2007 CVE Vulnerabilities
6,580 CVEs published in 2007.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2007-4416 | — | — | 2.4% | Aug 18, 2007 | captcha.php in BellaBook (aka BellaBuffs) allows remote attackers to obtain administrative privileges by sending the adm... |
| CVE-2007-4397 | — | — | 2.1% | Aug 18, 2007 | Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) ... |
| CVE-2007-4398 | — | — | 1.8% | Aug 18, 2007 | Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-ass... |
| CVE-2007-4401 | — | — | 2.4% | Aug 18, 2007 | Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts i... |
| CVE-2007-4402 | — | — | 3.2% | Aug 18, 2007 | Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) s... |
| CVE-2007-4403 | — | — | 2.9% | Aug 18, 2007 | The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) s... |
| CVE-2007-4404 | — | — | 2.4% | Aug 18, 2007 | ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with ce... |
| CVE-2007-4405 | — | — | 1.7% | Aug 18, 2007 | ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumptio... |
| CVE-2007-4406 | — | — | 1.5% | Aug 18, 2007 | ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS)... |
| CVE-2007-4407 | — | — | 1.5% | Aug 18, 2007 | ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which al... |
| CVE-2007-4408 | — | — | 1.3% | Aug 18, 2007 | ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a... |
| CVE-2007-4409 | — | — | 1.3% | Aug 18, 2007 | Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arr... |
| CVE-2007-4410 | — | — | 1.1% | Aug 18, 2007 | ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote ... |
| CVE-2007-4411 | — | — | 1.2% | Aug 18, 2007 | ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series... |
| CVE-2007-4412 | — | — | 0.8% | Aug 18, 2007 | Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated user... |
| CVE-2007-4413 | — | — | 0.8% | Aug 18, 2007 | Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote a... |
| CVE-2007-4414 | — | — | 0.3% | Aug 18, 2007 | Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon... |
| CVE-2007-4415 | — | — | 0.3% | Aug 18, 2007 | Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions fo... |
| CVE-2007-4417 | — | — | 1.3% | Aug 18, 2007 | IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remo... |
| CVE-2007-4418 | — | — | 1.3% | Aug 18, 2007 | IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a cer... |
| CVE-2007-4419 | — | — | 4.8% | Aug 18, 2007 | Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3... |
| CVE-2007-4420 | — | — | 2.9% | Aug 18, 2007 | Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer ... |
| CVE-2007-4421 | — | — | 2.3% | Aug 18, 2007 | SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL c... |
| CVE-2007-4422 | — | — | 2.6% | Aug 18, 2007 | The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled,... |
| CVE-2007-4423 | — | — | 3.5% | Aug 18, 2007 | Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attack... |
Check if your code is affected by 2007 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now