2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4373——The server in Babo Violent 2 2.08.00 and earlier does not properly implement password protection, which might allow remo...
CVE-2007-4374——Babo Violent 2 2.08.00 does not validate the sender field of a chat message composed by a client, which allows remote au...
CVE-2007-4376——Unrestricted file upload vulnerability in banner-upload.php in Szymon Kosok Best Top List allows remote attackers to upl...
CVE-2007-4377——Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary ...
CVE-2007-4378——Multiple format string vulnerabilities in Babo Violent 2 2.08.00 and earlier allow remote attackers to execute arbitrary...
CVE-2007-4091——Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via dir...
CVE-2007-4367——Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual func...
CVE-2007-4371——Unrestricted file upload vulnerability in admin/pages/blog-add.php in Neuron Blog 1.1 allows remote attackers to upload ...
CVE-2007-4368——SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack...
CVE-2007-4369——Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files ...
CVE-2007-4370——Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit...
CVE-2007-4278——Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attacke...
CVE-2007-4366——WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co...
CVE-2007-4358——Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (ak...
CVE-2007-4359——Multiple SQL injection vulnerabilities in SkilMatch Staffing Systems JobLister3 allow remote attackers to execute arbitr...
CVE-2007-4365——Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web s...
CVE-2007-4360——Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to...
CVE-2007-4361——NETGEAR (formerly Infrant) ReadyNAS RAIDiator before 4.00b2-p2-T1 beta creates a default SSH root password derived from ...
CVE-2007-4362——SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command...
CVE-2007-4363——Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK)...
CVE-2007-4364——Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory...
CVE-2007-2240——The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly...
CVE-2007-2929——The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly...
CVE-2007-2928——Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller....
CVE-2007-0319——Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now