2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2007-3503The Javadoc tool in Sun JDK 6 and JDK 5.0 Update 11 can generate HTML documentation pages that contain cross-site script...
CVE-2007-3502Unspecified vulnerability in the web-based product configuration system in Kaspersky Anti-Spam before 3.0 MP1 allows rem...
CVE-2007-3501Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to ...
CVE-2007-2801Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is e...
CVE-2007-3504Directory traversal vulnerability in the PersistenceService in Sun Java Web Start in JDK and JRE 5.0 Update 11 and earli...
CVE-2007-3490Unspecified vulnerability in Microsoft Excel 2003 SP2 allows remote attackers to have an unknown impact via unspecified ...
CVE-2007-3491Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attack...
CVE-2007-3492Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string c...
CVE-2007-3493A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienz...
CVE-2007-3494Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, ...
CVE-2007-3495Multiple cross-site scripting (XSS) vulnerabilities in the SAP Internet Communication Framework (BC-MID-ICF) in the SAP ...
CVE-2007-3496Cross-site scripting (XSS) vulnerability in SAP Web Dynpro Java (BC-WD-JAV) in SAP NetWeaver Nw04 SP15 through SP19 and ...
CVE-2007-3497Microsoft Internet Explorer 7 allows remote attackers to determine the existence of page history via the history.length ...
CVE-2007-3498Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attack...
CVE-2007-3499SlackRoll before 8 accepts gpg exit codes other than 0 and 1 as evidence of a valid signature, which allows remote Slack...
CVE-2007-3500Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.
CVE-2007-3378The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlie...
CVE-2007-3487Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi...
CVE-2007-3488Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5...
CVE-2007-3489Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X...
CVE-2007-3483Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of...
CVE-2007-3485Multiple cross-site scripting (XSS) vulnerabilities in Yandex.Server allow remote attackers to inject arbitrary web scri...
CVE-2007-3486Cross-site scripting (XSS) vulnerability in AltaVista search engine allows remote attackers to inject arbitrary web scri...
CVE-2007-3472Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assiste...
CVE-2007-3480PCSoft WinDEV 11 (01F110053p) allows user-assisted remote attackers to cause a denial of service (infinite loop and reso...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now