2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4373The server in Babo Violent 2 2.08.00 and earlier does not properly implement password protection, which might allow remo...
CVE-2007-4374Babo Violent 2 2.08.00 does not validate the sender field of a chat message composed by a client, which allows remote au...
CVE-2007-4376Unrestricted file upload vulnerability in banner-upload.php in Szymon Kosok Best Top List allows remote attackers to upl...
CVE-2007-4377Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary ...
CVE-2007-4378Multiple format string vulnerabilities in Babo Violent 2 2.08.00 and earlier allow remote attackers to execute arbitrary...
CVE-2007-4091Multiple off-by-one errors in the sender.c in rsync 2.6.9 might allow remote attackers to execute arbitrary code via dir...
CVE-2007-4367Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual func...
CVE-2007-4371Unrestricted file upload vulnerability in admin/pages/blog-add.php in Neuron Blog 1.1 allows remote attackers to upload ...
CVE-2007-4368SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack...
CVE-2007-4369Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files ...
CVE-2007-4370Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit...
CVE-2007-4278Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attacke...
CVE-2007-4366WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co...
CVE-2007-4358Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (ak...
CVE-2007-4359Multiple SQL injection vulnerabilities in SkilMatch Staffing Systems JobLister3 allow remote attackers to execute arbitr...
CVE-2007-4365Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web s...
CVE-2007-4360Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to...
CVE-2007-4361NETGEAR (formerly Infrant) ReadyNAS RAIDiator before 4.00b2-p2-T1 beta creates a default SSH root password derived from ...
CVE-2007-4362SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command...
CVE-2007-4363Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK)...
CVE-2007-4364Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory...
CVE-2007-2240The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly...
CVE-2007-2929The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly...
CVE-2007-2928Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller....
CVE-2007-0319Multiple stack-based buffer overflows in the Motive ActiveEmailTest.EmailData (ActiveUtils EmailData) ActiveX control in...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now