2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4565——sink.c in fetchmail before 6.3.9 allows context-dependent attackers to cause a denial of service (NULL dereference and a...
CVE-2007-4555——Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HT...
CVE-2007-4554——Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows r...
CVE-2007-4549——Multiple buffer overflows in ALPass 2.7 English and 3.02 Korean allow user-assisted remote attackers to execute arbitrar...
CVE-2007-4550——Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute ...
CVE-2007-4551——PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arb...
CVE-2007-4552——SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL c...
CVE-2007-4553——The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) vi...
CVE-2007-4548——The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed lo...
CVE-2007-4544——Cross-site scripting (XSS) vulnerability in wp-newblog.php in WordPress multi-user (MU) 1.0 and earlier allows remote at...
CVE-2007-4545——Multiple directory traversal vulnerabilities in Unreal Commander 0.92 build 565 and 573 allow user-assisted remote attac...
CVE-2007-4546——Unreal Commander 0.92 build 565 and 573 lists the filenames from the Central Directory of a ZIP archive, but extracts to...
CVE-2007-4547——Unreal Commander 0.92 build 565 and 573 writes portions of heap memory into local files when extracting from an archive ...
CVE-2007-4543——Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3...
CVE-2007-4537——Heap-based buffer overflow in the Huffman decompression algorithm implemented in Skulltag 0.97d-beta4.1 and earlier allo...
CVE-2007-4539——The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking f...
CVE-2007-4538——email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From addr...
CVE-2007-4541——Multiple cross-site scripting (XSS) vulnerabilities in Olate Download (od) 3.4.2 allow remote attackers to inject arbitr...
CVE-2007-4540——Multiple SQL injection vulnerabilities in download.php in Olate Download (od) 3.4.2 allow remote attackers to execute ar...
CVE-2007-4542——Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrar...
CVE-2007-3741——The (1) psp (aka .tub), (2) bmp, (3) pcx, and (4) psd plugins in gimp allow user-assisted remote attackers to cause a de...
CVE-2007-2797——xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership o...
CVE-2007-2958——Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail...
CVE-2007-4527——Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload a...
CVE-2007-4526——The Client Login Extension (CLE) in Novell Identity Manager before 3.5.1 20070730 stores the username and password in a ...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now