2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-2308Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web scrip...
CVE-2007-2309Cross-site scripting (XSS) vulnerability in cas.php in FloweRS 2.0 allows remote attackers to inject arbitrary web scrip...
CVE-2007-2319PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to e...
CVE-2007-2320SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL co...
CVE-2007-2306Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke,...
CVE-2007-2316Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to ...
CVE-2007-2310Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to in...
CVE-2007-2311PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbi...
CVE-2007-2312Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to...
CVE-2007-2313PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers ...
CVE-2007-2314Multiple SQL injection vulnerabilities in Crea-Book 1.0, and possibly earlier, when magic_quotes_gpc is disabled, allow ...
CVE-2007-2315MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a fl...
CVE-2007-2298Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbit...
CVE-2007-2299Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL com...
CVE-2007-2300Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebne...
CVE-2007-2318Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via f...
CVE-2007-2296Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows r...
CVE-2007-1683Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.d...
CVE-2007-2295Heap-based buffer overflow in the JVTCompEncodeFrame function in Apple Quicktime 7.1.5 and other versions before 7.2 all...
CVE-2007-2294The Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of serv...
CVE-2007-2293Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in As...
CVE-2007-2292CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey befor...
CVE-2007-2291CRLF injection vulnerability in the Digest Authentication support for Microsoft Internet Explorer 7.0.5730.11 allows rem...
CVE-2007-2297The SIP channel driver (chan_sip) in Asterisk before 1.2.18 and 1.4.x before 1.4.3 does not properly parse SIP UDP packe...
CVE-2007-2289PHP remote file inclusion vulnerability in admin/includes/spaw/dialogs/insert_link.php in download engine (Download-Engi...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now