2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-5620——Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to inclu...
CVE-2007-5617——Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and...
CVE-2007-5618——Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 a...
CVE-2007-5619——Unspecified vulnerability in VMware Server before 1.0.4 causes user passwords to be recorded in cleartext in server logs...
CVE-2007-5334——Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup lang...
CVE-2007-5337——Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might a...
CVE-2007-5338——Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with us...
CVE-2007-5340——Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and Sea...
CVE-2007-5339——Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow...
CVE-2007-5601——Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and e...
CVE-2007-5379——Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers and ActiveResource servers to determine the exist...
CVE-2007-5380——Session fixation vulnerability in Rails before 1.2.4, as used for Ruby on Rails, allows remote attackers to hijack web s...
CVE-2007-5588——Cross-site scripting (XSS) vulnerability in mnoGoSearch before 3.2.43 allows remote attackers to inject arbitrary web sc...
CVE-2007-5589——Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.11.1.2 allow remote attackers to inject arbit...
CVE-2007-5590——Multiple buffer overflows in Miranda before 0.7.1 allow remote attackers to execute arbitrary code via unspecified vecto...
CVE-2007-5591——The CS1000 signaling server in Nortel Enterprise VoIP-Core-CS 1000M Chassis/Cabinet, Enterprise VoIP-Core-CS 1000E and 1...
CVE-2007-5592——Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arb...
CVE-2007-5593——install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to e...
CVE-2007-5594——Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote...
CVE-2007-5595——CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before...
CVE-2007-5596——The core Upload module in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 places the .html extension on a whitelist, which ...
CVE-2007-5597——The hook_comments API in Drupal 4.7.x before 4.7.8 and 5.x before 5.3 does not pass publication status, which might allo...
CVE-2007-5598——Cross-site scripting (XSS) vulnerability in Weblinks for Drupal 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.8 allows rem...
CVE-2007-5599——Multiple PHP remote file inclusion vulnerabilities in awrate 1.0 allow remote attackers to execute arbitrary PHP code vi...
CVE-2007-5600——Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbit...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now