CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-0532

    Last Modified: 23 Apr 2026

    Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.

    Published: 26 Jan 2007
    5
    Medium

    CVE-2007-0533

    Last Modified: 23 Apr 2026

    The AToZed IntraWeb component 8.0 and earlier for Borland Delphi and Kylix, and IntraWeb 9.0 before build (9.0.12), allows remote attackers to cause a denial of service (thread hang or CPU consumption) via a crafted HTTP request, related to the OnBeforeDispatch function in the TIWServerController object.

    Published: 26 Jan 2007
    4.3
    Medium

    CVE-2007-0534

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain "fields on project nodes" or (b) "certain project-specific settings regarding issue tracking."

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0530

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804. NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use

    Published: 26 Jan 2007
    9
    Critical

    CVE-2007-0528

    Last Modified: 23 Apr 2026

    The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and earlier, as provided by various IP phones, does not require passwords or authentication tokens when using HTTP, which allows remote attackers to connect to existing superuser sessions and obtain sensitive information (passwords and configuration data).

    Published: 26 Jan 2007
    4.9
    Medium

    CVE-2007-0516

    Last Modified: 23 Apr 2026

    Yana Framework before 2.8.5a allows remote authenticated users with permissions to modify a guestbook profile to modify or delete arbitrary guestbook profiles via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jan 2007
    6.8
    Medium

    CVE-2007-0527

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information.

    Published: 26 Jan 2007
    4.3
    Medium

    CVE-2007-0529

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.html (aka the administration page) in PHP Link Directory (phpLD) 3.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted link, which is triggered when the administrator uses the "Validate Links" functionality.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0535

    Last Modified: 23 Apr 2026

    Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jan 2007
    3.3
    Low

    CVE-2007-0521

    Last Modified: 23 Apr 2026

    The Sony Ericsson K700i and W810i phones allow remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.

    Published: 26 Jan 2007
    10
    Critical

    CVE-2007-0510

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) preserve.c in AWFFull 3.7.1 and earlier have unknown impact and attack vectors. NOTE: some of these details are obtained from third party information. NOTE: There may not be any attack vector that crosses privilege boundaries.

    Published: 26 Jan 2007
    6.8
    Medium

    CVE-2007-0511

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) dom.php, (2) dtd.php, or (3) parser.php in include/.

    Published: 26 Jan 2007
    10
    Critical

    CVE-2007-0504

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0508

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitrary PHP code via a URL in the BBC_LANGUAGE_PATH parameter.

    Published: 26 Jan 2007
    2.1
    Low

    CVE-2007-0958

    Last Modified: 23 Apr 2026

    Linux kernel 2.6.x before 2.6.20 allows local users to read unreadable binaries by using the interpreter (PT_INTERP) functionality and triggering a core dump, a variant of CVE-2004-1073.

    Published: 26 Jan 2007
    7.5
    High

    CVE-2007-0455

    Last Modified: 23 Apr 2026

    Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.

    Published: 26 Jan 2007
    8.5
    High

    CVE-2007-0505

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a file with executable or multiple extensions to a project issue.

    Published: 26 Jan 2007
    6
    Medium

    CVE-2007-0506

    Last Modified: 23 Apr 2026

    The project_issue_access function in the Project issue tracking 4.7.0 through 5.x before 20070123 module for Drupal allows remote authenticated users to bypass other access control modules and obtain attached files by guessing the filename, and obtain issue information via direct requests.

    Published: 26 Jan 2007
    9.3
    Critical

    CVE-2007-0509

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages.

    Published: 26 Jan 2007
    5
    Medium

    CVE-2007-0512

    Last Modified: 23 Apr 2026

    Hitachi TP1/LiNK 05-00 through 05-03-/F, 03-04 through 03-06-/K, and 03-00 through 03-03-/H; and TP1/Server Base 05-00 through 05-00-/M, 03-01-E through 03-01-FD, 03-01 through 03-01-DB, and 05-03; allow attackers to cause a denial of service (process crash) via invalid data to an OpenTP1 port.

    Published: 26 Jan 2007
    5
    Medium

    CVE-2007-0513

    Last Modified: 23 Apr 2026

    Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64); and various products that bundle HiRDB Datareplicator; allows attackers to cause a denial of service (CPU consumption) via certain data.

    Published: 26 Jan 2007
    6.8
    Medium

    CVE-2007-0514

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.

    Published: 26 Jan 2007
    9.3
    Critical

    CVE-2007-0515

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.

    Published: 26 Jan 2007
    6
    Medium

    CVE-2007-0507

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Acidfree module for Drupal before 4.6.x-1.0, and before 4.7.x-1.0 in the 4.7 series, allows remote authenticated users with "create acidfree albums" privileges to execute arbitrary SQL commands via node titles.

    Published: 26 Jan 2007
    10
    Critical

    CVE-2007-0495

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0497

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0498

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in up.php in MySpeach 2.1 beta and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the my[root] parameter.

    Published: 25 Jan 2007
    10
    Critical

    CVE-2007-0496

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter.

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0502

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.

    Published: 25 Jan 2007
    6.9
    Medium

    CVE-2007-0503

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0501

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Generators (adv-random-gen) allows remote attackers to execute arbitrary PHP code via a URL in the gen parameter.

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0500

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0499

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in Sangwan Kim phpIndexPage 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[inc_path] parameter.

    Published: 25 Jan 2007
    4.6
    Medium

    CVE-2007-0476

    Last Modified: 23 Apr 2026

    The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.

    Published: 25 Jan 2007
    4.3
    Medium

    CVE-2007-0478

    Last Modified: 23 Apr 2026

    WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.

    Published: 25 Jan 2007
    4.6
    Medium

    CVE-2007-0482

    Last Modified: 23 Apr 2026

    cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified local attack.

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0484

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other files. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0485

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter.

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0486

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Openads (aka phpAdsNew) 2.0.7 allow remote attackers to execute arbitrary PHP code via a URL in the (1) phpAds_geoPlugin parameter to libraries/lib-remotehost.inc, the (2) filename parameter to admin/report-index, or the (3) phpAds_config[my_footer] parameter to admin/lib-gui.inc. NOTE: the vendor has disputed this issue, stating that the relevant variables are used within function definitions

    Published: 25 Jan 2007
    5
    Medium

    CVE-2007-0490

    Last Modified: 23 Apr 2026

    index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0491

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in up.php in Sky GUNNING MySpeach 3.0.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter, a different vector than CVE-2006-4630. NOTE: Some of these details are obtained from third party information.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0489

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 25 Jan 2007
    4.3
    Medium

    CVE-2007-0494

    Last Modified: 23 Apr 2026

    ISC BIND 9.0.x, 9.1.x, 9.2.0 up to 9.2.7, 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (exit) via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0477

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Openads 2.0.x before 2.0.10, 2.3 before 2.3.31 (aka Max Media Manager before 0.3.31-alpha-pr2), and phpAdsNew/phpPgAds before 2.0.9-pr1 allows remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in admin-search.php and (2) affiliate-search.php. NOTE: this issue may overlap CVE-2007-0363.

    Published: 25 Jan 2007
    10
    Critical

    CVE-2007-0480

    Last Modified: 23 Apr 2026

    Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.

    Published: 25 Jan 2007
    7.8
    High

    CVE-2007-0481

    Last Modified: 23 Apr 2026

    Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.

    Published: 25 Jan 2007
    6.8
    Medium

    CVE-2007-0483

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jan 2007
    5
    Medium

    CVE-2007-0488

    Last Modified: 23 Apr 2026

    The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command.

    Published: 25 Jan 2007
    7.8
    High

    CVE-2007-0493

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."

    Published: 25 Jan 2007
    7.8
    High

    CVE-2007-0479

    Last Modified: 23 Apr 2026

    Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.

    Published: 25 Jan 2007