2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-1373Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers ...
CVE-2007-1374Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to injec...
CVE-2007-1375Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens...
CVE-2007-1377AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to caus...
CVE-2007-1378The ovrimos_longreadlen function in the Ovrimos extension for PHP before 4.4.5 allows context-dependent attackers to wri...
CVE-2007-1379The ovrimos_close function in the Ovrimos extension for PHP before 4.4.5 can trigger efree of an arbitrary address, whic...
CVE-2007-1380The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-...
CVE-2007-1381The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and...
CVE-2007-1382The PHP COM extensions for PHP on Windows systems allow context-dependent attackers to execute arbitrary code via a WScr...
CVE-2007-1368The Project issue tracking module before 4.7.x-1.3, 4.7.x-2.* before 4.7.x-2.3, and 5 before 5.x-0.2-beta for Drupal all...
CVE-2007-1369ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by ...
CVE-2007-1370Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to ...
CVE-2007-1367Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 ...
CVE-2007-1340PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execu...
CVE-2007-1338The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the...
CVE-2007-1361Cross-site scripting (XSS) vulnerability in virtuemart_parser.php in VirtueMart before 20070213 allows remote attackers ...
CVE-2007-1346Unspecified vulnerability in ipmitool for Sun Fire X2100M2 and X2200M2 allows local users to gain privileges and reset o...
CVE-2007-1359Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules ...
CVE-2007-1360Unspecified vulnerability in the Nodefamily module for Drupal 5.x before 5.x-1.0 allows remote authenticated users to ac...
CVE-2007-1344Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code vi...
CVE-2007-1343includes/functions.php in Craig Knudsen WebCalendar before 1.0.5 does not protect the noSet variable from external modif...
CVE-2007-1342Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attac...
CVE-2007-1341include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages ...
CVE-2007-1339SQL injection vulnerability in index.php in Links Management Application 1.0 allows remote attackers to execute arbitrar...
CVE-2007-1347Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remot...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now