2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-1188WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2)...
CVE-2007-1187WebAPP before 0.9.9.5 allows remote authenticated users, without admin privileges, to obtain sensitive information via (...
CVE-2007-1185The (1) Search, (2) Edit Profile, (3) Recommend, and (4) User Approval forms in WebAPP before 0.9.9.5 use hidden inputs,...
CVE-2007-1184The default configuration of WebAPP before 0.9.9.5 has a CAPTCHA setting of "no," which makes it easier for automated pr...
CVE-2007-1183WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unkn...
CVE-2007-1182WebAPP before 0.9.9.5 allows remote Guest users to edit a Guest profile, which has unknown impact.
CVE-2007-1181WebAPP before 0.9.9.5 passes (1) Unused Informations and (2) the username through Edit Profile forms, which has unknown ...
CVE-2007-1186WebAPP before 0.9.9.5 does not "censor" the Latest Member real name, which has unknown impact.
CVE-2007-1218Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 ...
CVE-2007-1217Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-ut...
CVE-2007-1198Cross-site scripting (XSS) vulnerability in TaskFreak! before 0.5.7 allows remote attackers to inject arbitrary web scri...
CVE-2007-1197Multiple unspecified vulnerabilities in Epiware before 4.7.5 have unknown impact and attack vectors, possibly related to...
CVE-2007-1196Unspecified vulnerability in Citrix Presentation Server Client for Windows before 10.0 allows remote web sites to execut...
CVE-2007-1195Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp...
CVE-2007-1194Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local u...
CVE-2007-1193Multiple unspecified vulnerabilities in the Login page in OrangeHRM before 20070212 have unknown impact and attack vecto...
CVE-2007-1192Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access con...
CVE-2007-1191The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library...
CVE-2007-1190Unspecified vulnerability in the EmbeddedWB Web Browser ActiveX control allows remote attackers to execute arbitrary cod...
CVE-2007-1161Cross-site scripting (XSS) vulnerability in call_entry.php in Call Center Software 0,93 allows remote attackers to injec...
CVE-2007-1160webSPELL 4.0, and possibly later versions, allows remote attackers to bypass authentication via a ws_auth cookie, a diff...
CVE-2007-1159Cross-site scripting (XSS) vulnerability in modules/out.php in Pyrophobia 2.1.3.1 allows remote attackers to inject arbi...
CVE-2007-1158Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows r...
CVE-2007-1157Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform p...
CVE-2007-1156JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct re...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now