2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-4416captcha.php in BellaBook (aka BellaBuffs) allows remote attackers to obtain administrative privileges by sending the adm...
CVE-2007-4397Multiple CRLF injection vulnerabilities in (1) xmms-thing 1.0, (2) XMMS Remote Control Script 1.07, (3) Disrok 1.0, (4) ...
CVE-2007-4398Multiple CRLF injection vulnerabilities in the (1) now-playing.rb and (2) xmms.pl 1.1 scripts for WeeChat allow user-ass...
CVE-2007-4401Multiple CRLF injection vulnerabilities in the Advanced mIRC Integration Plugin and possibly other unspecified scripts i...
CVE-2007-4402Multiple unspecified scripts in mIRC allow user-assisted remote attackers to execute arbitrary code via the '|' (pipe) s...
CVE-2007-4403The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) s...
CVE-2007-4404ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with ce...
CVE-2007-4405ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumptio...
CVE-2007-4406ircu 2.10.12.01 through 2.10.12.04 does not remove ops privilege after a join from a server with an older timestamp (TS)...
CVE-2007-4407ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which al...
CVE-2007-4408ircu 2.10.12.05 and earlier ignores timestamps in bounces, which allows remote attackers to take over a channel during a...
CVE-2007-4409Race condition in ircu 2.10.12.01 through 2.10.12.05 allows remote attackers to set a new Apass during a netburst by arr...
CVE-2007-4410ircu 2.10.12.05 and earlier does not properly synchronize a kick action in certain cross scenarios, which allows remote ...
CVE-2007-4411ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series...
CVE-2007-4412Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated user...
CVE-2007-4413Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote a...
CVE-2007-4414Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon...
CVE-2007-4415Cisco VPN Client on Windows before 5.0.01.0600, and the 5.0.01.0600 InstallShield (IS) release, uses weak permissions fo...
CVE-2007-4417IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remo...
CVE-2007-4418IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a cer...
CVE-2007-4419Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3...
CVE-2007-4420Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer ...
CVE-2007-4421SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL c...
CVE-2007-4422The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled,...
CVE-2007-4423Stack-based buffer overflow in the AUTH_LIST_GROUPS_FOR_AUTHID function in IBM DB2 UDB 9.1 before Fixpak 3 allows attack...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now