2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-2425 | — | — | 7.8% | May 2, 2007 | Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a... |
| CVE-2007-2431 | — | — | 5.1% | May 2, 2007 | Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at... |
| CVE-2007-2424 | — | — | 9.9% | May 2, 2007 | PHP remote file inclusion vulnerability in help/index.php in The Merchant (themerchant) 2.2 allows remote attackers to e... |
| CVE-2007-2420 | — | — | 3.1% | May 2, 2007 | SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL command... |
| CVE-2007-2421 | — | — | 4.3% | May 2, 2007 | Buffer overflow in Hitachi Groupmax Mobile Option for Mobile-Phone 07-00 through 07-30, 5 for i-mode 05-11 through 05-23... |
| CVE-2007-2430 | — | — | 3.7% | May 2, 2007 | shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by... |
| CVE-2007-2412 | — | — | 1.7% | May 1, 2007 | Directory traversal vulnerability in modules/file.php in Seir Anphin allows remote attackers to obtain sensitive informa... |
| CVE-2007-2413 | — | — | — | May 1, 2007 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-2459. Reason: This candidate is a duplicate of... |
| CVE-2007-2411 | — | — | 2.7% | May 1, 2007 | PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP c... |
| CVE-2007-2414 | — | — | 2.9% | May 1, 2007 | MyServer before 0.8.8 allows remote attackers to cause a denial of service via unspecified vectors. |
| CVE-2007-2415 | — | — | 2.2% | May 1, 2007 | Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOT... |
| CVE-2007-2416 | — | — | 3.2% | May 1, 2007 | SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a pa... |
| CVE-2007-2381 | — | — | 1.6% | Apr 30, 2007 | The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, w... |
| CVE-2007-2382 | — | — | 1.6% | Apr 30, 2007 | The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, whi... |
| CVE-2007-2383 | — | — | 2.4% | Apr 30, 2007 | The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an... |
| CVE-2007-2384 | — | — | 1.3% | Apr 30, 2007 | The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection sc... |
| CVE-2007-2372 | — | — | 8.2% | Apr 30, 2007 | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit... |
| CVE-2007-2385 | — | — | 1.1% | Apr 30, 2007 | The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, ... |
| CVE-2007-2367 | — | — | 3.7% | Apr 30, 2007 | Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of ser... |
| CVE-2007-2373 | — | — | 3.7% | Apr 30, 2007 | SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att... |
| CVE-2007-2374 | — | — | 17.4% | Apr 30, 2007 | Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execut... |
| CVE-2007-2375 | — | — | 5.6% | Apr 30, 2007 | The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the aut... |
| CVE-2007-2376 | — | — | 1.6% | Apr 30, 2007 | The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which... |
| CVE-2007-2377 | — | — | 1.9% | Apr 30, 2007 | The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an... |
| CVE-2007-2378 | — | — | 0.7% | Apr 30, 2007 | The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated prot... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now