5
    Medium

    CVE-2008-0068

    Last Modified: 13 Feb 2014

    Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.

    Source:Luigi Auriemma
    Published:16 Apr 2008
    10
    Critical

    CVE-2008-0067

    Last Modified: 6 Mar 2011

    Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program.

    Source:Metasploit
    Published:8 Jan 2009
    10
    Critical

    CVE-2008-0065

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.

    Source:Metasploit
    Published:22 Jan 2008
    6.5
    Medium

    CVE-2008-0026

    Last Modified: 26 Jan 2014

    SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.

    Source:Nico Leidecker
    Published:14 Feb 2008
    10
    Critical

    CVE-2008-0016

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

    Source:dmc
    Published:23 Sept 2008
    8.8
    High

    CVE-2008-0015

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted web page, as exploited in the wild in July 2009, aka "Microsoft Video ActiveX Control Vulnerability."

    Source:Metasploit
    Published:7 Jul 2009
    2.1
    Low

    CVE-2008-0010

    Last Modified: 14 Nov 2016

    The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.

    Source:qaaz
    Published:12 Feb 2008
    2.1
    Low

    CVE-2008-0009

    Last Modified: 14 Nov 2016

    The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.

    Source:qaaz
    Published:7 Feb 2008
    6.8
    Medium

    CVE-2007-6752

    Last Modified: 5 Mar 2012

    Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that end a session via the user/logout URI. NOTE: the vendor disputes the significance of this issue, by considering the "security benefit against platform complexity and performance impact" and concluding that a change to the logout behavior is not planned because "for most sites it is not worth the trade-off.

    Source:Ivano Binetti
    Published:28 Mar 2012
    5
    Medium

    CVE-2007-6750

    Last Modified: 11 Apr 2025

    The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.

    Published:17 Jun 2009
    10
    Critical

    CVE-2007-6731

    Last Modified: 15 Jan 2014

    Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via an OXM file with a negative value, which bypasses a check in (1) test_oxm and (2) decrunch_oxm functions in misc/oxm.c, leading to a buffer overflow.

    Source:Luigi Auriemma
    Published:27 Dec 2007
    2.6
    Low

    CVE-2007-6704

    Last Modified: 10 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.

    Source:Adrian Pastor
    Published:5 Mar 2008
    5
    Medium

    CVE-2007-6702

    Last Modified: 25 Jan 2018

    goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603.

    Source:NeoCoderz
    Published:4 Mar 2008
    4.3
    Medium

    CVE-2007-6700

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.

    Source:Anton Karpov
    Published:5 Feb 2008
    4.3
    Medium

    CVE-2007-6699

    Last Modified: 15 Jan 2014

    Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy, and (8) UserAgent property values.

    Source:Elazar Broad
    Published:4 Feb 2008
    7.5
    High

    CVE-2007-6697

    Last Modified: 23 Jan 2014

    Buffer overflow in the LWZReadByte function in IMG_gif.c in SDL_image before 1.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, a similar issue to CVE-2006-4484. NOTE: some of these details are obtained from third party information.

    Source:Gynvael Coldwind
    Published:23 Jan 2008
    2.1
    Low

    CVE-2007-6696

    Last Modified: 9 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authentication.

    Source:Omer Singer
    Published:1 Feb 2008
    7.5
    High

    CVE-2007-6682

    Last Modified: 23 Nov 2016

    Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.

    Source:EpiBite
    Published:17 Jan 2008
    7.5
    High

    CVE-2007-6681

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.

    Source:j0rgan
    Published:17 Jan 2008
    4.3
    Medium

    CVE-2007-6673

    Last Modified: 15 Jan 2014

    Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action.

    Source:GeFORC3
    Published:8 Jan 2008
    7.5
    High

    CVE-2007-6671

    Last Modified: 15 Jan 2014

    SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Password parameter, a different product than CVE-2006-6021. NOTE: some of these details are obtained from third party information.

    Source:Aria-Security Team
    Published:8 Jan 2008
    7.5
    High

    CVE-2007-6670

    Last Modified: 15 Jan 2014

    SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter.

    Source:Lostmon
    Published:8 Jan 2008
    4.3
    Medium

    CVE-2007-6669

    Last Modified: 15 Jan 2014

    Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter.

    Source:Lostmon
    Published:8 Jan 2008
    7.5
    High

    CVE-2007-6668

    Last Modified: 23 Apr 2026

    admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file.

    Source:Don
    Published:8 Jan 2008
    6.8
    Medium

    CVE-2007-6667

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413.

    Source:x0kster
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6666

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter.

    Source:Silentz
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6665

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.asp in Netchemia oneSCHOOL allows remote attackers to execute arbitrary SQL commands via the txtLoginID parameter.

    Source:Guga360
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6664

    Last Modified: 24 Oct 2016

    SQL injection vulnerability in index.php in WebPortal CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.

    Source:x0kster
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6663

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter to index.php.

    Source:Houssamix
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6658

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.

    Source:Pr0metheuS
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6657

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in source/includes/load_forum.php in Mihalism Multi Forum Host 3.0.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mfh_root_path parameter.

    Source:GoLd_M
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6656

    Last Modified: 2 Dec 2016

    SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.

    Source:EgiX
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6655

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:bd0rk
    Published:4 Jan 2008
    9.3
    Critical

    CVE-2007-6654

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660.

    Source:Elazar
    Published:4 Jan 2008
    5
    Medium

    CVE-2007-6653

    Last Modified: 24 Oct 2016

    Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:GoLd_M
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6652

    Last Modified: 23 Apr 2026

    cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer).

    Source:x0kster
    Published:4 Jan 2008
    5
    Medium

    CVE-2007-6651

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter.

    Source:BugReport.IR
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6650

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image/gif content type, and possibly other image and PDF content types, as demonstrated by uploading a .htaccess file.

    Source:BugReport.IR
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6649

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.

    Source:Crackers_Child
    Published:4 Jan 2008
    5
    Medium

    CVE-2007-6648

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.

    Source:jackal
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6647

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:IHTeam
    Published:4 Jan 2008
    4.3
    Medium

    CVE-2007-6646

    Last Modified: 21 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow remote attackers to inject arbitrary web script or HTML via (1) the return parameter to user/remindPassword, (2) the q parameter to the category script, (3) the return parameter to the order script, or (4) the email parameter to user/remindComplete.

    Source:Doz
    Published:4 Jan 2008
    4.3
    Medium

    CVE-2007-6641

    Last Modified: 15 Jan 2014

    Cross-site scripting (XSS) vulnerability in dir.php in milliscripts Redirection allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a browse action.

    Source:Jose Luis Gangora Fernandez
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6639

    Last Modified: 8 Nov 2016

    SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewdir action.

    Source:MhZ91
    Published:4 Jan 2008
    10
    Critical

    CVE-2007-6638

    Last Modified: 23 Apr 2026

    March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.

    Source:Alex Hernandez
    Published:4 Jan 2008
    6.8
    Medium

    CVE-2007-6634

    Last Modified: 15 Jan 2014

    Multiple SQL injection vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to execute arbitrary SQL commands via the category_id parameter to faq.php, and unspecified other vectors involving additional scripts.

    Source:Juan Galiana Lara
    Published:4 Jan 2008
    4.3
    Medium

    CVE-2007-6633

    Last Modified: 15 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to inject arbitrary web script or HTML via (1) the cat_name parameter to faq.php; and unspecified parameters to the (2) add categories, (3) edit categories, (4) delete categories, (5) add faq, (6) edit faq, and (7) delete faq Admin scripts.

    Source:Juan Galiana Lara
    Published:4 Jan 2008
    6.8
    Medium

    CVE-2007-6632

    Last Modified: 8 Nov 2016

    showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter.

    Source:MhZ91
    Published:4 Jan 2008
    7.5
    High

    CVE-2007-6631

    Last Modified: 20 Jan 2014

    Multiple buffer overflows in LScube libnemesi 0.6.4-rc1 and earlier allow remote attackers to execute arbitrary code via (1) a reply that begins with a long version string, which triggers an overflow in handle_rtsp_pkt in rtsp_handlers.c; long headers that trigger overflows in (2) send_pause_request, (3) send_play_request, (4) send_setup_request, or (5) send_teardown_request in rtsp_send.c, as demonstrated by the Content-Base header; or a long Transport header, which triggers an overflow in (6) get_transport_str_sctp, (7) get_transport_str_tcp, or (8) get_transport_str_udp in rtsp_transport.c.

    Source:Luigi Auriemma
    Published:27 Dec 2007
    5
    Medium

    CVE-2007-6630

    Last Modified: 20 Jan 2014

    The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a malformed URI containing a "/:" sequence, as demonstrated by a "DESCRIBE /: RTSP/1.0" request.

    Source:Luigi Auriemma
    Published:4 Jan 2008