2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-6283 | — | — | 0.4% | Dec 18, 2007 | Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows ... |
| CVE-2007-6418 | — | — | 0.3% | Dec 18, 2007 | The libdspam7-drv-mysql cron job in Debian GNU/Linux includes the MySQL dspam database password in a command line argume... |
| CVE-2007-6417 | — | — | 0.4% | Dec 18, 2007 | The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory i... |
| CVE-2007-6413 | — | — | 3.3% | Dec 17, 2007 | Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attacker... |
| CVE-2007-6414 | — | — | 4.2% | Dec 17, 2007 | admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which all... |
| CVE-2007-6416 | — | — | 0.4% | Dec 17, 2007 | The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, al... |
| CVE-2007-4473 | — | — | 5.7% | Dec 17, 2007 | Gesytec Easylon OPC Server before 2.3.44 does not properly validate server handles, which allows remote attackers to exe... |
| CVE-2007-6389 | — | — | 0.4% | Dec 17, 2007 | The notify feature in GNOME screensaver (gnome-screensaver) 2.20.0 might allow local users to read the clipboard content... |
| CVE-2007-6390 | — | — | 0.5% | Dec 17, 2007 | Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attac... |
| CVE-2007-6391 | — | — | 1.0% | Dec 17, 2007 | SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman... |
| CVE-2007-6392 | — | — | 1.0% | Dec 17, 2007 | SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2007-6393 | — | — | 0.9% | Dec 17, 2007 | SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit... |
| CVE-2007-6394 | — | — | 1.0% | Dec 17, 2007 | SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL comma... |
| CVE-2007-6395 | — | — | 6.2% | Dec 17, 2007 | Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which a... |
| CVE-2007-6396 | — | — | 2.4% | Dec 17, 2007 | Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj... |
| CVE-2007-6397 | — | — | 2.8% | Dec 17, 2007 | Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1... |
| CVE-2007-6398 | — | — | 2.4% | Dec 17, 2007 | Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrar... |
| CVE-2007-6399 | — | — | 2.1% | Dec 17, 2007 | index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current use... |
| CVE-2007-6400 | — | — | 2.8% | Dec 17, 2007 | Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read ar... |
| CVE-2007-6401 | — | — | 29.7% | Dec 17, 2007 | Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 o... |
| CVE-2007-6402 | — | — | 5.8% | Dec 17, 2007 | Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 ... |
| CVE-2007-6403 | — | — | 3.4% | Dec 17, 2007 | Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via ... |
| CVE-2007-6404 | — | — | 2.7% | Dec 17, 2007 | Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attac... |
| CVE-2007-6405 | — | — | 2.7% | Dec 17, 2007 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI progra... |
| CVE-2007-6406 | — | — | 1.9% | Dec 17, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in CA (formerly Computer Associates) eTrust Threat Management Consol... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now