2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2007-2425Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a...
CVE-2007-2431Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at...
CVE-2007-2424PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to e...
CVE-2007-2420SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL command...
CVE-2007-2421Buffer overflow in Hitachi Groupmax Mobile Option for Mobile-Phone 07-00 through 07-30, 5 for i-mode 05-11 through 05-23...
CVE-2007-2430shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by...
CVE-2007-2412Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive informa...
CVE-2007-2413Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2459. Reason: This candidate is a duplicate of...
CVE-2007-2411PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP c...
CVE-2007-2414MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2007-2415Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOT...
CVE-2007-2416SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a pa...
CVE-2007-2381The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, w...
CVE-2007-2382The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, whi...
CVE-2007-2383The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an...
CVE-2007-2384The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection sc...
CVE-2007-2372admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit...
CVE-2007-2385The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, ...
CVE-2007-2367Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of ser...
CVE-2007-2373SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att...
CVE-2007-2374Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execut...
CVE-2007-2375The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the aut...
CVE-2007-2376The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which...
CVE-2007-2377The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an...
CVE-2007-2378The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated prot...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now