2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4886Incomplete blacklist vulnerability in index.php in AuraCMS 1.x and probably 2.x allows remote attackers to execute arbit...
CVE-2007-4887The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application cr...
CVE-2007-4888The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire docume...
CVE-2007-4879Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates w...
CVE-2007-4840PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long...
CVE-2007-4849JFFS2, as used on One Laptop Per Child (OLPC) build 542 and possibly other Linux systems, when POSIX ACL support is enab...
CVE-2007-4841Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execut...
CVE-2007-4842Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP ...
CVE-2007-4843Directory traversal vulnerability in X-Diesel Unreal Commander 0.92 build 565 and 573 allows remote FTP servers to creat...
CVE-2007-4844X-Diesel Unreal Commander 0.92 build 565 and 573 does not properly react to an FTP server's behavior after sending a "CW...
CVE-2007-4845Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute ...
CVE-2007-4846SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to ...
CVE-2007-4847Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa://...
CVE-2007-4848Microsoft Internet Explorer 4.0 through 7 allows remote attackers to determine the existence of local files that have as...
CVE-2007-3871Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of serv...
CVE-2007-4727Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd bef...
CVE-2007-4832Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code ...
CVE-2007-4838Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via...
CVE-2007-4839Unspecified vulnerability in the PD tools component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6....
CVE-2007-4828Cross-site scripting (XSS) vulnerability in the API pretty-printing mode in MediaWiki 1.8.0 through 1.8.4, 1.9.0 through...
CVE-2007-4830Cross-site scripting (XSS) vulnerability in CMD_BANDWIDTH_BREAKDOWN in DirectAdmin 1.30.2 and earlier allows remote atta...
CVE-2007-4831Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers...
CVE-2007-4833Unspecified vulnerability in the Edge Component in IBM WebSphere Application Server (WAS) 6.1 before Fix Pack 11 (6.1.0....
CVE-2007-4834Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP cod...
CVE-2007-4835SQL injection vulnerability in index.php in phpMyQuote 0.20 allows remote attackers to execute arbitrary SQL commands vi...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now