CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-0664

    Last Modified: 23 Apr 2026

    thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.

    Published: 2 Feb 2007
    7.5
    High

    CVE-2007-0656

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 1 Feb 2007
    6.8
    Medium

    CVE-2007-0660

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."

    Published: 1 Feb 2007
    7.5
    High

    CVE-2007-0662

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 1 Feb 2007
    7.5
    High

    CVE-2007-0663

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Feb 2007
    5
    Medium

    CVE-2007-0658

    Last Modified: 23 Apr 2026

    The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

    Published: 1 Feb 2007
    5.4
    Medium

    CVE-2007-0661

    Last Modified: 23 Apr 2026

    Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is enabled, allow remote attackers to connect and issue arbitrary IPMI commands, possibly triggering a denial of service.

    Published: 1 Feb 2007
    7.5
    High

    CVE-2007-0659

    Last Modified: 23 Apr 2026

    download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials.

    Published: 1 Feb 2007
    7.5
    High

    CVE-2007-0657

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Nexuiz 2.2.2 allows remote attackers to read and overwrite arbitrary files via the gamedir command.

    Published: 1 Feb 2007
    6.8
    Medium

    CVE-2007-0650

    Last Modified: 23 Apr 2026

    Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename. NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function.

    Published: 1 Feb 2007
    7.8
    High

    CVE-2007-0648

    Last Modified: 23 Apr 2026

    Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.

    Published: 1 Feb 2007
    4.3
    Medium

    CVE-2007-0649

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.

    Published: 1 Feb 2007
    5
    Medium

    CVE-2007-0459

    Last Modified: 23 Apr 2026

    packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.

    Published: 1 Feb 2007
    7.1
    High

    CVE-2007-0644

    Last Modified: 23 Apr 2026

    Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.

    Published: 1 Feb 2007
    6.8
    Medium

    CVE-2007-0645

    Last Modified: 23 Apr 2026

    Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.

    Published: 1 Feb 2007
    7.1
    High

    CVE-2007-0646

    Last Modified: 23 Apr 2026

    Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.

    Published: 1 Feb 2007
    7.1
    High

    CVE-2007-0647

    Last Modified: 23 Apr 2026

    Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.

    Published: 1 Feb 2007
    4.3
    Medium

    CVE-2007-0457

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 1 Feb 2007
    6.8
    Medium

    CVE-2007-0008

    Last Modified: 23 Apr 2026

    Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.

    Published: 1 Feb 2007
    6.8
    Medium

    CVE-2007-0009

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

    Published: 1 Feb 2007
    4.3
    Medium

    CVE-2007-0456

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 1 Feb 2007
    4.3
    Medium

    CVE-2007-0458

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.

    Published: 1 Feb 2007
    7.5
    High

    CVE-2007-0635

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.

    Published: 31 Jan 2007
    2.1
    Low

    CVE-2007-0636

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files."

    Published: 31 Jan 2007
    5
    Medium

    CVE-2007-0638

    Last Modified: 23 Apr 2026

    show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.

    Published: 31 Jan 2007
    10
    Critical

    CVE-2007-0640

    Last Modified: 23 Apr 2026

    Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0639

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0642

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.

    Published: 31 Jan 2007
    7.8
    High

    CVE-2007-0634

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.

    Published: 31 Jan 2007
    4.3
    Medium

    CVE-2007-0643

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0637

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0641

    Last Modified: 23 Apr 2026

    Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0633

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.

    Published: 31 Jan 2007
    4.9
    Medium

    CVE-2007-0625

    Last Modified: 23 Apr 2026

    nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service.

    Published: 31 Jan 2007
    4.3
    Medium

    CVE-2007-0628

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.

    Published: 31 Jan 2007
    4.9
    Medium

    CVE-2007-0627

    Last Modified: 23 Apr 2026

    Michael Still gtalkbot before 1.2 places username and password arguments on the command line, which allows local users to obtain sensitive information by listing the process.

    Published: 31 Jan 2007
    6.5
    Medium

    CVE-2007-0626

    Last Modified: 23 Apr 2026

    The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."

    Published: 31 Jan 2007
    6.4
    Medium

    CVE-2007-0629

    Last Modified: 23 Apr 2026

    The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attackers to delete unauthorized assets. NOTE: some of these details are obtained from third party information.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0630

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) from, and (3) q parameters, different vectors than CVE-2007-0569. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0631

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0632

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitrary SQL commands via a username cookie, a different vector than CVE-2007-0560.

    Published: 31 Jan 2007
    5
    Medium

    CVE-2007-0624

    Last Modified: 23 Apr 2026

    user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly other invalid values, in the uname parameter in a userinfo operation.

    Published: 31 Jan 2007
    7.5
    High

    CVE-2007-0623

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.

    Published: 31 Jan 2007
    5
    Medium

    CVE-2007-0622

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Jan 2007
    Unknown

    CVE-2007-0621

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-6456. Reason: This candidate is a duplicate of CVE-2006-6456. It was assigned for a targeted zero-day attack, but further analysis revealed it was for an older issue. Notes: All CVE users should reference CVE-2006-6456 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Jan 2007
    6.8
    Medium

    CVE-2007-0617

    Last Modified: 23 Apr 2026

    The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked "safe for scripting," which allows remote attackers to add arbitrary e-mail addresses and domains to the spam blocker whitelist via the (1) AddSenderToWhitelist and (2) AddDomainToWhitelist functions.

    Published: 31 Jan 2007
    7.8
    High

    CVE-2007-0616

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories via ".." sequences in the album parameter to index.php.

    Published: 31 Jan 2007
    7.8
    High

    CVE-2007-0612

    Last Modified: 23 Apr 2026

    Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.

    Published: 31 Jan 2007
    9.3
    Critical

    CVE-2007-0619

    Last Modified: 23 Apr 2026

    chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a CHM file, which triggers memory corruption.

    Published: 31 Jan 2007
    5
    Medium

    CVE-2007-0620

    Last Modified: 23 Apr 2026

    download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.

    Published: 31 Jan 2007