2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4886——Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbit...
CVE-2007-4887——The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application cr...
CVE-2007-4888——The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire docume...
CVE-2007-4879——Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates w...
CVE-2007-4840——PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long...
CVE-2007-4849——JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enab...
CVE-2007-4841——Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execut...
CVE-2007-4842——Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP ...
CVE-2007-4843——Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to creat...
CVE-2007-4844——X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a "CW...
CVE-2007-4845——Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute ...
CVE-2007-4846——SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to ...
CVE-2007-4847——Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa://...
CVE-2007-4848——Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have as...
CVE-2007-3871——Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of serv...
CVE-2007-4727——Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd bef...
CVE-2007-4832——Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code ...
CVE-2007-4838——Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via...
CVE-2007-4839——Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6....
CVE-2007-4828——Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through...
CVE-2007-4830——Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote atta...
CVE-2007-4831——Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers...
CVE-2007-4833——Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0....
CVE-2007-4834——Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP cod...
CVE-2007-4835——SQL injection vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to execute arbitrary SQL commands vi...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now