4.3
    Medium

    CVE-2007-4528

    Last Modified: 19 Oct 2016

    The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code by loading an arbitrary DLL and calling a function, as demonstrated by kernel32.dll and the WinExec function. NOTE: this issue does not cross privilege boundaries in most contexts, so perhaps it should not be included in CVE.

    Source:NetJackal
    Published:25 Aug 2007
    7.5
    High

    CVE-2007-4527

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:wlhaan-hacker
    Published:25 Aug 2007
    7.5
    High

    CVE-2007-4524

    Last Modified: 12 Oct 2016

    PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.

    Source:Nice Name Crew
    Published:25 Aug 2007
    6
    Medium

    CVE-2007-4522

    Last Modified: 26 Dec 2013

    Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/; the (2) menu_id, (3) name, (3) page_id, and (4) url parameters in (d) admin/navigation/do_new_item.php; the (5) new_menuname parameter in (e) admin/navigation/do_new_nav.php; and (6) area1, name, and url parameters to (f) admin/pages/do_new_page.php. NOTE: some vectors might be reachable through the url and name parameters to (g) admin/navigation/new_nav_item.php. NOTE: the original disclosure does not precisely state which vectors are associated with SQL injection versus XSS.

    Source:Nagendra Kumar G
    Published:25 Aug 2007
    6
    Medium

    CVE-2007-4517

    Last Modified: 7 Nov 2011

    Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code via a long (1) OWNER or (2) NAME argument.

    Source:David Maman
    Published:8 Nov 2007
    9.3
    Critical

    CVE-2007-4515

    Last Modified: 19 Oct 2016

    Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.

    Source:minhbq
    Published:31 Aug 2007
    7.5
    High

    CVE-2007-4509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the did parameter in a details action.

    Source:ajann
    Published:23 Aug 2007
    6.8
    Medium

    CVE-2007-4508

    Last Modified: 28 Dec 2013

    Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.

    Source:Luigi Auriemma
    Published:23 Aug 2007
    6.8
    Medium

    CVE-2007-4507

    Last Modified: 12 Oct 2016

    Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial of service or execute arbitrary code via long arguments to the (1) ntuser_getuserlist, (2) ntuser_getuserinfo, (3) ntuser_getusergroups, or (4) ntuser_getdomaincontroller functions.

    Source:shinnai
    Published:23 Aug 2007
    7.5
    High

    CVE-2007-4506

    Last Modified: 14 Feb 2017

    SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an offer_view action.

    Source:ajann
    Published:23 Aug 2007
    7.5
    High

    CVE-2007-4505

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.

    Source:ajann
    Published:23 Aug 2007
    5
    Medium

    CVE-2007-4504

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action.

    Source:ajann
    Published:23 Aug 2007
    7.5
    High

    CVE-2007-4503

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the tagid parameter.

    Source:ajann
    Published:23 Aug 2007
    7.5
    High

    CVE-2007-4502

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the afilter parameter.

    Source:ajann
    Published:23 Aug 2007
    7.8
    High

    CVE-2007-4498

    Last Modified: 26 Dec 2013

    The Grandstream SIP Phone GXV-3000 with firmware 1.0.1.7, Loader 1.0.0.6, and Boot 1.0.0.18 allows remote attackers to force silent call completion, eavesdrop on the phone's local environment, and cause a denial of service (blocked call reception) via a certain SIP INVITE message followed by a certain "SIP/2.0 183 Session Progress" message.

    Source:MADYNES
    Published:23 Aug 2007
    7.5
    High

    CVE-2007-4491

    Last Modified: 26 Dec 2013

    SQL injection vulnerability in uyeler2.php in Gurur haber 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:dumenci
    Published:23 Aug 2007
    6.8
    Medium

    CVE-2007-4489

    Last Modified: 23 Apr 2026

    Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary code via a long Username argument to the ReInit method.

    Source:rgod
    Published:22 Aug 2007
    7.5
    High

    CVE-2007-4486

    Last Modified: 2 Jan 2014

    Multiple PHP remote file inclusion vulnerabilities in index.php in Linkliste 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) styl[top], (2) url_eintrag, or (3) styl[themen] parameter.

    Source:iNs
    Published:22 Aug 2007
    4.3
    Medium

    CVE-2007-4482

    Last Modified: 27 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).

    Source:MustLive
    Published:22 Aug 2007
    4.3
    Medium

    CVE-2007-4479

    Last Modified: 26 Dec 2013

    Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter.

    Source:MustLive
    Published:22 Aug 2007
    7.5
    High

    CVE-2007-4476

    Last Modified: 14 Nov 2017

    Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."

    Source:Dmitry V. Levin
    Published:17 Aug 2007
    9.3
    Critical

    CVE-2007-4475

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.

    Source:Metasploit
    Published:1 Apr 2009
    9.3
    Critical

    CVE-2007-4474

    Last Modified: 14 Nov 2016

    Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

    Source:Elazar
    Published:27 Dec 2007
    6.8
    Medium

    CVE-2007-4466

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters.

    Source:Metasploit
    Published:9 Oct 2007
    5
    Medium

    CVE-2007-4463

    Last Modified: 27 Dec 2013

    The Fileinfo 2.0.9 plugin for Total Commander allows user-assisted remote attackers to cause a denial of service (unhandled exception) via an invalid RVA address function pointer in (1) an IMAGE_THUNK_DATA structure, involving the (a) OriginalFirstThunk and (b) FirstThunk IMAGE_IMPORT_DESCRIPTOR fields, or (2) the AddressOfNames IMAGE_EXPORT_DIRECTORY field in a PE file.

    Source:Gynvael Coldwind
    Published:21 Aug 2007
    7.1
    High

    CVE-2007-4459

    Last Modified: 12 Oct 2016

    Cisco IP Phone 7940 and 7960 with P0S3-08-6-00 firmware, and other SIP firmware before 8.7(0), allows remote attackers to cause a denial of service (device reboot) via (1) a certain sequence of 10 invalid SIP INVITE and OPTIONS messages; or (2) a certain invalid SIP INVITE message that contains a remote tag, followed by a certain set of two related SIP OPTIONS messages.

    Source:MADYNES
    Published:21 Aug 2007
    7.5
    High

    CVE-2007-4458

    Last Modified: 26 Dec 2013

    PHP remote file inclusion vulnerability in includes/class/class_tpl.php in Firesoft allows remote attackers to execute arbitrary PHP code via a URL in the cache_file parameter.

    Source:DarKdewiL
    Published:21 Aug 2007
    6.4
    Medium

    CVE-2007-4457

    Last Modified: 26 Dec 2013

    Directory traversal vulnerability in forumreply.php in Dalai Forum 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the chemin parameter.

    Source:DarKdewiL
    Published:21 Aug 2007
    7.5
    High

    CVE-2007-4456

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.

    Source:k1tk4t
    Published:21 Aug 2007
    7.5
    High

    CVE-2007-4446

    Last Modified: 27 Dec 2013

    Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the NICK command (client nickname) when entering a game.

    Source:Luigi Auriemma
    Published:21 Aug 2007
    7.5
    High

    CVE-2007-4444

    Last Modified: 27 Dec 2013

    Multiple buffer overflows in Image Space rFactor 1.250 and earlier allow remote attackers to execute arbitrary code via a packet with ID (1) 0x80 or (2) 0x88 to UDP port 34297, related to the buffer containing the server version number.

    Source:Luigi Auriemma
    Published:21 Aug 2007
    5
    Medium

    CVE-2007-4442

    Last Modified: 27 Dec 2013

    Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII.

    Source:Luigi Auriemma
    Published:21 Aug 2007
    4.6
    Medium

    CVE-2007-4441

    Last Modified: 12 Oct 2016

    Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attackers to execute arbitrary code via a long string in the filename argument to the win_browse_file function.

    Source:Inphex
    Published:21 Aug 2007
    7.5
    High

    CVE-2007-4440

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.

    Source:eliteboy
    Published:21 Aug 2007
    7.5
    High

    CVE-2007-4439

    Last Modified: 3 May 2018

    PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the site_isp_root parameter, probably related to cart.php.

    Source:ShaiMagal
    Published:21 Aug 2007
    4.3
    Medium

    CVE-2007-4434

    Last Modified: 26 Dec 2013

    Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:GeFORC3
    Published:20 Aug 2007
    5
    Medium

    CVE-2007-4430

    Last Modified: 26 Dec 2013

    Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

    Source:anonymous
    Published:20 Aug 2007
    9.3
    Critical

    CVE-2007-4420

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the HttpDownloadFile method, a different vulnerability than CVE-2007-3168 and CVE-2007-3169.

    Source:shinnai
    Published:18 Aug 2007
    9.3
    Critical

    CVE-2007-4419

    Last Modified: 26 Dec 2013

    Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication cookie, which makes it easier for remote attackers to guess the cookie and access the Admin area.

    Source:imei
    Published:18 Aug 2007
    9.3
    Critical

    CVE-2007-4391

    Last Modified: 27 Dec 2013

    Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by sending an "invite to view my webcam" request, and then injecting a DLL into the attacker's peer Yahoo! Messenger application when this request is accepted.

    Source:team509
    Published:17 Aug 2007
    7.2
    High

    CVE-2007-4390

    Last Modified: 26 Dec 2013

    The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5.0.2.8 allows local admin users to gain root privileges on the underlying operating system via shell metacharacters in a command.

    Source:forloop
    Published:17 Aug 2007
    7.8
    High

    CVE-2007-4389

    Last Modified: 17 Jan 2014

    Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG, 1800HW, and 2071 Gateway routers, with 3.17.5, 3.7.1, and 5.29.51 software, allows remote attackers to create DNS mappings as administrators, and conduct DNS poisoning attacks, via the NAME and ADDR parameters.

    Source:hkm
    Published:17 Aug 2007
    6
    Medium

    CVE-2007-4386

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in GetMyOwnArcade allows remote attackers to execute arbitrary SQL commands via the query parameter.

    Source:RoXur777
    Published:17 Aug 2007
    6.8
    Medium

    CVE-2007-4385

    Last Modified: 25 Dec 2013

    OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the validation routines.

    Source:Meder Kydyraliev
    Published:17 Aug 2007
    6.8
    Medium

    CVE-2007-4384

    Last Modified: 26 Dec 2013

    Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code via a URL in the (1) NomVote and (2) FilePalHex parameters.

    Source:Crackers_Child
    Published:17 Aug 2007
    5
    Medium

    CVE-2007-4382

    Last Modified: 23 Apr 2026

    CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header.

    Source:ZwelL
    Published:17 Aug 2007
    9.3
    Critical

    CVE-2007-4381

    Last Modified: 27 Dec 2013

    Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to perform unauthorized actions via an applet that grants certain privileges to itself.

    Source:John Heasman
    Published:15 Aug 2007
    6
    Medium

    CVE-2007-4377

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argument to the SEARCH command. NOTE: this might overlap CVE-2007-4372.

    Source:Joey Mengele
    Published:16 Aug 2007
    5.8
    Medium

    CVE-2007-4375

    Last Modified: 12 Oct 2016

    The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.

    Source:Pravus
    Published:16 Aug 2007
    7.5
    High

    CVE-2007-4370

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbitrary code via a long string to UDP port 26000.

    Source:n00b
    Published:15 Aug 2007