2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2007-4538——email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From addr...
CVE-2007-4541——Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitr...
CVE-2007-4540——Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute ar...
CVE-2007-4542——Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrar...
CVE-2007-2797——xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership o...
CVE-2007-2958——Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail...
CVE-2007-3741——The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a de...
CVE-2007-4527——Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload a...
CVE-2007-4526——The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a ...
CVE-2007-4522——Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to exe...
CVE-2007-4523——Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated...
CVE-2007-4524——PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH...
CVE-2007-4525——PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PH...
CVE-2007-4528——The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context...
CVE-2007-4529——The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assig...
CVE-2007-4530——Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitr...
CVE-2007-4531——Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client ...
CVE-2007-4532——Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial ...
CVE-2007-4533——Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to exec...
CVE-2007-4534——Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote atta...
CVE-2007-4535——The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (da...
CVE-2007-4536——TorrentTrader 1.07 and earlier sets insecure permissions for files in the root directory, which allows attackers to exec...
CVE-2007-4131——Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote...
CVE-2007-3847——The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remo...
CVE-2007-1356——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now