2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4565sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and a...
CVE-2007-4555Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HT...
CVE-2007-4554Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows r...
CVE-2007-4549Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrar...
CVE-2007-4550Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute ...
CVE-2007-4551PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arb...
CVE-2007-4552SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL c...
CVE-2007-4553The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) vi...
CVE-2007-4548The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed lo...
CVE-2007-4544Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote at...
CVE-2007-4545Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attac...
CVE-2007-4546Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to...
CVE-2007-4547Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive ...
CVE-2007-4543Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3...
CVE-2007-4537Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allo...
CVE-2007-4539The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking f...
CVE-2007-4538email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From addr...
CVE-2007-4541Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitr...
CVE-2007-4540Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute ar...
CVE-2007-4542Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrar...
CVE-2007-3741The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a de...
CVE-2007-2797xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership o...
CVE-2007-2958Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail...
CVE-2007-4527Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload a...
CVE-2007-4526The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now