2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2007-1159Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbi...
CVE-2007-1158Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows r...
CVE-2007-1157Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform p...
CVE-2007-1156JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct re...
CVE-2007-1155Unrestricted file upload vulnerability in webSPELL allows remote authenticated administrators to upload and execute arbi...
CVE-2007-1154SQL injection vulnerability in webSPELL allows remote attackers to execute arbitrary SQL commands via a ws_auth cookie, ...
CVE-2007-1142Cross-site scripting (XSS) vulnerability in Magic News Plus 1.0.2 allows remote attackers to inject arbitrary web script...
CVE-2007-1153Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary...
CVE-2007-0001The file watch implementation in the audit subsystem (auditctl -w) in the Red Hat Enterprise Linux (RHEL) 4 kernel 2.6.9...
CVE-2007-1005Heap-based buffer overflow in SW3eng.exe in the eID Engine service in CA (formerly Computer Associates) eTrust Intrusion...
CVE-2007-1199Adobe Reader and Acrobat Trial allow remote attackers to read arbitrary files via a file:// URI in a PDF document, as de...
CVE-2007-1134Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized...
CVE-2007-1143Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary d...
CVE-2007-1144Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitra...
CVE-2007-1145Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite - ESupport 3.00.13 and 3.04.10 allow remote a...
CVE-2007-1186WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
CVE-2007-1187WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (...
CVE-2007-1188WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2)...
CVE-2007-1189Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite ...
CVE-2007-1190Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary cod...
CVE-2007-1191The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library...
CVE-2007-1192Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access con...
CVE-2007-1193Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vecto...
CVE-2007-1194Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local u...
CVE-2007-1195Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now