2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-2745Cross-site scripting (XSS) vulnerability in printcal.pl in vDesk Webmail 4.03 allows remote attackers to inject arbitrar...
CVE-2007-2749SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar...
CVE-2007-2748The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information vi...
CVE-2007-2747Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary...
CVE-2007-2740Unspecified vulnerability in xajax before 0.2.5 has unknown impact and attack vectors, not related to XSS.
CVE-2007-2738SQL injection vulnerability in glossaire-p-f.php in the Glossaire 1.7 and earlier module for Xoops allows remote attacke...
CVE-2007-2741Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause ...
CVE-2007-2743PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra...
CVE-2007-2742Unrestricted file upload vulnerability in labs.beffa.org w2box 4.0.0 Beta4 allows remote attackers to upload arbitrary P...
CVE-2007-2744Stack-based buffer overflow in the PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll allows remote atta...
CVE-2007-2735SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers...
CVE-2007-2736PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c...
CVE-2007-2737SQL injection vulnerability in index.php in the MyConference 1.0 module for Xoops allows remote attackers to execute arb...
CVE-2007-2739Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or...
CVE-2007-2445The png_handle_tRNS function in pngrutil.c in libpng before 1.0.25 and 1.2.x before 1.2.17 allows remote attackers to ca...
CVE-2007-1898formmail.php in Jetbox CMS 2.1 allows remote attackers to send arbitrary e-mails (spam) via modified recipient, _SETTING...
CVE-2007-2722Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili...
CVE-2007-2724Cross-site scripting (XSS) vulnerability in all_photos.html in fotolog allows remote attackers to inject arbitrary web s...
CVE-2007-2725The DB Software Laboratory DeWizardX (DEWizardAX.ocx) ActiveX control allows remote attackers to overwrite arbitrary fil...
CVE-2007-2726BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with c...
CVE-2007-2727The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 vers...
CVE-2007-2728The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vect...
CVE-2007-2729Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do no...
CVE-2007-2734The 3Com TippingPoint IPS do not properly handle certain full-width and half-width Unicode character encodings in an HTT...
CVE-2007-2733Unrestricted file upload vulnerability in Jetbox CMS allows remote authenticated users with author privileges to upload ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now