2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-1603admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new conte...
CVE-2007-1604Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute ar...
CVE-2007-1606Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we...
CVE-2007-1607search.php in w-Agora (Web-Agora) allows remote attackers to obtain potentially sensitive information via a ' (quote) va...
CVE-2007-1608CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject...
CVE-2007-1609Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Serve...
CVE-2007-1610Cross-site scripting (XSS) vulnerability in the RSS reader in Glue Software NewsGlue before 1.3.4 allows remote attacker...
CVE-2007-1611Cross-site scripting (XSS) vulnerability in the RSS reader in a certain SOURCENEXT product, probably IKANARI JIJYOU 1.0....
CVE-2007-1592net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TC...
CVE-2007-1591VsapiNT.sys in the Scan Engine 8.0 for Trend Micro AntiVirus 14.10.1041, and other products, allows remote attackers to ...
CVE-2007-0240Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web scri...
CVE-2007-1587templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by spec...
CVE-2007-1588server.cpp in MyServer 0.8.5 calls Process::setuid before calling Process::setgid and thus does not properly drop privil...
CVE-2007-1589TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem u...
CVE-2007-1590The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a...
CVE-2007-1582The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb...
CVE-2007-1581The resource system in PHP 5.0.0 through 5.2.1 allows context-dependent attackers to execute arbitrary code by interrupt...
CVE-2007-1580FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive ...
CVE-2007-1579Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC...
CVE-2007-1578Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a...
CVE-2007-1577Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary lo...
CVE-2007-1584Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas...
CVE-2007-1585The Linksys WAG200G with firmware 1.01.01, WRT54GC 2 with firmware 1.00.7, and WRT54GC 1 with firmware 1.03.0 and earlie...
CVE-2007-1586ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via ...
CVE-2007-1583The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now