7.5
    High

    CVE-2007-1413

    Last Modified: 28 Sept 2016

    Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers to execute arbitrary code via a long value in the third argument (object id).

    Source:rgod
    Published:12 Mar 2007
    7.8
    High

    CVE-2007-1412

    Last Modified: 27 Sept 2016

    The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensitive information (script source code) via a long string in the second argument.

    Source:rgod
    Published:12 Mar 2007
    6.8
    Medium

    CVE-2007-1411

    Last Modified: 27 Sept 2016

    Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to execute arbitrary code via long server name arguments to the (1) mssql_connect and (2) mssql_pconnect functions.

    Source:rgod
    Published:10 Mar 2007
    7.5
    High

    CVE-2007-1410

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL commands via the kategori parameter.

    Source:CyberGhost
    Published:10 Mar 2007
    7.3
    High

    CVE-2007-1404

    Last Modified: 27 Oct 2016

    tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.

    Source:Umesh Wanve
    Published:10 Mar 2007
    7.5
    High

    CVE-2007-1403

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote attackers to cause a denial of service (Internet Explorer 7 crash) and possibly execute arbitrary code via a long (1) BGCOLOR, (2) SRC, (3) AutoStart, (4) Sound, (5) DrawLogo, or (6) DrawProgress property value, different vectors than CVE-2006-6885.

    Source:shinnai
    Published:10 Mar 2007
    7.5
    High

    CVE-2007-1402

    Last Modified: 23 Apr 2026

    The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possibly involving improper initialization or blank arguments.

    Source:Umesh Wanve
    Published:10 Mar 2007
    6.9
    Medium

    CVE-2007-1401

    Last Modified: 28 Sept 2016

    Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allow local users to gain privileges via a long argument to the crack_opendict function.

    Source:rgod
    Published:10 Mar 2007
    9.8
    Critical

    CVE-2007-1399

    Last Modified: 28 Sept 2016

    Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1, allows remote attackers to execute arbitrary code via a long zip:// URL, as demonstrated by actively triggering URL access from a remote PHP interpreter via avatar upload or blog pingback.

    Source:Stefan Esser
    Published:10 Mar 2007
    7.1
    High

    CVE-2007-1398

    Last Modified: 27 Sept 2016

    The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip_conntrack module loaded, allows remote attackers to cause a denial of service (segmentation fault and application crash) via certain UDP packets produced by send_morefrag_packet and send_overlap_packet.

    Source:Antimatt3r
    Published:10 Mar 2007
    10
    Critical

    CVE-2007-1397

    Last Modified: 17 Apr 2011

    Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings.

    Source:Caleb James DeLisle
    Published:10 Mar 2007
    10
    Critical

    CVE-2007-1394

    Last Modified: 23 Apr 2026

    Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php. NOTE: some of these details are obtained from third party information.

    Source:Dj7xpl
    Published:10 Mar 2007
    10
    Critical

    CVE-2007-1393

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter.

    Source:DNX
    Published:10 Mar 2007
    5
    Medium

    CVE-2007-1392

    Last Modified: 27 Sept 2016

    Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a .. (dot dot) in the file_to_download parameter.

    Source:GoLd_M
    Published:10 Mar 2007
    10
    Critical

    CVE-2007-1391

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

    Source:K-159
    Published:10 Mar 2007
    4.4
    Medium

    CVE-2007-1388

    Last Modified: 6 Sept 2016

    The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid option value, which triggers a NULL pointer dereference.

    Source:Joey Mengele
    Published:8 Mar 2007
    9.8
    Critical

    CVE-2007-1383

    Last Modified: 27 Sept 2016

    Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitrary code by overflowing this counter, which causes the same variable to be destroyed twice, a related issue to CVE-2007-1286.

    Source:Stefan Esser
    Published:10 Mar 2007
    6.8
    Medium

    CVE-2007-1382

    Last Modified: 23 Apr 2026

    The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScript.Shell COM object, as demonstrated by using the Run method of this object to execute cmd.exe, which bypasses PHP's safe mode.

    Source:anonymous
    Published:10 Mar 2007
    7.6
    High

    CVE-2007-1381

    Last Modified: 1 Dec 2016

    The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intended and uses improper arguments, which allows context-dependent attackers to execute arbitrary code via a WDDX packet with a malformed overlap of a STRING element, which triggers a buffer overflow.

    Source:Stefan Esser
    Published:10 Mar 2007
    5
    Medium

    CVE-2007-1380

    Last Modified: 27 Sept 2016

    The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-dependent attackers to obtain sensitive information (memory contents) via a serialized variable entry with a large length value, which triggers a buffer over-read.

    Source:Stefan Esser
    Published:14 Feb 2007
    5
    Medium

    CVE-2007-1377

    Last Modified: 23 Apr 2026

    AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027 and CVE-2006-6236.

    Source:shinnai
    Published:10 Mar 2007
    7.5
    High

    CVE-2007-1376

    Last Modified: 27 Sept 2016

    The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspond to a shmop resource, which allows context-dependent attackers to read and write arbitrary memory locations via arguments associated with an inappropriate resource, as demonstrated by a GD Image resource.

    Source:Stefan Esser
    Published:10 Mar 2007
    5
    Medium

    CVE-2007-1375

    Last Modified: 28 Sept 2016

    Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sensitive memory via a large value in the length argument, a different vulnerability than CVE-2006-1991.

    Source:Stefan Esser
    Published:10 Mar 2007
    10
    Critical

    CVE-2007-1373

    Last Modified: 27 Sept 2016

    Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: this might be the same issue as CVE-2006-5961.

    Source:mu-b
    Published:10 Mar 2007
    10
    Critical

    CVE-2007-1372

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the tpl_pgb_moddir parameter.

    Source:GoLd_M
    Published:10 Mar 2007
    6.9
    Medium

    CVE-2007-1371

    Last Modified: 20 Nov 2013

    Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.

    Source:Luigi Auriemma
    Published:10 Mar 2007
    4.4
    Medium

    CVE-2007-1369

    Last Modified: 20 Nov 2013

    ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by editing a copy of php.ini file using the -f parameter, and then performing a symlink attack using the directory that contains the attacker-controlled php.ini file, and linking this directory to /usr/local/Zend/etc.

    Source:Stefan Esser
    Published:9 Mar 2007
    10
    Critical

    CVE-2007-1365

    Last Modified: 20 Nov 2013

    Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "incorrect mbuf handling for ICMP6 packets." NOTE: this was originally reported as a denial of service.

    Source:Alfredo Ortega
    Published:10 Mar 2007
    6.4
    Medium

    CVE-2007-1364

    Last Modified: 26 Nov 2013

    DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.

    Source:Alexander Klink
    Published:11 Apr 2007
    7.5
    High

    CVE-2007-1363

    Last Modified: 26 Nov 2013

    Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.

    Source:Alexander Klink
    Published:11 Apr 2007
    4.3
    Medium

    CVE-2007-1362

    Last Modified: 20 Nov 2013

    Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter within cookie path or name values, which could trigger a misinterpretation of cookie data, aka "Path Abuse in Cookies."

    Source:Nicolas DEROUET
    Published:31 May 2007
    6.8
    Medium

    CVE-2007-1359

    Last Modified: 23 Apr 2026

    Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules via application/x-www-form-urlencoded POST data that contains an ASCIIZ (0x00) byte, which mod_security treats as a terminator even though it is still processed as normal data by some HTTP parsers including PHP 5.2.0, and possibly parsers in Perl, and Python.

    Source:Stefan Esser
    Published:8 Mar 2007
    7.8
    High

    CVE-2007-1357

    Last Modified: 26 Nov 2013

    The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when an attempt is made to perform a checksum.

    Source:Jean Delvare
    Published:11 Apr 2007
    4.3
    Medium

    CVE-2007-1355

    Last Modified: 5 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.

    Source:Ferruh Mavituna
    Published:19 May 2007
    7.1
    High

    CVE-2007-1347

    Last Modified: 23 Apr 2026

    Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.

    Source:Marsu
    Published:8 Mar 2007
    7.5
    High

    CVE-2007-1340

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the sqllog parameter.

    Source:bd0rk
    Published:8 Mar 2007
    7.5
    High

    CVE-2007-1339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrary SQL commands via the lcnt parameter.

    Source:ajann
    Published:8 Mar 2007
    4.3
    Medium

    CVE-2007-1331

    Last Modified: 19 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program. NOTE: some of these details are obtained from third party information.

    Source:Stefan Friedli
    Published:7 Mar 2007
    4.4
    Medium

    CVE-2007-1330

    Last Modified: 20 Nov 2013

    Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLM\SYSTEM\Software\Comodo\Personal Firewall registry key by guessing the name of a named pipe under \Device\NamedPipe\OLE and attempting to open it multiple times.

    Source:Matousec Transparent security
    Published:7 Mar 2007
    7.8
    High

    CVE-2007-1327

    Last Modified: 20 Nov 2013

    The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a request without a cipher algorithm and an invalid HMAC algorithm.

    Source:Frank Benkstein
    Published:7 Mar 2007
    4.3
    Medium

    CVE-2007-1308

    Last Modified: 20 Nov 2013

    ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.

    Source:mark
    Published:4 Mar 2007
    7.8
    High

    CVE-2007-1306

    Last Modified: 23 Apr 2026

    Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session Initiation Protocol (SIP) packet without a URI and SIP-version header, which results in a NULL pointer dereference.

    Source:fbffff
    Published:7 Mar 2007
    7.8
    High

    CVE-2007-1303

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Sebastian Wolfgarten
    Published:7 Mar 2007
    9
    Critical

    CVE-2007-1301

    Last Modified: 15 Nov 2016

    Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command. NOTE: this is probably different than CVE-2006-6423.

    Source:mu-b
    Published:7 Mar 2007
    7.5
    High

    CVE-2007-1299

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ipath parameter.

    Source:mozi
    Published:7 Mar 2007
    7.5
    High

    CVE-2007-1298

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Source:ajann
    Published:7 Mar 2007
    7.5
    High

    CVE-2007-1297

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Source:ajann
    Published:7 Mar 2007
    7.5
    High

    CVE-2007-1296

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.

    Source:ajann
    Published:7 Mar 2007
    7.5
    High

    CVE-2007-1295

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.

    Source:ajann
    Published:7 Mar 2007
    7.8
    High

    CVE-2007-1294

    Last Modified: 23 Apr 2026

    A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.

    Source:shinnai
    Published:7 Mar 2007