2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-0636Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to wa...
CVE-2007-0635Multiple PHP remote file inclusion vulnerabilities in EncapsCMS 0.3.6 allow remote attackers to execute arbitrary PHP co...
CVE-2007-0634Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system...
CVE-2007-0629The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attac...
CVE-2007-0627Michael Still gtalkbot before 1.2 places username and password arguments on the command line, which allows local users t...
CVE-2007-0628Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 20...
CVE-2007-0623SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL command...
CVE-2007-0624user.php in MAXdev MDPro 1.0.76 allows remote attackers to obtain the full path via a ' (quote) character, and possibly ...
CVE-2007-0625nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to m...
CVE-2007-0622Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send mess...
CVE-2007-0626The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows...
CVE-2007-0633PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attack...
CVE-2007-0632SQL injection vulnerability in artreplydelete.asp in ASP EDGE 1.3a and earlier allows remote attackers to execute arbitr...
CVE-2007-0631SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe...
CVE-2007-0630Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and ear...
CVE-2007-0621Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-6456. Reason: This candidate is a duplicate of...
CVE-2007-0614The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allow...
CVE-2007-0612Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of se...
CVE-2007-0618Unspecified vulnerability in (1) pop3d, (2) pop3ds, (3) imapd, and (4) imapds in IBM AIX 5.3.0 has unspecified impact an...
CVE-2007-0617The SpamBlocker.dll ActiveX control in Earthlink TotalAccess is marked "safe for scripting," which allows remote attacke...
CVE-2007-0616Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to...
CVE-2007-0615Unspecified vulnerability in Hitachi JP1/HIBUN Advanced Edition Management Server and Log Server before 20070124 allows ...
CVE-2007-0613The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does ...
CVE-2007-0620download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root ...
CVE-2007-0619chmlib before 0.39 allows user-assisted remote attackers to execute arbitrary code via a crafted page block length in a ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now