2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-6275 | — | — | 0.9% | Dec 7, 2007 | SQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to exec... |
| CVE-2007-6276 | — | — | 9.1% | Dec 7, 2007 | The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows... |
| CVE-2007-6277 | — | — | 6.7% | Dec 7, 2007 | Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers ... |
| CVE-2007-6278 | — | — | 2.1% | Dec 7, 2007 | Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to downloa... |
| CVE-2007-6279 | — | — | 4.0% | Dec 7, 2007 | Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote... |
| CVE-2007-5938 | — | — | 2.1% | Dec 6, 2007 | The iwl_set_rate function in compatible/iwl3945-base.c in iwlwifi 1.1.21 and earlier dereferences an iwl_get_hw_mode ret... |
| CVE-2007-5939 | — | — | 3.8% | Dec 6, 2007 | The gss_userok function in appl/ftp/ftpd/gss_userok.c in Heimdal 0.7.2 does not allocate memory for the ticketfile point... |
| CVE-2007-5769 | — | — | 1.7% | Dec 6, 2007 | Double free vulnerability in the getreply function in ftp.c in netkit ftp (netkit-ftp) 0.17 20040614 and later allows re... |
| CVE-2007-6263 | — | — | 2.5% | Dec 6, 2007 | The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been i... |
| CVE-2007-5902 | — | — | 5.9% | Dec 6, 2007 | Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows rem... |
| CVE-2007-5901 | — | — | 0.5% | Dec 6, 2007 | Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 ... |
| CVE-2007-5894 | — | — | 2.7% | Dec 6, 2007 | The reply function in ftpd.c in the gssftp ftpd in MIT Kerberos 5 (krb5) does not initialize the length variable when au... |
| CVE-2007-4575 | — | — | 14.3% | Dec 6, 2007 | HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute ... |
| CVE-2007-6194 | — | — | 4.4% | Dec 6, 2007 | Unspecified vulnerability in HP Select Identity 4.01 before 4.01.012 and 4.1x before 4.13.003 allows remote attackers to... |
| CVE-2007-5972 | — | — | 2.7% | Dec 6, 2007 | Double free vulnerability in the krb5_def_store_mkey function in lib/kdb/kdb_default.c in MIT Kerberos 5 (krb5) 1.5 has ... |
| CVE-2007-5971 | — | — | 0.4% | Dec 6, 2007 | Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5... |
| CVE-2007-6260 | — | — | 1.4% | Dec 6, 2007 | The installation process for Oracle 10g and llg uses accounts with default passwords, which allows remote attackers to o... |
| CVE-2007-6261 | — | — | 0.8% | Dec 6, 2007 | Integer overflow in the load_threadstack function in the Mach-O loader (mach_loader.c) in the xnu kernel in Apple Mac OS... |
| CVE-2007-6262 | — | — | 11.1% | Dec 6, 2007 | A certain ActiveX control in axvlc.dll in VideoLAN VLC 0.8.6 before 0.8.6d allows remote attackers to execute arbitrary ... |
| CVE-2007-5614 | — | — | 4.0% | Dec 5, 2007 | Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows... |
| CVE-2007-6014 | — | — | 1.3% | Dec 5, 2007 | SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary ... |
| CVE-2007-5613 | — | — | 2.9% | Dec 5, 2007 | Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inj... |
| CVE-2007-5355 | — | — | 16.6% | Dec 5, 2007 | The Web Proxy Auto-Discovery (WPAD) feature in Microsoft Internet Explorer 6 and 7, when a primary DNS suffix with three... |
| CVE-2007-5615 | — | — | 3.6% | Dec 5, 2007 | CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers a... |
| CVE-2007-6240 | — | — | 1.0% | Dec 5, 2007 | SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL c... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now