CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2007-0125

    Last Modified: 23 Apr 2026

    Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning a crafted PE file.

    Published: 9 Jan 2007
    9.3
    Critical

    CVE-2007-0126

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an invalid number of index bytes in the Define Huffman Table (DHT) marker.

    Published: 9 Jan 2007
    9.3
    Critical

    CVE-2007-0127

    Last Modified: 23 Apr 2026

    The Javascript SVG support in Opera before 9.10 does not properly validate object types in a createSVGTransformFromMatrix request, which allows remote attackers to execute arbitrary code via JavaScript code that uses an invalid object in this request that causes a controlled pointer to be referenced during the virtual function call.

    Published: 9 Jan 2007
    7.5
    High

    CVE-2007-0116

    Last Modified: 23 Apr 2026

    Digger Solutions Intranet Open Source (IOS) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for data/intranet.mdb.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0119

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script or HTML via the plain parameter to (1) mkpw_mp.cgi, (2) mkpw.pl, or (3) mkpw.cgi.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0123

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.

    Published: 9 Jan 2007
    6
    Medium

    CVE-2007-0115

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.

    Published: 9 Jan 2007
    10
    Critical

    CVE-2007-0117

    Last Modified: 23 Apr 2026

    DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon execution of a diskutil permission repair operation.

    Published: 9 Jan 2007
    4.3
    Medium

    CVE-2007-0118

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an absolute pathname in the file parameter to (1) edittag.cgi, (2) edittag.pl, (3) edittag_mp.cgi, or (4) edittag_mp.pl.

    Published: 9 Jan 2007
    3.5
    Low

    CVE-2007-0124

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Drupal before 4.6.11, and 4.7 before 4.7.5, when MySQL is used, allows remote authenticated users to cause a denial of service by poisoning the page cache via unspecified vectors, which triggers erroneous 404 HTTP errors for pages that exist.

    Published: 9 Jan 2007
    6.5
    Medium

    CVE-2007-0122

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0110

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 allows remote attackers to inject arbitrary web script or HTML via the IssueInstant parameter, which is not properly handled in the resulting error message.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0102

    Last Modified: 23 Apr 2026

    The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0103

    Last Modified: 23 Apr 2026

    The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

    Published: 9 Jan 2007
    7.5
    High

    CVE-2007-0105

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.

    Published: 9 Jan 2007
    5
    Medium

    CVE-2007-0109

    Last Modified: 23 Apr 2026

    wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

    Published: 9 Jan 2007
    7.5
    High

    CVE-2007-0112

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0107

    Last Modified: 23 Apr 2026

    WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charsets, as demonstrated using UTF-7.

    Published: 9 Jan 2007
    5
    Medium

    CVE-2007-0114

    Last Modified: 23 Apr 2026

    Sun Java System Content Delivery Server 5.0 and 5.0 PU1 allows remote attackers to obtain sensitive information regarding "content details" via unspecified vectors.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0104

    Last Modified: 23 Apr 2026

    The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0106

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the CSRF protection scheme in WordPress before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via a CSRF attack with an invalid token and quote characters or HTML tags in URL variable names, which are not properly handled when WordPress generates a new link to verify the request.

    Published: 9 Jan 2007
    6
    Medium

    CVE-2007-0108

    Last Modified: 23 Apr 2026

    nwgina.dll in Novell Client 4.91 SP3 for Windows 2000/XP/2003 does not delete user profiles during a Terminal Service or Citrix session, which allows remote authenticated users to invoke alternate user profiles.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0111

    Last Modified: 23 Apr 2026

    Buffer overflow in Resco Photo Viewer for PocketPC 4.11 and 6.01, as used in mobile devices running Windows Mobile 5.0, 2003, and 2003SE, allows remote attackers to execute arbitrary code via a crafted PNG image.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-0113

    Last Modified: 23 Apr 2026

    Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service (reset or reboot) via (1) a long traffic class argument to the "class show" command or (2) a long POLICY parameter value in clastree.htm.

    Published: 9 Jan 2007
    6.8
    Medium

    CVE-2007-2348

    Last Modified: 23 Apr 2026

    mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which could overwrite executable files.

    Published: 9 Jan 2007
    10
    Critical

    CVE-2007-0100

    Last Modified: 23 Apr 2026

    The Perforce client does not restrict the set of files that it overwrites upon receiving a request from the server, which allows remote attackers to overwrite arbitrary files by modifying the client config file on the server, or by operating a malicious server.

    Published: 8 Jan 2007
    9.3
    Critical

    CVE-2007-0099

    Last Modified: 23 Apr 2026

    Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via many nested tags in an XML document in an IFRAME, when synchronous document rendering is frequently disrupted with asynchronous events, as demonstrated using a JavaScript timer, which can trigger NULL pointer dereferences or memory corruption, aka "MSXML Memory Corruption Vulnerability."

    Published: 8 Jan 2007
    6.8
    Medium

    CVE-2007-0101

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in SPINE allows remote attackers to perform unauthorized actions as administrators via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 8 Jan 2007
    7.8
    High

    CVE-2007-0087

    Last Modified: 23 Apr 2026

    Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal

    Published: 5 Jan 2007
    5
    Medium

    CVE-2007-0088

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in openmedia allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) src parameter to page.php or the (2) format parameter to search_form.php.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0089

    Last Modified: 23 Apr 2026

    jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0090

    Last Modified: 23 Apr 2026

    WineGlass stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/data.mdb.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0096

    Last Modified: 23 Apr 2026

    CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb.

    Published: 5 Jan 2007
    6.8
    Medium

    CVE-2007-0098

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.

    Published: 5 Jan 2007
    5
    Medium

    CVE-2007-0095

    Last Modified: 23 Apr 2026

    phpMyAdmin 2.9.1.1 allows remote attackers to obtain sensitive information via a direct request for themes/darkblue_orange/layout.inc.php, which reveals the path in an error message.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0092

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL commands via the product_id parameter.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0094

    Last Modified: 23 Apr 2026

    Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.

    Published: 5 Jan 2007
    7.8
    High

    CVE-2007-0086

    Last Modified: 23 Apr 2026

    The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who state that the large window size required by the attack is not normally supported or configured by the server, or that a DDoS-style attack would accomplish the same goal

    Published: 5 Jan 2007
    9.3
    Critical

    CVE-2007-0097

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the (1) LoadTree and (2) ReadHeader functions in PAISO.DLL 1.7.3.0 (1.7.3 beta) in ConeXware PowerArchiver 2006 9.64.02 allow user-assisted attackers to execute arbitrary code via a crafted ISO file containing a file within several nested directories.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0091

    Last Modified: 23 Apr 2026

    newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for newsCMS.mdb.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Jan 2007
    6.6
    Medium

    CVE-2007-0080

    Last Modified: 23 Apr 2026

    Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute

    Published: 5 Jan 2007
    6.8
    Medium

    CVE-2007-0081

    Last Modified: 23 Apr 2026

    Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.

    Published: 5 Jan 2007
    6.5
    Medium

    CVE-2007-0082

    Last Modified: 23 Apr 2026

    users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows remote authenticated users to upload and execute arbitrary PHP scripts.

    Published: 5 Jan 2007
    7.5
    High

    CVE-2007-0076

    Last Modified: 23 Apr 2026

    Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb.

    Published: 5 Jan 2007
    5
    Medium

    CVE-2007-0077

    Last Modified: 23 Apr 2026

    lblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a certain file in admin/db/newFolder/.

    Published: 5 Jan 2007
    6.6
    Medium

    CVE-2007-0084

    Last Modified: 23 Apr 2026

    Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename. NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed

    Published: 5 Jan 2007
    5
    Medium

    CVE-2007-0078

    Last Modified: 23 Apr 2026

    BattleBlog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/blankmaster.mdb.

    Published: 5 Jan 2007
    7.8
    High

    CVE-2007-0079

    Last Modified: 23 Apr 2026

    rblog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/admin.mdb or (2) data/rblog.mdb.

    Published: 5 Jan 2007
    6.8
    Medium

    CVE-2007-0083

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nuked Klan 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in a getURL statement in a .swf file, as demonstrated by "Remote Cookie Disclosure." NOTE: it could be argued that this is an issue in Shockwave instead of Nuked Klan.

    Published: 5 Jan 2007