2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-2378The Google Web Toolkit (GWT) framework exchanges data using JavaScript Object Notation (JSON) without an associated prot...
CVE-2007-2377The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an...
CVE-2007-2376The Dojo framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which...
CVE-2007-2375The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the aut...
CVE-2007-2374Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execut...
CVE-2007-2373SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att...
CVE-2007-2372admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit...
CVE-2007-2371admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification...
CVE-2007-2370SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers...
CVE-2007-2369Directory traversal vulnerability in picture.php in WebSPELL 4.01.02 and earlier, when PHP before 4.3.0 is used, allows ...
CVE-2007-2367Buffer overflow in wserve_console.exe in Wserve HTTP Server (whttp) 4.6 allows remote attackers to cause a denial of ser...
CVE-2007-2368picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
CVE-2007-2383The Prototype (prototypejs) framework before 1.5.1 RC3 exchanges data using JavaScript Object Notation (JSON) without an...
CVE-2007-2384The Script.aculo.us framework exchanges data using JavaScript Object Notation (JSON) without an associated protection sc...
CVE-2007-2385The Yahoo! UI framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, ...
CVE-2007-2382The Moo.fx framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, whi...
CVE-2007-2381The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, w...
CVE-2007-2354Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing ...
CVE-2007-2055AFFLIB 2.2.8 and earlier allows attackers to execute arbitrary commands via shell metacharacters involving (1) certain c...
CVE-2007-2029File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service ...
CVE-2007-2053Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash)...
CVE-2007-2054Multiple format string vulnerabilities in AFFLIB before 2.2.6 allow remote attackers to execute arbitrary code via certa...
CVE-2007-2366Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a craf...
CVE-2007-2365Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assist...
CVE-2007-2364Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now