2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-1621 | — | — | 4.2% | Mar 23, 2007 | PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allow... |
| CVE-2007-1595 | — | — | 2.6% | Mar 22, 2007 | The Asterisk Extension Language (AEL) in pbx/pbx_ael.c in Asterisk does not properly generate extensions, which allows r... |
| CVE-2007-1611 | — | — | 1.0% | Mar 22, 2007 | Cross-site scripting (XSS) vulnerability in the RSS reader in a certain SOURCENEXT product, probably IKANARI JIJYOU 1.0.... |
| CVE-2007-1610 | — | — | 1.3% | Mar 22, 2007 | Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attacker... |
| CVE-2007-1609 | — | — | 1.3% | Mar 22, 2007 | Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Serve... |
| CVE-2007-1608 | — | — | 1.7% | Mar 22, 2007 | CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject... |
| CVE-2007-1607 | — | — | 2.3% | Mar 22, 2007 | search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) va... |
| CVE-2007-1606 | — | — | 2.0% | Mar 22, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we... |
| CVE-2007-1605 | — | — | 1.7% | Mar 22, 2007 | w-Agora (Web-Agora) allows remote attackers to obtain sensitive information via a request to rss.php with an invalid (1)... |
| CVE-2007-1604 | — | — | 3.0% | Mar 22, 2007 | Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute ar... |
| CVE-2007-1603 | — | — | 1.3% | Mar 22, 2007 | admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new conte... |
| CVE-2007-1602 | — | — | 1.0% | Mar 22, 2007 | SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitra... |
| CVE-2007-1601 | — | — | 1.4% | Mar 22, 2007 | Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbi... |
| CVE-2007-1600 | — | — | 3.5% | Mar 22, 2007 | PHP remote file inclusion vulnerability in module.php in Digital Eye Gallery 1.1 Beta (aka 0.1.1b) allows remote attacke... |
| CVE-2007-1599 | — | — | 1.9% | Mar 22, 2007 | wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obta... |
| CVE-2007-1598 | — | — | 3.1% | Mar 22, 2007 | Stack-based buffer overflow in InterVations FileCOPA FTP Server 1.01 allows remote attackers to execute arbitrary code v... |
| CVE-2007-1597 | — | — | 1.2% | Mar 22, 2007 | Unclassified NewsBoard 1.6.3 stores sensitive information under the web root with insufficient access control, which all... |
| CVE-2007-1596 | — | — | 7.8% | Mar 22, 2007 | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo... |
| CVE-2007-1594 | — | — | 2.6% | Mar 22, 2007 | The handle_response function in chan_sip.c in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to c... |
| CVE-2007-1591 | — | — | 2.5% | Mar 22, 2007 | VsapiNT.sys in the Scan Engine 8.0 for Trend Micro AntiVirus 14.10.1041, and other products, allows remote attackers to ... |
| CVE-2007-1592 | — | — | 0.4% | Mar 22, 2007 | net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TC... |
| CVE-2007-0240 | — | — | 1.6% | Mar 22, 2007 | Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web scri... |
| CVE-2007-1588 | — | — | 1.3% | Mar 21, 2007 | server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privil... |
| CVE-2007-1587 | — | — | 1.8% | Mar 21, 2007 | templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by spec... |
| CVE-2007-1586 | — | — | 3.1% | Mar 21, 2007 | ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via ... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now