Total
27865 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2007-3774 | 1 Dvbbs | 1 Dvbbs | 2018-10-15 | 7.8 HIGH | N/A |
| Dvbbs 7.1.0 SP1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Data/Dvbbs7.mdb. | |||||
| CVE-2007-3786 | 1 Esoft | 1 Instagate Ex2 Utm | 2018-10-15 | 9.3 HIGH | N/A |
| ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer. | |||||
| CVE-2007-3725 | 1 Clam Anti-virus | 1 Clamav | 2018-10-15 | 4.3 MEDIUM | N/A |
| The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference. | |||||
| CVE-2007-3726 | 1 Rarlab | 1 Unrar | 2018-10-15 | 4.3 MEDIUM | N/A |
| Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number. | |||||
| CVE-2007-3792 | 1 Azerbaijan Development Group | 1 Azdgdating | 2018-10-15 | 4.3 MEDIUM | N/A |
| Multiple PHP remote file inclusion vulnerabilities in AzDG Dating Gold 3.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter to (1) header.php, (2) footer.php, or (3) secure.admin.php in templates/. | |||||
| CVE-2007-3736 | 1 Mozilla | 1 Firefox | 2018-10-15 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed. | |||||
| CVE-2007-3788 | 1 Esoft | 1 Instagate Ex2 Utm | 2018-10-15 | 7.6 HIGH | N/A |
| The eSoft InstaGate EX2 UTM device stores the admin password within the settings HTML document, which might allow context-dependent attackers to obtain sensitive information by reading this document. | |||||
| CVE-2007-3783 | 1 Envivosoft | 1 Envivo Cms | 2018-10-15 | 7.5 HIGH | N/A |
| SQL injection vulnerability in default.asp in enVivo!CMS allows remote attackers to execute arbitrary SQL commands via the ID parameter in an article action. NOTE: this is probably different from CVE-2005-1413.4. | |||||
| CVE-2007-3613 | 1 Sap | 1 Internet Graphics Server | 2018-10-15 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter. | |||||
| CVE-2007-3707 | 1 Codeigniter | 1 Codeigniter | 2018-10-15 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in index.php in CodeIgniter 1.5.3 before 20070628, when enable_query_strings is true, allows remote attackers to read arbitrary files via a .. (dot dot) in the c parameter. | |||||
| CVE-2007-3706 | 1 Codeigniter | 1 Codeigniter | 2018-10-15 | 2.1 LOW | N/A |
| The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie. | |||||
| CVE-2007-3681 | 1 Winpcap | 1 Winpcap | 2018-10-15 | 6.6 MEDIUM | N/A |
| The IOCTL 9031 (BIOCGSTATS) handler in the NPF.SYS device driver in WinPcap before 4.0.1 allows local users to overwrite memory and execute arbitrary code via malformed Interrupt Request Packet (Irp) parameters. | |||||
| CVE-2007-3704 | 1 Entertainment Cms | 1 Entertainment Cms | 2018-10-15 | 7.5 HIGH | N/A |
| Entertainment CMS allows remote attackers to bypass authentication and perform certain administrative actions by setting the adminLogged cookie to "Administrator." | |||||
| CVE-2007-3708 | 1 Codeigniter | 1 Codeigniter | 2018-10-15 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in CodeIgniter 1.5.3 before 20070626 allows remote attackers to inject arbitrary web script or HTML via (1) String.fromCharCode and (2) malformed nested tag manipulations in an unspecified component, related to insufficient sanitization by the xss_clean function. | |||||
| CVE-2007-3679 | 1 Citrix | 1 Access Gateway | 2018-10-15 | 4.3 MEDIUM | N/A |
| The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system. | |||||
| CVE-2007-3709 | 1 Codeigniter | 1 Codeigniter | 2018-10-15 | 5.0 MEDIUM | N/A |
| CRLF injection vulnerability in the redirect function in url_helper.php in CodeIgniter 1.5.3 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in an unspecified parameter, as demonstrated by a Set-Cookie header. | |||||
| CVE-2007-3710 | 1 Php Comet-server | 1 Php Comet-server | 2018-10-15 | 7.5 HIGH | N/A |
| PHP remote file inclusion vulnerability in example/gamedemo/inc.functions.php in PHP Comet-Server allows remote attackers to execute arbitrary PHP code via a URL in the projectPath parameter. | |||||
| CVE-2007-3697 | 1 Tufat | 1 Flashbb | 2018-10-15 | 7.5 HIGH | N/A |
| PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to execute arbitrary code via a URL in the phpbb_root_path parameter. | |||||
| CVE-2007-3714 | 1 Ada | 1 Imgsvr | 2018-10-15 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in Ada Image Server (ImgSvr) 0.6.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this is probably a different issue than CVE-2004-2464. NOTE: it was later reported that 0.6.21 and earlier is also affected. | |||||
| CVE-2007-3511 | 1 Mozilla | 2 Firefox, Seamonkey | 2018-10-15 | 4.3 MEDIUM | N/A |
| The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which bypasses the focus prevention, as demonstrated by changing focus from a textarea to a file upload field. | |||||
