CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-0487

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used

    Published: 25 Jan 2007
    7.5
    High

    CVE-2007-0492

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jan 2007
    7.2
    High

    CVE-2006-6952

    Last Modified: 23 Apr 2026

    Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.

    Published: 24 Jan 2007
    7.2
    High

    CVE-2007-0444

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.

    Published: 24 Jan 2007
    9.3
    Critical

    CVE-2007-0018

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice; (2) Magic Audio Recorder, Music Editor, and Audio Converter; (3) Aurora Media Workshop; DB Audio Mixer And Editor; (4) J. Hepple Products including Fx Audio Editor and others; (5) EXPStudio Audio Editor; (6) iMesh; (7) Quikscribe; (8) RMBSoft AudioConvert and SoundEdit Pro 2.1; (9) CDBurnerXP; (10) Code-it Software Wave MP3 Editor and aBasic Editor; (11) Movavi VideoMessage, DVD to iPod, and others; (12) SoftDiv Software Dexster, iVideoMAX, and others; (13) Sienzo Digital Music Mentor (DMM); (14) MP3 Normalizer; (15) Roemer Software FREE and Easy Hi-Q Recorder, and Easy Hi-Q Converter; (16) Audio Edit Magic; (17) Joshua Video and Audio Converter; (18) Virtual CD; (19) Cheetah CD and DVD Burner; (20) Mystik Media AudioEdit Deluxe, Blaze Media, and others; (21) Power Audio Editor; (22) DanDans Digital Media Full Audio Converter, Music Editing Master, and others; (23) Xrlly Software Text to Speech Makerand Arial Sound Recorder / Audio Converter; (24) Absolute Sound Recorder, Video to Audio Converter, and MP3 Splitter; (25) Easy Ringtone Maker; (26) RecordNRip; (27) McFunSoft iPod Audio Studio, Audio Recorder for Free, and others; (28) MP3 WAV Converter; (29) BearShare 6.0.2.26789; and (30) Oracle Siebel SimBuilder and CRM 7.x.

    Published: 24 Jan 2007
    9.3
    Critical

    CVE-2007-0020

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.

    Published: 24 Jan 2007
    6.9
    Medium

    CVE-2007-0023

    Last Modified: 23 Apr 2026

    The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.

    Published: 24 Jan 2007
    10
    Critical

    CVE-2007-0460

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."

    Published: 24 Jan 2007
    5
    Medium

    CVE-2007-0461

    Last Modified: 23 Apr 2026

    Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.

    Published: 24 Jan 2007
    6.8
    Medium

    CVE-2007-0468

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.

    Published: 24 Jan 2007
    7.2
    High

    CVE-2007-0470

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.

    Published: 24 Jan 2007
    7.5
    High

    CVE-2007-0471

    Last Modified: 23 Apr 2026

    sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.

    Published: 24 Jan 2007
    9.3
    Critical

    CVE-2007-0469

    Last Modified: 23 Apr 2026

    The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.

    Published: 24 Jan 2007
    2.6
    Low

    CVE-2007-0537

    Last Modified: 23 Apr 2026

    The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.

    Published: 24 Jan 2007
    7.2
    High

    CVE-2007-0003

    Last Modified: 23 Apr 2026

    pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent attackers to log into accounts whose password hash, as stored in /etc/passwd or /etc/shadow, has only two characters.

    Published: 23 Jan 2007
    10
    Critical

    CVE-2007-0449

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1 SP1, Mobile Backup r4.0, Desktop and Business Protection Suite r2, and Desktop Management Suite (DMS) r11.0 and r11.1 allow remote attackers to execute arbitrary code via crafted packets to TCP port (1) 1900 or (2) 2200.

    Published: 23 Jan 2007
    5.1
    Medium

    CVE-2007-0441

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, and 7.50 allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0442

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM OS/400 R530 and R535 has unknown impact and remote attack vectors, related to an "Integrity Problem" involving LIC-TCPIP and TCP reset. NOTE: it is possible that this issue is related to CVE-2004-0230, but this is not certain.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2006-6946

    Last Modified: 23 Apr 2026

    The web server in the NEC MultiWriter 1700C allows remote attackers to modify the device configuration via unspecified vectors.

    Published: 23 Jan 2007
    7.8
    High

    CVE-2006-6947

    Last Modified: 23 Apr 2026

    The FTP server in the NEC MultiWriter 1700C allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command, a variant of CVE-1999-0017.

    Published: 23 Jan 2007
    7.8
    High

    CVE-2006-6948

    Last Modified: 23 Apr 2026

    MyODBC Japanese conversion edition 3.51.06, 2.50.29, and 2.50.25 allows remote attackers to cause a denial of service via a certain string in a response, which has unspecified impact on the MySQL database.

    Published: 23 Jan 2007
    4.6
    Medium

    CVE-2006-6949

    Last Modified: 23 Apr 2026

    Conti FTPServer 1.0 Build 2.8 stores user passwords in cleartext in MyServerSettings.ini, which allows local users to obtain sensitive information by reading this file.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2006-6950

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Conti FTPServer 1.0 Build 2.8 allows remote attackers to read arbitrary files and list arbitrary directories via a .. (dot dot) in a filename argument.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0428

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to cause a denial of service via a crafted FTP command, probably due to a NULL pointer dereference.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0429

    Last Modified: 23 Apr 2026

    DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the GoWindowed method for a certain instance of the ActiveX object.

    Published: 23 Jan 2007
    4.9
    Medium

    CVE-2007-0430

    Last Modified: 23 Apr 2026

    The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.

    Published: 23 Jan 2007
    4.6
    Medium

    CVE-2007-0434

    Last Modified: 23 Apr 2026

    BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2007-0435

    Last Modified: 23 Apr 2026

    T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the device via a LOGINKEY=TECOM cookie value.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2007-0432

    Last Modified: 23 Apr 2026

    BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities.

    Published: 23 Jan 2007
    6.5
    Medium

    CVE-2007-0433

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled.

    Published: 23 Jan 2007
    6.8
    Medium

    CVE-2006-6951

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in blog.php in OdysseusBlog allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 23 Jan 2007
    7.8
    High

    CVE-2007-0431

    Last Modified: 23 Apr 2026

    AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP application crash) via a zero-length UDP packet to the SIP port (port 5060).

    Published: 23 Jan 2007
    4.9
    Medium

    CVE-2006-5754

    Last Modified: 23 Apr 2026

    The aio_setup_ring function in Linux kernel does not properly initialize a variable, which allows local users to cause a denial of service (crash) via an unspecified error path that causes an incorrect free operation.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2007-0021

    Last Modified: 23 Apr 2026

    Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.

    Published: 23 Jan 2007
    7.2
    High

    CVE-2007-0022

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to a malicious launchctl program.

    Published: 23 Jan 2007
    1.5
    Low

    CVE-2007-0409

    Last Modified: 23 Apr 2026

    BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0410

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1, when T3 authentication is used, allows remote attackers to cause a denial of service (thread and system hang) via unspecified "sequences of events."

    Published: 23 Jan 2007
    6.8
    Medium

    CVE-2007-0411

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate certificates, which allows remote attackers to conduct a man-in-the-middle (MITM) attack.

    Published: 23 Jan 2007
    4.4
    Medium

    CVE-2007-0413

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which allows local users to obtain sensitive information by reading this backup file.

    Published: 23 Jan 2007
    10
    Critical

    CVE-2007-0417

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibility realm, allows attackers to execute certain EJB container persistence operations with an administrative identity.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2007-0418

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that declares permissions for EJB methods that have array parameters, which allows remote attackers to obtain unauthorized access to these methods.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0419

    Last Modified: 23 Apr 2026

    The BEA WebLogic Server proxy plug-in before June 2006 for the Apache HTTP Server does not properly handle protocol errors, which allows remote attackers to cause a denial of service (server outage).

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0420

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 9.0, 9.1, and 9.2 Gold allows remote attackers to obtain sensitive information via malformed HTTP requests, which reveal data from previous requests.

    Published: 23 Jan 2007
    6.4
    Medium

    CVE-2007-0421

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 6.1 through 6.1 SP7, and 7.0 through 7.0 SP7 allows remote attackers to cause a denial of service (disk consumption) via requests containing malformed headers, which cause a large amount of data to be written to the server log.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0422

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2007-0416

    Last Modified: 23 Apr 2026

    The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting client messages, which allows remote attackers to bypass application security.

    Published: 23 Jan 2007
    9.3
    Critical

    CVE-2007-0427

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.

    Published: 23 Jan 2007
    5
    Medium

    CVE-2007-0412

    Last Modified: 23 Apr 2026

    BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read arbitrary files inside the class-path property via .ear or exploded .ear files that use the manifest class-path property to point to utility jar files.

    Published: 23 Jan 2007
    7.5
    High

    CVE-2007-0425

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BEA WebLogic Platform and Server 8.1 through 8.1 SP5, and JRockit 1.4.2 R4.5 and earlier, allows attackers to gain privileges via unspecified vectors, related to an "overflow condition," probably a buffer overflow.

    Published: 23 Jan 2007
    7.1
    High

    CVE-2010-1188

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.

    Published: 23 Jan 2007