2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-1234Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HT...
CVE-2007-1235Unrestricted file upload vulnerability in sitex allows remote attackers to upload arbitrary PHP code via an avatar filen...
CVE-2007-1236sitex allows remote attackers to obtain sensitive information via a request with a numerical value for the (1) sxMonth[]...
CVE-2007-1237sitex allows remote attackers to obtain potentially sensitive information via a ' (quote) value for certain parameters, ...
CVE-2007-1238Microsoft Office 2003 allows user-assisted remote attackers to cause a denial of service (application crash) by attempti...
CVE-2007-1239Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (app...
CVE-2007-1240Multiple cross-site scripting (XSS) vulnerabilities in Docebo CMS 3.0.3 through 3.0.5 allow remote attackers to inject a...
CVE-2007-1241Cross-site scripting (XSS) vulnerability in setup.php in Audins Audiens 3.3 allows remote attackers to inject arbitrary ...
CVE-2007-1243Audins Audiens 3.3 allows remote attackers to bypass authentication and perform certain privileged actions, possibly an ...
CVE-2007-1244Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers...
CVE-2007-1245IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.
CVE-2007-1246The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, ...
CVE-2007-1221The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of th...
CVE-2007-1220The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall ...
CVE-2007-1219PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arb...
CVE-2007-1229Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitra...
CVE-2007-1228IBM DB2 UDB 8.2 before Fixpak 7 (aka fixpack 14), and DB2 9 before Fix Pack 2, on UNIX allows the "fenced" user to acces...
CVE-2007-1227VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary...
CVE-2007-1230Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/functions.php in WordPress before 2.1.2-alpha allow r...
CVE-2007-1226McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/V...
CVE-2007-1225The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in ...
CVE-2007-1224Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from ...
CVE-2007-1223Unspecified vulnerability in Hitachi OSAS/FT/W before 20070223 allows attackers to cause a denial of service (responder ...
CVE-2007-1222Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf sha...
CVE-2007-1189Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now