2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2007-5967MEDIUM6.5A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user...
CVE-2007-4774MEDIUM5.9The Linux kernel before 2.4.36-rc1 has a race condition. It was possible to bypass systrace policies by flooding the ptr...
CVE-2007-3732MEDIUM5.5In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments...
CVE-2007-6716MEDIUM5.5fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which a...
CVE-2007-3650MEDIUM5.3myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to ca...
CVE-2007-3651MEDIUM5.3class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '...
CVE-2007-5954MEDIUM6.1Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary w...
CVE-2007-5817MEDIUM6.1dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1...
CVE-2007-5626MEDIUM5.5make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and someti...
CVE-2007-5460MEDIUM4.6Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when se...
CVE-2007-4465MEDIUM6.1Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on ...
CVE-2007-4786MEDIUM5.3Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8....
CVE-2007-3968MEDIUM5.3index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL ...
CVE-2007-3484MEDIUM6.1Cross-site scripting (XSS) vulnerability in search.php in Google Custom Search Engine allows remote attackers to inject ...
CVE-2007-2237MEDIUM5.5Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of ...
CVE-2007-2723MEDIUM5.5Media Player Classic 6.4.9.0 allows user-assisted remote attackers to cause a denial of service (web browser crash) via ...
CVE-2007-2479MEDIUM5.9Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to obtain potentially sensitive information via lon...
CVE-2007-1679MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to i...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now