2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-5620 | — | — | 6.3% | Oct 22, 2007 | Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to inclu... |
| CVE-2007-5617 | — | — | 2.2% | Oct 21, 2007 | Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and... |
| CVE-2007-5618 | — | — | 0.5% | Oct 21, 2007 | Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 a... |
| CVE-2007-5619 | — | — | 0.4% | Oct 21, 2007 | Unspecified vulnerability in VMware Server before 1.0.4 causes user passwords to be recorded in cleartext in server logs... |
| CVE-2007-5334 | — | — | 3.0% | Oct 21, 2007 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup lang... |
| CVE-2007-5337 | — | — | 2.4% | Oct 21, 2007 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might a... |
| CVE-2007-5338 | — | — | 3.2% | Oct 21, 2007 | Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with us... |
| CVE-2007-5340 | — | — | 3.4% | Oct 21, 2007 | Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and Sea... |
| CVE-2007-5339 | — | — | 3.4% | Oct 21, 2007 | Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow... |
| CVE-2007-5601 | — | — | 42.4% | Oct 20, 2007 | Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and e... |
| CVE-2007-5379 | — | — | 4.0% | Oct 19, 2007 | Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the exist... |
| CVE-2007-5380 | — | — | 3.6% | Oct 19, 2007 | Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web s... |
| CVE-2007-5588 | — | — | 1.1% | Oct 19, 2007 | Cross-site scripting (XSS) vulnerability in mnoGoSearch before 3.2.43 allows remote attackers to inject arbitrary web sc... |
| CVE-2007-5589 | — | — | 3.3% | Oct 19, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbit... |
| CVE-2007-5590 | — | — | 3.6% | Oct 19, 2007 | Multiple buffer overflows in Miranda before 0.7.1 allow remote attackers to execute arbitrary code via unspecified vecto... |
| CVE-2007-5591 | — | — | 2.3% | Oct 19, 2007 | The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1... |
| CVE-2007-5592 | — | — | 28.7% | Oct 19, 2007 | Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arb... |
| CVE-2007-5593 | — | — | 3.8% | Oct 19, 2007 | install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to e... |
| CVE-2007-5594 | — | — | 1.2% | Oct 19, 2007 | Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote... |
| CVE-2007-5595 | — | — | 2.0% | Oct 19, 2007 | CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before... |
| CVE-2007-5596 | — | — | 1.6% | Oct 19, 2007 | The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which ... |
| CVE-2007-5597 | — | — | 1.5% | Oct 19, 2007 | The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allo... |
| CVE-2007-5598 | — | — | 1.4% | Oct 19, 2007 | Cross-site scripting (XSS) vulnerability in Weblinks for Drupal 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.8 allows rem... |
| CVE-2007-5599 | — | — | 1.2% | Oct 19, 2007 | Multiple PHP remote file inclusion vulnerabilities in awrate 1.0 allow remote attackers to execute arbitrary PHP code vi... |
| CVE-2007-5600 | — | — | 1.9% | Oct 19, 2007 | Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbit... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now