allows remote attackers to read or modify account names and passwords via a spoofed Referer.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0761

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers to execute arbitrary PHP code via a URL in the ezconvert_dir parameter.

    Published: 6 Feb 2007
    6.8
    Medium

    CVE-2007-0769

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.php in Phorum 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the vendor disputes this vulnerability, stating that "The characters are escaped properly.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0758

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Feb 2007
    5.8
    Medium

    CVE-2006-6968

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the group moderation control center page in Phorum before 5.1.19 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0454

    Last Modified: 23 Apr 2026

    Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0759

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.

    Published: 6 Feb 2007
    7.5
    High

    CVE-2007-0765

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arbitrary SQL commands via the c_id parameter.

    Published: 6 Feb 2007
    6.8
    Medium

    CVE-2007-0767

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the core in Phorum before 5.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2007
    4.3
    Medium

    CVE-2007-0768

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.

    Published: 6 Feb 2007