2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-3577PHPIDS before 20070703 does not properly handle use of the substr method in (1) document.location.search and (2) documen...
CVE-2007-3578PHPIDS before 20070703 does not properly handle (1) arithmetic expressions and (2) unclosed comments, which allows remot...
CVE-2007-3579PHPIDS before 20070703 does not properly handle setting the .text property of a SCRIPT element before its attachment to ...
CVE-2007-3580PHPIDS does not properly handle certain code containing newlines, as demonstrated by a try/catch block within a loop, wh...
CVE-2007-3581The Jedox Palo 1.5 client transmits the password in cleartext, which might allow remote attackers to obtain the password...
CVE-2007-3582SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitr...
CVE-2007-3583SQL injection vulnerability in details_news.php in Girlserv ads 1.5 and earlier allows remote attackers to execute arbit...
CVE-2007-3584SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execut...
CVE-2007-3585PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbit...
CVE-2007-3586Multiple direct static code injection vulnerabilities in MyCMS 0.9.8 and earlier allow remote attackers to inject arbitr...
CVE-2007-3011The DBAsciiAccess CGI Script in the web interface in Fujitsu-Siemens Computers ServerView before 4.50.09 allows remote a...
CVE-2007-3012The web interface in Fujitsu-Siemens Computers PRIMERGY BX300 Switch Blade allows remote attackers to obtain sensitive i...
CVE-2007-3571The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive informatio...
CVE-2007-3567MySQLDumper 1.21b through 1.23 REV227 uses a "Limit GET" statement in the .htaccess authentication mechanism, which allo...
CVE-2007-3568The _LoadBMP function in imlib 1.9.15 and earlier allows context-dependent attackers to cause a denial of service (infin...
CVE-2007-3569Multiple cross-site scripting (XSS) vulnerabilities in Oliver Library Management System allow remote attackers to inject...
CVE-2007-3570The Linux Access Gateway in Novell Access Manager before 3.0 SP1 Release Candidate 1 (RC1) allows remote attackers to by...
CVE-2007-3560Multiple unspecified vulnerabilities in Esqlanelapse before 2.6 have unknown impact and attack vectors.
CVE-2007-3561Cross-site scripting (XSS) vulnerability in ara.asp in Efendy Blog 1.0 allows remote attackers to inject arbitrary web s...
CVE-2007-3557SQL injection vulnerability in admin/login.php in Wheatblog (wB) 1.1, when magic_quotes_gpc is disabled, allows remote a...
CVE-2007-3562SQL injection vulnerability in videos.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary ...
CVE-2007-3558SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary...
CVE-2007-3559Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9...
CVE-2007-3563SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL...
CVE-2007-2949Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now