CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2007-0314

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_DIR parameter to (1) forms.php, (2) issue_edit.php, (3) client.php, and (4) classes.php.

    Published: 18 Jan 2007
    7.8
    High

    CVE-2007-0318

    Last Modified: 23 Apr 2026

    The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0308

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0316

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0300

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Published: 18 Jan 2007
    6.8
    Medium

    CVE-2007-0301

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0306

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Jan 2007
    5
    Medium

    CVE-2007-0310

    Last Modified: 23 Apr 2026

    BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.

    Published: 18 Jan 2007
    5
    Medium

    CVE-2007-0311

    Last Modified: 23 Apr 2026

    Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.

    Published: 18 Jan 2007
    9.3
    Critical

    CVE-2007-0315

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp). NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0317

    Last Modified: 23 Apr 2026

    Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments. NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0307

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the env[rootPath] parameter.

    Published: 18 Jan 2007
    7.5
    High

    CVE-2007-0309

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blocks/block-Old_Articles.php in Francisco Burzi PHP-Nuke 7.9 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 18 Jan 2007
    10
    Critical

    CVE-2006-6940

    Last Modified: 23 Apr 2026

    Buffer overflow in the ParseHeader function in clsOWA.cls in POP3/SMTP to OWA (pop2owa) 1.1.3 allows remote attackers to execute arbitrary code via a long header in an e-mail message.

    Published: 17 Jan 2007
    7.1
    High

    CVE-2007-0299

    Last Modified: 23 Apr 2026

    Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer dereference.

    Published: 17 Jan 2007
    6.8
    Medium

    CVE-2007-0298

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PollDir parameter.

    Published: 17 Jan 2007
    8.5
    High

    CVE-2007-0272

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via unspecified vectors involving certain public procedures, aka DB05.

    Published: 17 Jan 2007
    4.3
    Medium

    CVE-2007-0273

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to XMLDB, aka DB06. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that DB06 is for multiple cross-site scripting (XSS) vulnerabilities.

    Published: 17 Jan 2007
    7.5
    High

    CVE-2007-0279

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07.

    Published: 17 Jan 2007
    6.4
    Medium

    CVE-2007-0284

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.

    Published: 17 Jan 2007
    5
    Medium

    CVE-2007-0285

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.

    Published: 17 Jan 2007
    2.6
    Low

    CVE-2007-0286

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.

    Published: 17 Jan 2007
    1.7
    Low

    CVE-2007-0288

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.

    Published: 17 Jan 2007
    6.4
    Medium

    CVE-2007-0293

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console. NOTE: EM05 might be related to CVE-2007-0222.

    Published: 17 Jan 2007
    7.8
    High

    CVE-2007-0295

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13 and 8.47.11 has unknown impact and attack vectors in PeopleTools, aka PSE01.

    Published: 17 Jan 2007
    4
    Medium

    CVE-2007-0297

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03.

    Published: 17 Jan 2007
    7.5
    High

    CVE-2007-0280

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).

    Published: 17 Jan 2007
    6.5
    Medium

    CVE-2007-0270

    Last Modified: 23 Apr 2026

    Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via the GET_PROPERTY function in SYS.DBMS_DRS, aka DB03.

    Published: 17 Jan 2007
    6.5
    Medium

    CVE-2007-0274

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.2.0.7 and 10.1.0.5 have unknown impact and attack vectors related to (1) Export and sys.dbms_logrep_util (DB08), and (2) Oracle Streams and sys.dbms_capture_adm_internal privileges (DB09). NOTE: Oracle has not disputed reliable researcher claims that DB08 is for a buffer overflow in the GET_OBJECT_NAME procedure in the DBMS_LOGREP_UTIL package, and DB09 is for buffer overflows in the CREATE_CAPTURE, ALTER_CAPTURE, and ABORT_TABLE_INSTANTIATION procedures in SYS.DBMS_CAPTURE_ADM_INTERNAL.

    Published: 17 Jan 2007
    3.5
    Low

    CVE-2007-0275

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.

    Published: 17 Jan 2007
    6.8
    Medium

    CVE-2007-0276

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4 and 9.0.1.5 have unknown impact and attack vectors related to (1) Advanced Security Option and oklist or okdstry (DB10), (2) Oracle Net Services (DB13), and (3) Recovery Manager and oklist (DB16).

    Published: 17 Jan 2007
    6.8
    Medium

    CVE-2007-0277

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Database client-only 10.1.0.4 has unknown impact and attack vectors related to the Export component and expdp or impdp, aka DB11.

    Published: 17 Jan 2007
    6.8
    Medium

    CVE-2007-0278

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) NLS Runtime and lmsgen (DB12), and (2) Oracle Text and ctxkbtc (DB14).

    Published: 17 Jan 2007
    3.2
    Low

    CVE-2007-0282

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN02.

    Published: 17 Jan 2007
    4
    Medium

    CVE-2007-0283

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.

    Published: 17 Jan 2007
    1.7
    Low

    CVE-2007-0287

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.

    Published: 17 Jan 2007
    4
    Medium

    CVE-2007-0291

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle E-Business Suite and Applications 6.2.3 has unknown impact and attack vectors related to Oracle Exchange, aka APPS02.

    Published: 17 Jan 2007
    7.5
    High

    CVE-2007-0292

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02. NOTE: EM05 might be related to CVE-2007-0222.

    Published: 17 Jan 2007
    1.7
    Low

    CVE-2007-0294

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06.

    Published: 17 Jan 2007
    2.1
    Low

    CVE-2007-0296

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.

    Published: 17 Jan 2007
    6.5
    Medium

    CVE-2007-0268

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unknown impact and attack vectors related to (1) the Advanced Queuing component and sys.dbms_aqsys.dbms_aq privileges (DB01), (2) Advanced Replication and sys.dbms_repcat_untrusted (DB07), and (3) Oracle Text and ctxload (DB15). NOTE: Oracle has not publicly claims by reliable researchers that DB01 is for SQL injection in the SYS.DBMS_AQ_INV package, and DB07 is for a buffer overflow in the UNREGISTER_SNAPSHOT procedure in the DBMS_REPCAT_UNTRUSTED package.

    Published: 17 Jan 2007
    5.5
    Medium

    CVE-2007-0269

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and attack vectors related to the Change Data Capture and sys.dbms_cdc_subscribe privileges, aka DB02.

    Published: 17 Jan 2007
    6.5
    Medium

    CVE-2007-0271

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors related to the Log Miner component and sys.dbms_log_mnr privileges, aka DB04. NOTE: Oracle has not disputed a reliable researcher claim that this is a buffer overflow in the ADD_LOGFILE procedure for the SYS.DBMS_LOGMNR package that allows code execution.

    Published: 17 Jan 2007
    5
    Medium

    CVE-2007-0281

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.

    Published: 17 Jan 2007
    6.4
    Medium

    CVE-2007-0289

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.

    Published: 17 Jan 2007
    5.5
    Medium

    CVE-2007-0290

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors related to (1) Application Object Library (APPS01), (2) Human Resources (APPS03), (3) Payables (APPS04), (4) Trading Community Architecture (APPS05), and (5) Web Applications Desktop Integrator (APPS06).

    Published: 17 Jan 2007
    5
    Medium

    CVE-2007-0222

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the EmChartBean server side component for Oracle Application Server 10g allows remote attackers to read arbitrary files via unknown vectors, probably "\.." sequences in the beanId parameter. NOTE: this is likely a duplicate of another CVE that Oracle addressed in CPU Jan 2007, but due to lack of details by Oracle, it is unclear which BugID this issue is associated with, so the other CVE cannot be determined. Possibilities include EM02 (CVE-2007-0292) or EM05 (CVE-2007-0293).

    Published: 17 Jan 2007
    7.5
    High

    CVE-2006-6937

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.

    Published: 17 Jan 2007
    5
    Medium

    CVE-2006-6938

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote attackers to include arbitrary files via ".." sequences in the root parameter.

    Published: 17 Jan 2007
    4.6
    Medium

    CVE-2006-6939

    Last Modified: 23 Apr 2026

    GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files, possibly in the open_sbuf function.

    Published: 17 Jan 2007