2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-4906 | — | — | 38.4% | Sep 17, 2007 | PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e... |
| CVE-2007-4895 | — | — | 2.7% | Sep 14, 2007 | Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr... |
| CVE-2007-4901 | — | — | 2.8% | Sep 14, 2007 | The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lit... |
| CVE-2007-4894 | — | — | 3.6% | Sep 14, 2007 | Multiple SQL injection vulnerabilities in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a allow remot... |
| CVE-2007-4892 | — | — | 1.2% | Sep 14, 2007 | Multiple SQL injection vulnerabilities in SWSoft Plesk 7.6.1, 8.1.0, 8.1.1, and 8.2.0 for Windows allow remote attackers... |
| CVE-2007-4893 | — | — | 1.5% | Sep 14, 2007 | wp-admin/admin-functions.php in Wordpress before 2.2.3 and Wordpress multi-user (MU) before 1.2.5a does not properly ver... |
| CVE-2007-4896 | — | — | 1.7% | Sep 14, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in admin/header.php in Toms Gaestebuch 1.01 and earlier allow remote... |
| CVE-2007-4897 | — | — | 10.9% | Sep 14, 2007 | pwlib, as used by Ekiga 2.0.5 and possibly other products, allows remote attackers to cause a denial of service (applica... |
| CVE-2007-4898 | — | — | 0.9% | Sep 14, 2007 | Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, ... |
| CVE-2007-4899 | — | — | 1.5% | Sep 14, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject ... |
| CVE-2007-4900 | — | — | 1.3% | Sep 14, 2007 | Cross-site scripting (XSS) vulnerability in the logon page in RSA EnVision 3.3.6 Build 0115 allows remote attackers to i... |
| CVE-2007-3739 | — | — | 0.4% | Sep 14, 2007 | mm/mmap.c in the hugetlb kernel, when run on PowerPC systems, does not prevent stack expansion from entering into reserv... |
| CVE-2007-4138 | — | — | 0.7% | Sep 14, 2007 | The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind n... |
| CVE-2007-3740 | — | — | 0.4% | Sep 14, 2007 | The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask ... |
| CVE-2007-4891 | — | — | 31.0% | Sep 14, 2007 | A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) St... |
| CVE-2007-4889 | — | — | 1.2% | Sep 14, 2007 | The MySQL extension in PHP 5.2.4 and earlier allows remote attackers to bypass safe_mode and open_basedir restrictions v... |
| CVE-2007-4890 | — | — | 16.4% | Sep 14, 2007 | Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1... |
| CVE-2007-4465 | MEDIUM | 6.1 | 26.2% | Sep 14, 2007 | Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on ... |
| CVE-2007-1688 | — | — | 6.5% | Sep 14, 2007 | Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to ... |
| CVE-2007-4749 | — | — | 1.8% | Sep 14, 2007 | The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers ... |
| CVE-2007-4881 | — | — | 1.3% | Sep 14, 2007 | SQL injection vulnerability in profile/myprofile.php in psi-labs.com social networking script (psisns), probably 1.0, al... |
| CVE-2007-4882 | — | — | 1.0% | Sep 14, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in TechExcel CustomerWise (formerly TechExcel CRM) allow remote atta... |
| CVE-2007-4883 | — | — | 0.9% | Sep 14, 2007 | Cross-site scripting (XSS) vulnerability in the BotQuery extension in MediaWiki 1.7.x and earlier before SVN 20070910 al... |
| CVE-2007-4884 | — | — | 1.0% | Sep 14, 2007 | Media Player Classic (MPC) allows user-assisted remote attackers to cause a denial of service (application crash) via a ... |
| CVE-2007-4885 | — | — | 1.0% | Sep 14, 2007 | Avnex AV MP3 Player allows user-assisted remote attackers to cause a denial of service (application crash) via a malform... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now