2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-6656 | — | — | 1.2% | Jan 4, 2008 | SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote... |
| CVE-2007-6655 | — | — | 2.8% | Jan 4, 2008 | PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to exec... |
| CVE-2007-6654 | — | — | 5.6% | Jan 4, 2008 | Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows ... |
| CVE-2007-6653 | — | — | 2.3% | Jan 4, 2008 | Directory traversal vulnerability in download.php in Mihalism Multi Host 2.0.7 allows remote attackers to read arbitrary... |
| CVE-2007-6652 | — | — | 4.2% | Jan 4, 2008 | cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers t... |
| CVE-2007-6650 | — | — | 2.9% | Jan 4, 2008 | Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbit... |
| CVE-2007-6649 | — | — | 6.0% | Jan 4, 2008 | PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to ... |
| CVE-2007-6648 | — | — | 5.5% | Jan 4, 2008 | Directory traversal vulnerability in index.php in SanyBee Gallery 0.1.0 and 0.1.1 allows remote attackers to include and... |
| CVE-2007-6647 | — | — | 1.0% | Jan 4, 2008 | SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL c... |
| CVE-2007-6651 | — | — | 3.7% | Jan 4, 2008 | Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote attackers to obtain sensitive infor... |
| CVE-2007-6598 | — | — | 2.0% | Jan 4, 2008 | Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LD... |
| CVE-2007-6599 | — | — | 1.7% | Jan 4, 2008 | Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a... |
| CVE-2007-6644 | — | — | 1.9% | Jan 4, 2008 | Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group,... |
| CVE-2007-6643 | — | — | 1.9% | Jan 4, 2008 | Cross-site scripting (XSS) vulnerability in the com_poll component in Joomla! before 1.5 RC4 allows remote attackers to ... |
| CVE-2007-6642 | — | — | 1.1% | Jan 4, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a... |
| CVE-2007-6641 | — | — | 1.7% | Jan 4, 2008 | Cross-site scripting (XSS) vulnerability in dir.php in milliscripts Redirection allows remote attackers to inject arbitr... |
| CVE-2007-6640 | — | — | 1.2% | Jan 4, 2008 | Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which... |
| CVE-2007-6639 | — | — | 1.0% | Jan 4, 2008 | SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL com... |
| CVE-2007-6645 | — | — | 2.5% | Jan 4, 2008 | Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified... |
| CVE-2007-6646 | — | — | 4.1% | Jan 4, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow r... |
| CVE-2007-6638 | — | — | 11.8% | Jan 4, 2008 | March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r... |
| CVE-2007-6637 | — | — | 4.9% | Jan 4, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player allow remote attackers to inject arbitrary web... |
| CVE-2007-6636 | — | — | 1.1% | Jan 4, 2008 | Unspecified vulnerability in the StorageFarabDb module in Bitflu before 0.42 allows user-assisted remote attackers to cr... |
| CVE-2007-6635 | — | — | 0.9% | Jan 4, 2008 | FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in cleartext in a database, which might allow context... |
| CVE-2007-6634 | — | — | 1.1% | Jan 4, 2008 | Multiple SQL injection vulnerabilities in FAQMasterFlexPlus, possibly 1.5 or 1.52, allow remote attackers to execute arb... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now