2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2007-4918SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL comma...
CVE-2007-4919Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the...
CVE-2007-4920SQL injection vulnerability in soporte_derecha_w.php in PHP Webquest 2.5 and earlier allows remote attackers to execute ...
CVE-2007-4921PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker...
CVE-2007-4922SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec...
CVE-2007-4923PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f...
CVE-2007-4908Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute...
CVE-2007-4902Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Co...
CVE-2007-4903Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allo...
CVE-2007-4907Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a ...
CVE-2007-4904RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other pl...
CVE-2007-4905Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar...
CVE-2007-4906PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e...
CVE-2007-4895Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr...
CVE-2007-4901The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lit...
CVE-2007-4894Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remot...
CVE-2007-4892Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers...
CVE-2007-4893wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly ver...
CVE-2007-4896Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote...
CVE-2007-4897pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (applica...
CVE-2007-4898Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, ...
CVE-2007-4899Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject ...
CVE-2007-4900Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to i...
CVE-2007-3739mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserv...
CVE-2007-4138The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind n...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now