CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-0618

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact and attack vectors, involving an "authentication vulnerability."

    Published: 31 Jan 2007
    7.8
    High

    CVE-2007-0614

    Last Modified: 23 Apr 2026

    The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

    Published: 31 Jan 2007
    5
    Medium

    CVE-2007-0613

    Last Modified: 23 Apr 2026

    The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.

    Published: 31 Jan 2007
    7.8
    High

    CVE-2007-0615

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi JP1/HIBUN Advanced Edition Management Server and Log Server before 20070124 allows remote attackers to cause a denial of service (application stop) via unexpected data.

    Published: 31 Jan 2007
    6.2
    Medium

    CVE-2007-0467

    Last Modified: 23 Apr 2026

    crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.

    Published: 31 Jan 2007
    10
    Critical

    CVE-2007-0466

    Last Modified: 23 Apr 2026

    Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption.

    Published: 31 Jan 2007
    6.8
    Medium

    CVE-2007-0610

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the mailform feature in CMSimple 2.7 fix1 allows remote attackers to inject arbitrary web script or HTML via the sender parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Jan 2007
    6.8
    Medium

    CVE-2007-0611

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) inc.page.php and (2) inc.text.php.

    Published: 31 Jan 2007
    7.6
    High

    CVE-2007-0465

    Last Modified: 23 Apr 2026

    Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.

    Published: 31 Jan 2007
    6.9
    Medium

    CVE-2007-0602

    Last Modified: 23 Apr 2026

    Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan, allows local users to gain privileges via a long command line argument, a different vulnerability than CVE-2005-0533.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0599

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET, (3) COOKIE, and (4) SERVER superglobal arrays.

    Published: 30 Jan 2007
    5
    Medium

    CVE-2007-0594

    Last Modified: 23 Apr 2026

    Siteman 2.0.x2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for db/siteman/users.MYD.

    Published: 30 Jan 2007
    6.8
    Medium

    CVE-2007-0604

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Movable Type (MT) before 3.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the MTCommentPreviewIsStatic tag, which can open the "comment entry screen," a different vulnerability than CVE-2007-0231.

    Published: 30 Jan 2007
    7.1
    High

    CVE-2007-0603

    Last Modified: 23 Apr 2026

    PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0601

    Last Modified: 23 Apr 2026

    common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays.

    Published: 30 Jan 2007
    5
    Medium

    CVE-2007-0593

    Last Modified: 23 Apr 2026

    Siteman 1.1.11 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing password hashes via a direct request for data/members.txt.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0591

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0589

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0600

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and earlier allows remote attackers to execute arbitrary SQL commands via the uid parameter.

    Published: 30 Jan 2007
    4.3
    Medium

    CVE-2007-0595

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search in High 5 Review Site allows remote attackers to inject arbitrary web script or HTML via the q parameter (aka the search box).

    Published: 30 Jan 2007
    5
    Medium

    CVE-2007-0597

    Last Modified: 23 Apr 2026

    Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0598

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php.

    Published: 30 Jan 2007
    6
    Medium

    CVE-2007-0596

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter.

    Published: 30 Jan 2007
    7.1
    High

    CVE-2007-0588

    Last Modified: 23 Apr 2026

    The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.

    Published: 30 Jan 2007
    6.8
    Medium

    CVE-2007-0592

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in EzDatabase 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to admin/login.php and the Admin Panel Database.

    Published: 30 Jan 2007
    5.8
    Medium

    CVE-2007-0590

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter.

    Published: 30 Jan 2007
    9.3
    Critical

    CVE-2007-0585

    Last Modified: 23 Apr 2026

    include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. NOTE: some of these details are obtained from third party information. It is likely that this issue can be exploited to conduct directory traversal attacks.

    Published: 30 Jan 2007
    6.8
    Medium

    CVE-2007-0567

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0573

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racineTBS parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0575

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow remote attackers to execute arbitrary SQL commands via the (1) Userid and (2) Password fields.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0576

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0577

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0571

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/lib/lib_head.php in phpMyReports 3.0.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathModule parameter.

    Published: 30 Jan 2007
    5.1
    Medium

    CVE-2007-0579

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the calendar component in Horde Groupware Webmail Edition before 1.0, and Groupware before 1.0, allows remote attackers to include certain files via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 30 Jan 2007
    6.8
    Medium

    CVE-2007-0580

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP code via a URL in the sesion_idioma parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0581

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands via the User (username) field.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0584

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neric) allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0569

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a shownews action.

    Published: 30 Jan 2007
    5
    Medium

    CVE-2007-0464

    Last Modified: 23 Apr 2026

    The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0572

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Published: 30 Jan 2007
    4.3
    Medium

    CVE-2007-0578

    Last Modified: 23 Apr 2026

    The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0568

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0570

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News Script (AINS) 0.02b allows remote attackers to execute arbitrary PHP code via a URL in the ains_path parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0574

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jan 2007
    4.3
    Medium

    CVE-2007-0583

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in HTTP Commander 6.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) LogoffMessage parameter to logofflast.aspx or the (2) txtUsername parameter to Default.aspx. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0558

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR parameter.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0559

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the sql_language parameter.

    Published: 30 Jan 2007
    4
    Medium

    CVE-2007-0564

    Last Modified: 23 Apr 2026

    The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.

    Published: 30 Jan 2007
    7.5
    High

    CVE-2007-0566

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Jan 2007