2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-2713ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allo...
CVE-2007-2698The Administration Console in BEA WebLogic Server 9.0 may show plaintext Web Service attributes during configuration cre...
CVE-2007-2692The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privil...
CVE-2007-2688The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-wi...
CVE-2007-2689Check Point Web Intelligence does not properly handle certain full-width and half-width Unicode character encodings, whi...
CVE-2007-2690Multiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width ...
CVE-2007-2691MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE s...
CVE-2007-2693MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from par...
CVE-2007-2694Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 thr...
CVE-2007-2695The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7...
CVE-2007-2696The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access pol...
CVE-2007-2697The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, whe...
CVE-2007-2699The Administration Console in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not properly enforce certain Dom...
CVE-2007-2700The WLST script generated by the configToScript command in BEA WebLogic Express and WebLogic Server 9.0 and 9.1 does not...
CVE-2007-2701The JMS Message Bridge in BEA WebLogic Server 7.0 through SP7 and 8.1 through Service Pack 6, when configured without a ...
CVE-2007-2702Cross-site scripting (XSS) vulnerability in the GroupSpace application in BEA WebLogic Portal 9.2 GA allows remote authe...
CVE-2007-2703BEA WebLogic Portal 9.2 GA can corrupt a visitor entitlements role if an administrator provides a long role description,...
CVE-2007-2704BEA WebLogic Server 9.0 through 9.2 allows remote attackers to cause a denial of service (SSL port unavailability) by ac...
CVE-2007-2705Directory traversal vulnerability in the Test View Console in BEA WebLogic Integration 9.2 before SP1 and WebLogic Works...
CVE-2007-2683Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, w...
CVE-2007-2681Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute a...
CVE-2007-2680Cross-site scripting (XSS) vulnerability in the management interface in Canon Network Camera Server VB100 and VB101 with...
CVE-2007-2679PHP file inclusion vulnerability in index.php in Ivan Peevski gallery 0.3 in Simple PHP Scripts (sphp) allows remote att...
CVE-2007-2678Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execut...
CVE-2007-2673SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now