4.4
    Medium

    CVE-2007-4652

    Last Modified: 23 Apr 2026

    The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

    Source:Maksymilian Arciemowicz
    Published:4 Sept 2007
    7.2
    High

    CVE-2007-4649

    Last Modified: 28 Dec 2013

    MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.

    Source:Edi Strosar
    Published:31 Aug 2007
    7.2
    High

    CVE-2007-4648

    Last Modified: 12 Oct 2016

    The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa device, which allows local users to gain privileges by (1) triggering a buffer overflow in a kernel pool via a string argument to ioctl 0xBF67201C; or by (2) sending a crafted KEVENT structure through ioctl 0xBF672028 to overwrite arbitrary memory locations.

    Source:inocraM
    Published:31 Aug 2007
    5
    Medium

    CVE-2007-4647

    Last Modified: 23 Apr 2026

    newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.cgi.

    Source:Don
    Published:31 Aug 2007
    10
    Critical

    CVE-2007-4646

    Last Modified: 23 Apr 2026

    Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long USER command.

    Source:rgod
    Published:31 Aug 2007
    6.4
    Medium

    CVE-2007-4645

    Last Modified: 12 Oct 2016

    SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2006-1108.

    Source:not sec group
    Published:31 Aug 2007
    10
    Critical

    CVE-2007-4642

    Last Modified: 28 Dec 2013

    Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2) Msg_Write function in net_msg.c, or (3) many commands that are not properly handled by the NetSv_ReadCommands function in d_netsv.c; or (4) cause a denial of service (daemon crash) via a chat (PKT_CHAT) message without a final '\0' character.

    Source:Luigi Auriemma
    Published:31 Aug 2007
    6.4
    Medium

    CVE-2007-4641

    Last Modified: 12 Oct 2016

    Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter, as demonstrated by injecting code into an Apache log file.

    Source:GoLd_M
    Published:31 Aug 2007
    6.4
    Medium

    CVE-2007-4640

    Last Modified: 12 Oct 2016

    Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files in uploads/ via an Uploads action.

    Source:GoLd_M
    Published:31 Aug 2007
    6.5
    Medium

    CVE-2007-4639

    Last Modified: 28 Dec 2013

    EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as demonstrated by (1) pldbg_get_stack and (2) pldbg_abort_target, which triggers use of an uninitialized pointer.

    Source:Joxean Koret
    Published:29 Aug 2007
    4.3
    Medium

    CVE-2007-4638

    Last Modified: 28 Dec 2013

    Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview.

    Source:Gynvael Coldwind
    Published:31 Aug 2007
    6.4
    Medium

    CVE-2007-4637

    Last Modified: 23 Apr 2026

    xGB.php in xGB 2.0 does not require authentication for an admin edit action, which allows remote attackers to make unspecified changes via an unknown series of steps.

    Source:DarkFuneral
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4636

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpBG 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to (1) intern/admin/other/backup.php, (2) intern/admin/, (3) intern/clan/member_add.php, (4) intern/config/key_2.php, or (5) intern/config/forum.php.

    Source:GoLd_M
    Published:31 Aug 2007
    5
    Medium

    CVE-2007-4635

    Last Modified: 28 Dec 2013

    Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:SlicK
    Published:31 Aug 2007
    9.3
    Critical

    CVE-2007-4634

    Last Modified: 22 Jun 2017

    Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.

    Source:anonymous
    Published:31 Aug 2007
    4.3
    Medium

    CVE-2007-4630

    Last Modified: 26 Dec 2016

    Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:Richard Brain
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:SmOk3
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4627

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:k1tk4t
    Published:31 Aug 2007
    9
    Critical

    CVE-2007-4620

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.

    Source:Metasploit
    Published:7 Apr 2008
    7.5
    High

    CVE-2007-4611

    Last Modified: 27 Dec 2013

    SQL injection vulnerability in viewevent.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:s0cratex
    Published:31 Aug 2007
    9.3
    Critical

    CVE-2007-4607

    Last Modified: 10 Mar 2011

    Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15.

    Source:Metasploit
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4606

    Last Modified: 18 Dec 2016

    PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PNC) 4.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1602. NOTE: it is possible that this issue stems from a problem in VWar itself.

    Source:DNX
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4605

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter, a different vector than CVE-2006-1503, CVE-2006-1636, and CVE-2006-1747.

    Source:DNX
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4604

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Source:irvian
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4603

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter in a showarticle action or (2) the catid parameter in a showcat action.

    Source:SmOk3
    Published:31 Aug 2007
    6.8
    Medium

    CVE-2007-4602

    Last Modified: 12 Oct 2016

    SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:not sec group
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4597

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to execute arbitrary SQL commands via the s[cid] parameter in a search_list action, a different vector than CVE-2007-2549.

    Source:k1tk4t
    Published:30 Aug 2007
    7.5
    High

    CVE-2007-4596

    Last Modified: 23 Apr 2026

    The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.

    Source:NetJackal
    Published:30 Aug 2007
    4.3
    Medium

    CVE-2007-4592

    Last Modified: 6 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.

    Source:sasquatch
    Published:20 Mar 2008
    7.5
    High

    CVE-2007-4586

    Last Modified: 19 Oct 2016

    Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent attackers to execute arbitrary code, probably during Unicode conversion, as demonstrated by a long string in the first argument to the iis_getservicestate function, related to the ServiceId argument to the (1) fnStartService, (2) fnGetServiceState, (3) fnStopService, and possibly other functions.

    Source:boecke
    Published:29 Aug 2007
    7.5
    High

    CVE-2007-4585

    Last Modified: 12 Oct 2016

    Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Source:bd0rk
    Published:29 Aug 2007
    10
    Critical

    CVE-2007-4584

    Last Modified: 12 Oct 2016

    Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable.

    Source:bannedit
    Published:29 Aug 2007
    5
    Medium

    CVE-2007-4583

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method.

    Source:shinnai
    Published:29 Aug 2007
    7.5
    High

    CVE-2007-4582

    Last Modified: 22 Nov 2017

    Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method.

    Source:shinnai
    Published:29 Aug 2007
    7.5
    High

    CVE-2007-4581

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL commands via the show parameter.

    Source:D4m14n
    Published:29 Aug 2007
    7.2
    High

    CVE-2007-4573

    Last Modified: 6 Sept 2016

    The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.

    Source:Wojciech Purczynski
    Published:21 Sept 2007
    2.1
    Low

    CVE-2007-4571

    Last Modified: 6 Sept 2016

    The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.

    Source:Karimo_DM
    Published:25 Sept 2007
    7.8
    High

    CVE-2007-4567

    Last Modified: 6 Sept 2016

    The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.

    Source:Clemens Kurtenbach
    Published:7 Sept 2007
    10
    Critical

    CVE-2007-4566

    Last Modified: 12 Oct 2016

    Multiple buffer overflows in the login mechanism in sidvault in Alpha Centauri Software SIDVault LDAP Server before 2.0f allow remote attackers to execute arbitrary code via crafted LDAP packets, as demonstrated by a long dc entry in an LDAP bind.

    Source:Joxean Koret
    Published:28 Aug 2007
    7.6
    High

    CVE-2007-4560

    Last Modified: 6 Mar 2011

    clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."

    Source:Metasploit
    Published:28 Aug 2007
    9.8
    Critical

    CVE-2007-4559

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

    Published:24 Aug 2007
    5
    Medium

    CVE-2007-4553

    Last Modified: 27 Oct 2016

    The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message with a Via header that contains a '/' (slash) instead of the required space following the SIP version number.

    Source:MADYNES
    Published:28 Aug 2007
    7.5
    High

    CVE-2007-4552

    Last Modified: 12 Oct 2016

    SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.

    Source:SmOk3
    Published:28 Aug 2007
    7.5
    High

    CVE-2007-4551

    Last Modified: 27 Dec 2013

    PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter.

    Source:sm0k3
    Published:28 Aug 2007
    6.8
    Medium

    CVE-2007-4545

    Last Modified: 28 Dec 2013

    Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a filename within a (1) ZIP or (2) RAR archive.

    Source:Gynvael Coldwind
    Published:27 Aug 2007
    6.8
    Medium

    CVE-2007-4537

    Last Modified: 28 Dec 2013

    Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet.

    Source:Luigi Auriemma
    Published:27 Aug 2007
    4.3
    Medium

    CVE-2007-4535

    Last Modified: 27 Dec 2013

    The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within a certain UDP packet that triggers an assertion error.

    Source:Luigi Auriemma
    Published:25 Aug 2007
    7.5
    High

    CVE-2007-4534

    Last Modified: 27 Dec 2013

    Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a chat message and possibly (2) a long name field.

    Source:Luigi Auriemma
    Published:25 Aug 2007
    6.8
    Medium

    CVE-2007-4533

    Last Modified: 27 Dec 2013

    Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a chat message, related to a call to the BroadcastPrintf function.

    Source:Luigi Auriemma
    Published:25 Aug 2007
    5
    Medium

    CVE-2007-4531

    Last Modified: 28 Dec 2013

    Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many 0x07 or other control characters to the file transfer port.

    Source:Luigi Auriemma
    Published:25 Aug 2007