2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-1652OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal informati...
CVE-2007-1651Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user...
CVE-2007-1650pcapsipdump.cpp in pcapsipdump before 0.1.3 allows remote attackers to cause a denial of service (application crash) via...
CVE-2007-1649PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a seriali...
CVE-2007-16480irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se...
CVE-2007-1647Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides ...
CVE-2007-1646Multiple cross-site scripting (XSS) vulnerabilities in SubHub 2.3.0 allow remote attackers to inject arbitrary web scrip...
CVE-2007-1645Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrar...
CVE-2007-1644The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients i...
CVE-2007-1643Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at...
CVE-2007-1639Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticate...
CVE-2007-1638Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProje...
CVE-2007-1641SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via...
CVE-2007-1640Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr...
CVE-2007-1636Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files ...
CVE-2007-1634Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote...
CVE-2007-1637Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow...
CVE-2007-1635Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows re...
CVE-2007-1625Cross-site scripting (XSS) vulnerability in save_entry.php in realGuestbook 5.01 allows remote attackers to inject arbit...
CVE-2007-1633Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo...
CVE-2007-1632Unspecified vulnerability in TYPOlight webCMS before 2.2 Build 5 has unknown impact and attack vectors related to a "maj...
CVE-2007-1631PHP remote file inclusion vulnerability in signup.php in CLBOX 1.01 allows remote attackers to execute arbitrary PHP cod...
CVE-2007-1630SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a...
CVE-2007-1629SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute...
CVE-2007-1628Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globa...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now