7.5
    High

    CVE-2007-0758

    Last Modified: 13 Nov 2013

    PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Hasadya Raed
    Published:6 Feb 2007
    7.5
    High

    CVE-2007-0757

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter.

    Source:ThE dE@Th
    Published:6 Feb 2007
    7.8
    High

    CVE-2007-0756

    Last Modified: 27 Sept 2016

    Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large computer-name size value in a ServerInit packet, which triggers a failed malloc and a resulting NULL dereference.

    Source:poplix
    Published:6 Feb 2007
    7.2
    High

    CVE-2007-0753

    Last Modified: 7 Dec 2013

    Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.

    Source:Chris Anley
    Published:24 May 2007
    7.2
    High

    CVE-2007-0752

    Last Modified: 5 Oct 2016

    The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.

    Source:qaaz
    Published:24 May 2007
    2.1
    Low

    CVE-2007-0710

    Last Modified: 23 Apr 2026

    The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.

    Source:MoAB
    Published:16 Feb 2007
    7.2
    High

    CVE-2007-0708

    Last Modified: 13 Nov 2013

    cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.

    Source:Matousec Transparent security
    Published:4 Feb 2007
    6.8
    Medium

    CVE-2007-0707

    Last Modified: 30 Nov 2011

    Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Debasish Mandal
    Published:4 Feb 2007
    7.5
    High

    CVE-2007-0704

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter, a different vector than CVE-2006-4669. NOTE: the documentation says to remove install.php after installation.

    Source:basher13
    Published:4 Feb 2007
    7.5
    High

    CVE-2007-0703

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[core][module_path] parameter.

    Source:GoLd_M
    Published:4 Feb 2007
    7.5
    High

    CVE-2007-0702

    Last Modified: 27 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) Shared/controller/text.ctrl.php or (2) UserMan/controller/common.function.php.

    Source:Mehmet Ince
    Published:4 Feb 2007
    7.5
    High

    CVE-2007-0701

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.

    Source:GoLd_M
    Published:4 Feb 2007
    7.5
    High

    CVE-2007-0699

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in includes/includes.php in Guernion Sylvain Portail Web Php (aka Gsylvain35 Portail Web, PwP) before 2.5.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.

    Source:laurent gaffié
    Published:4 Feb 2007
    6.4
    Medium

    CVE-2007-0697

    Last Modified: 23 Apr 2026

    index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. NOTE: some of these details are obtained from third party information.

    Source:ajann
    Published:3 Feb 2007
    4.3
    Medium

    CVE-2007-0694

    Last Modified: 7 Dec 2013

    Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.

    Source:Jesper Jurcenoks
    Published:30 May 2007
    6.8
    Medium

    CVE-2007-0693

    Last Modified: 7 Dec 2013

    SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).

    Source:Jesper Jurcenoks
    Published:30 May 2007
    7.5
    High

    CVE-2007-0688

    Last Modified: 27 Sept 2016

    SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:cl24zy
    Published:3 Feb 2007
    6.5
    Medium

    CVE-2007-0687

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.

    Source:Codebreak
    Published:3 Feb 2007
    7.1
    High

    CVE-2007-0686

    Last Modified: 28 Apr 2011

    The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different vulnerability than CVE-2006-6651. NOTE: this issue might overlap CVE-2006-3992.

    Source:Breno Silva Pinto
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0684

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0683

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0682

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the galleryfilesdir parameter.

    Source:ThE dE@Th
    Published:3 Feb 2007
    9.8
    Critical

    CVE-2007-0681

    Last Modified: 27 Sept 2016

    profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, via modified values to register.php.

    Source:ajann
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0680

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0679

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fichier parameter.

    Source:ajann
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0678

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrary SQL commands via the kategori_id parameter.

    Source:cl24zy
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0677

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter.

    Source:y3dips
    Published:3 Feb 2007
    6.8
    Medium

    CVE-2007-0676

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:3 Feb 2007
    7.5
    High

    CVE-2007-0663

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Source:ajann
    Published:1 Feb 2007
    7.5
    High

    CVE-2007-0662

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:1 Feb 2007
    7.5
    High

    CVE-2007-0656

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in includes/functions.php in phpBB2-MODificat 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:1 Feb 2007
    4.3
    Medium

    CVE-2007-0649

    Last Modified: 13 Nov 2013

    Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via the srcdir parameter in custom/import_xml.php or (b) cross-site scripting (XSS) attacks via the rootdir parameter in interface/login/login_frame.php, via vectors associated with extract operations on the (1) POST and (2) GET superglobal arrays. NOTE: this issue was originally disputed before the extract behavior was identified in post-disclosure analysis. Also, the original report identified "Open Conference Systems," but this was an error.

    Source:trzindan
    Published:1 Feb 2007
    7.1
    High

    CVE-2007-0647

    Last Modified: 13 Nov 2013

    Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSBeginAlertSheet Apple AppKit function.

    Source:LMH
    Published:1 Feb 2007
    7.1
    High

    CVE-2007-0646

    Last Modified: 13 Nov 2013

    Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.

    Source:LMH
    Published:1 Feb 2007
    6.8
    Medium

    CVE-2007-0645

    Last Modified: 13 Nov 2013

    Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling certain Apple AppKit functions.

    Source:LMH
    Published:1 Feb 2007
    7.1
    High

    CVE-2007-0644

    Last Modified: 13 Nov 2013

    Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAlertSheet Apple AppKit functions.

    Source:LMH
    Published:1 Feb 2007
    4.3
    Medium

    CVE-2007-0643

    Last Modified: 28 Sept 2016

    Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.

    Source:shinnai
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0641

    Last Modified: 11 Nov 2013

    Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444.

    Source:Andres Tarasco Acuna
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0639

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].

    Source:rgod
    Published:31 Jan 2007
    5
    Medium

    CVE-2007-0638

    Last Modified: 14 Dec 2016

    show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.

    Source:ajann
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0637

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the galeria parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by zd_numer.php.

    Source:ajann
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0635

    Last Modified: 11 Nov 2013

    Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) config[path] parameter to (a) common_foot.php or (b) blogs.php, or (2) the config[theme] parameter to (c) admin/gallery_head.php.

    Source:Tr_ZiNDaN
    Published:31 Jan 2007
    7.8
    High

    CVE-2007-0634

    Last Modified: 11 Nov 2013

    Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.

    Source:kcope
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0633

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.

    Source:GoLd_M
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0631

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:ajann
    Published:31 Jan 2007
    7.5
    High

    CVE-2007-0623

    Last Modified: 11 Nov 2013

    SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL commands via the startrow parameter.

    Source:adexior
    Published:31 Jan 2007
    5
    Medium

    CVE-2007-0620

    Last Modified: 27 Oct 2016

    download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root with certain extensions, including .php, via a relative pathname in the fname parameter, as demonstrated by downloading config.php.

    Source:ajann
    Published:31 Jan 2007
    7.8
    High

    CVE-2007-0614

    Last Modified: 23 Apr 2026

    The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

    Source:MoAB
    Published:31 Jan 2007
    5
    Medium

    CVE-2007-0613

    Last Modified: 23 Apr 2026

    The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.

    Source:MoAB
    Published:31 Jan 2007
    7.8
    High

    CVE-2007-0612

    Last Modified: 11 Nov 2013

    Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1) giffile, (2) htmlfile, (3) jpegfile, (4) mhtmlfile, (5) ODCfile, (6) pjpegfile, (7) pngfile, (8) xbmfile, (9) xmlfile, (10) xslfile, or (11) wdfile objects in (a) mshtml.dll; or the (12) TriEditDocument.TriEditDocument or (13) TriEditDocument.TriEditDocument.1 objects in (b) triedit.dll, which cause a NULL pointer dereference.

    Source:Alexander Sotirov
    Published:31 Jan 2007