7.5
    High

    CVE-2007-2971

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Source:Silentz
    Published:1 Jun 2007
    7.5
    High

    CVE-2007-2969

    Last Modified: 5 Oct 2016

    PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.

    Source:Mogatil
    Published:1 Jun 2007
    5
    Medium

    CVE-2007-2964

    Last Modified: 7 Dec 2013

    The fsmsh.dll host module in F-Secure Policy Manager Server 7.00 and earlier allows remote attackers to cause a denial of service (application crash) via NTFS reserved words in filenames in URLs.

    Source:David Maciejak
    Published:31 May 2007
    4.3
    Medium

    CVE-2007-2962

    Last Modified: 8 Dec 2013

    Cross-site scripting (XSS) vulnerability in search.php in Particle Gallery 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the order parameter.

    Source:Serapis.net
    Published:31 May 2007
    7.5
    High

    CVE-2007-2959

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.

    Source:laurent gaffie
    Published:31 May 2007
    7.5
    High

    CVE-2007-2947

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the root_prefix parameter to (1) index.php, (2) email_subscribe.php, (3) download.php, or (4) development.php.

    Source:DeltahackingTEAM
    Published:31 May 2007
    10
    Critical

    CVE-2007-2946

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) or execute arbitrary code via a long DestinationPath property value.

    Source:shinnai
    Published:31 May 2007
    6.8
    Medium

    CVE-2007-2943

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:ThE TiGeR
    Published:31 May 2007
    7.5
    High

    CVE-2007-2942

    Last Modified: 5 Oct 2016

    SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Silentz
    Published:31 May 2007
    7.5
    High

    CVE-2007-2941

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 for vBulletin allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) vbgsitemap/vbgsitemap-config.php or (2) vbgsitemap/vbgsitemap-vbseo.php.

    Source:Cold Zero
    Published:31 May 2007
    6.8
    Medium

    CVE-2007-2940

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary PHP code via a URL in the pachtofile parameter to (1) skin/html/table.php or (2) login.php.

    Source:Mehmet Ince
    Published:31 May 2007
    6.8
    Medium

    CVE-2007-2939

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the basepath parameter to (1) ITX.php, (2) IT_Error.php, or (3) IT.php in include/pear/.

    Source:ThE TiGeR
    Published:31 May 2007
    10
    Critical

    CVE-2007-2938

    Last Modified: 5 Oct 2016

    Buffer overflow in the BaseRunner ActiveX control in the Ademco ATNBaseLoader100 Module (ATNBaseLoader100.dll) 5.4.0.6, when Internet Explorer 6 is used, allows remote attackers to execute arbitrary code via a long argument to the (1) Send485CMD method, and possibly the (2) SetLoginID, (3) AddSite, (4) SetScreen, and (5) SetVideoServer methods.

    Source:rgod
    Published:31 May 2007
    7.5
    High

    CVE-2007-2937

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.

    Source:Mehmet Ince
    Published:31 May 2007
    7.5
    High

    CVE-2007-2936

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute arbitrary PHP code via a URL in the securelib parameter to (1) conf.php or (2) cp2.php.

    Source:ThE TiGeR
    Published:31 May 2007
    7.5
    High

    CVE-2007-2935

    Last Modified: 23 Apr 2026

    core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dict parameter.

    Source:Kacper
    Published:31 May 2007
    7.8
    High

    CVE-2007-2934

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter.

    Source:GoLd_M
    Published:31 May 2007
    7.5
    High

    CVE-2007-2933

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the form_id parameter.

    Source:CypherXero
    Published:31 May 2007
    4.3
    Medium

    CVE-2007-2932

    Last Modified: 7 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.

    Source:newbinaryfile
    Published:31 May 2007
    9.3
    Critical

    CVE-2007-2931

    Last Modified: 27 Oct 2016

    Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.

    Source:wushi
    Published:31 Aug 2007
    4.3
    Medium

    CVE-2007-2930

    Last Modified: 17 Oct 2017

    The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors. NOTE: this issue is different from CVE-2007-2926.

    Source:Amit Klein
    Published:12 Sept 2007
    4.3
    Medium

    CVE-2007-2926

    Last Modified: 12 Oct 2016

    ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.

    Source:posedge
    Published:23 Jul 2007
    9.3
    Critical

    CVE-2007-2919

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3) PAGENO, (4) LaunchMode, (5) SubID, (6) BookID, (7) LibraryID, (8) SubURL, and (9) LoadOpf properties.

    Source:Metasploit
    Published:6 Jun 2007
    6.8
    Medium

    CVE-2007-2918

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors.

    Source:Metasploit
    Published:1 Jun 2007
    4.3
    Medium

    CVE-2007-2908

    Last Modified: 5 Dec 2013

    Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action.

    Source:laurent gaffie
    Published:30 May 2007
    5
    Medium

    CVE-2007-2903

    Last Modified: 23 Apr 2026

    Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Source:shinnai
    Published:30 May 2007
    7.5
    High

    CVE-2007-2902

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter.

    Source:Silentz
    Published:30 May 2007
    4.3
    Medium

    CVE-2007-2901

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors.

    Source:Silentz
    Published:30 May 2007
    6.8
    Medium

    CVE-2007-2900

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/.

    Source:Mehmet Ince
    Published:30 May 2007
    7.5
    High

    CVE-2007-2899

    Last Modified: 5 Oct 2016

    Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters, as demonstrated via the threadperpage parameter in an editconfig action.

    Source:Dj7xpl
    Published:30 May 2007
    7.5
    High

    CVE-2007-2895

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbitrary code via a long Directory property value.

    Source:shinnai
    Published:30 May 2007
    2.1
    Low

    CVE-2007-2894

    Last Modified: 8 Dec 2013

    The emulated floppy disk controller in Bochs 2.3 allows local users of the guest operating system to cause a denial of service (virtual machine crash) via unspecified vectors, resulting in a divide-by-zero error.

    Source:Tavis Ormandy
    Published:30 May 2007
    4.3
    Medium

    CVE-2007-2892

    Last Modified: 6 Dec 2013

    Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:vagrant
    Published:30 May 2007
    7.5
    High

    CVE-2007-2891

    Last Modified: 5 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.

    Source:DeltahackingTEAM
    Published:30 May 2007
    7.5
    High

    CVE-2007-2890

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id_category parameter.

    Source:Kacper
    Published:30 May 2007
    7.5
    High

    CVE-2007-2889

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter.

    Source:Silentz
    Published:30 May 2007
    7.6
    High

    CVE-2007-2888

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.

    Source:n00b
    Published:30 May 2007
    4.3
    Medium

    CVE-2007-2887

    Last Modified: 6 Dec 2013

    Cross-site scripting (XSS) vulnerability in index.php in Web Icerik Yonetim Sistemi (WIYS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the No parameter in the Sayfa page.

    Source:vagrant
    Published:30 May 2007
    9.3
    Critical

    CVE-2007-2884

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.

    Source:UmZ
    Published:30 May 2007
    4.3
    Medium

    CVE-2007-2879

    Last Modified: 6 Dec 2013

    Cross-site scripting (XSS) vulnerability in mods.php in GTP GNUTurk Portal System 3G allows remote attackers to inject arbitrary web script or HTML via the month parameter.

    Source:vagrant
    Published:29 May 2007
    4.9
    Medium

    CVE-2007-2878

    Last Modified: 6 Sept 2016

    The VFAT compat ioctls in the Linux kernel before 2.6.21.2, when run on a 64-bit system, allow local users to corrupt a kernel_dirent struct and cause a denial of service (system crash) via unknown vectors.

    Source:Bart Oldeman
    Published:8 May 2007
    6.8
    Medium

    CVE-2007-2872

    Last Modified: 8 Dec 2013

    Multiple integer overflows in the chunk_split function in PHP 5 before 5.2.3 and PHP 4 before 4.4.8 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via the (1) chunks, (2) srclen, and (3) chunklen arguments.

    Source:Gerhard Wagner
    Published:1 Jun 2007
    9.3
    Critical

    CVE-2007-2865

    Last Modified: 6 Jan 2017

    Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter.

    Source:Michal Majchrowicz
    Published:25 May 2007
    9.3
    Critical

    CVE-2007-2864

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.

    Source:Metasploit
    Published:6 Jun 2007
    7.5
    High

    CVE-2007-2857

    Last Modified: 6 Dec 2013

    PHP remote file inclusion vulnerability in sample/xls2mysql in ABC Excel Parser Pro 4.0 allows remote attackers to execute arbitrary PHP code via a URL in the parser_path parameter.

    Source:the_Edit0r
    Published:24 May 2007
    9.3
    Critical

    CVE-2007-2856

    Last Modified: 5 Oct 2016

    Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2855.

    Source:rgod
    Published:24 May 2007
    7.5
    High

    CVE-2007-2854

    Last Modified: 5 Oct 2016

    Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) style or (2) langue parameter.

    Source:m@ge|ozz
    Published:24 May 2007
    10
    Critical

    CVE-2007-2853

    Last Modified: 23 Apr 2026

    The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function.

    Source:rgod
    Published:24 May 2007
    7.5
    High

    CVE-2007-2851

    Last Modified: 23 Apr 2026

    A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to overwrite arbitrary files via the WriteDataToFile method.

    Source:shinnai
    Published:24 May 2007
    10
    Critical

    CVE-2007-2843

    Last Modified: 6 Dec 2013

    Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.

    Source:Gareth Heyes
    Published:24 May 2007