Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-6487 | 1 Plain Black | 1 Webgui | 2017-08-07 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in Plain Black WebGUI 7.4.0 through 7.4.17 allows remote authenticated users with Secondary Admin privileges to create Admin accounts, a different vulnerability than CVE-2006-0680. | |||||
CVE-2007-6509 | 1 Appian | 1 Business Process Management Suite | 2017-08-07 | 7.8 HIGH | N/A |
Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers to cause a denial of service via a crafted packet to port 5400/tcp. | |||||
CVE-2007-6510 | 1 Prowizard | 1 Prowizard 4 Pc | 2017-08-07 | 6.8 MEDIUM | N/A |
Multiple stack-based buffer overflows in ProWizard 4 PC (prowiz) 1.62 and earlier allow remote attackers to execute arbitrary code via a crafted file to the (1) AMOS-MusicBank, (2) FuzzacPacker, and (3) QuadraComposer rippers; and (4) have an unknown impact via a crafted file to the SkytPacker ripper. | |||||
CVE-2007-6513 | 1 Hp | 1 Esupportdiagnostics | 2017-08-07 | 4.3 MEDIUM | N/A |
HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method. | |||||
CVE-2007-6516 | 1 Ravware | 1 Flic Activex Control | 2017-08-07 | 6.8 MEDIUM | N/A |
Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property. | |||||
CVE-2007-6519 | 1 Hp | 1 Tru64 | 2017-08-07 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in the File-on-File Mounting File System (FFM) in HP Tru64 UNIX 5.1B-4 and 5.1B-3 allows local users to cause a denial of service (system crash) via unspecified vectors. | |||||
CVE-2007-6520 | 1 Opera | 1 Opera Browser | 2017-08-07 | 4.3 MEDIUM | N/A |
Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins. | |||||
CVE-2007-6521 | 1 Opera | 1 Opera Browser | 2017-08-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates. | |||||
CVE-2007-6522 | 1 Opera | 1 Opera Browser | 2017-08-07 | 4.3 MEDIUM | N/A |
The rich text editing functionality in Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks by using designMode to modify contents of pages in other domains. | |||||
CVE-2007-6525 | 1 Ibm | 1 Db2 Content Manager Toolkit | 2017-08-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in eClient in IBM DB2 Content Manager (CM) Toolkit 8.3 before fix pack 7 for z/OS has unknown impact and attack vectors, related to "scripting." | |||||
CVE-2007-6527 | 1 Rickard Andersson | 1 Punbb | 2017-08-07 | 5.8 MEDIUM | N/A |
uploadimg.php in the Automatic Image Upload with Thumbnails (imgUpload) module 1.3.2 for PunBB only verifies the Content-type field of uploaded files, which allows remote attackers to upload and execute arbitrary content via a file with a (1) JPG, (2) GIF, or (3) PNG MIME type. | |||||
CVE-2007-6535 | 1 Yahoo | 1 Toolbar | 2017-08-07 | 6.8 MEDIUM | N/A |
Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary code via a long string to the IsTaggedBM method. | |||||
CVE-2007-6549 | 1 Runcms | 1 Runcms | 2017-08-07 | 7.5 HIGH | N/A |
Unspecified vulnerability in RunCMS before 1.6.1 has unknown impact and attack vectors, related to "pagetype using." | |||||
CVE-2007-6562 | 1 Tcpreen | 1 Tcpreen | 2017-08-07 | 5.0 MEDIUM | N/A |
Multiple stack-based buffer overflows in the use of FD_SET in TCPreen before 1.4.4 allow remote attackers to cause a denial of service via multiple concurrent connections, which result in overflows in the (1) SocketAddress::Connect function in libsolve/sockprot.cpp and (2) monitor_bridge function in src/bridge.cpp. | |||||
CVE-2007-6563 | 1 Winace | 1 Winace | 2017-08-07 | 10.0 HIGH | N/A |
Heap-based buffer overflow in WinAce 2.65 and earlier, and possibly other versions before 2.69, allows user-assisted remote attackers to execute arbitrary code via a long filename in a compressed UUE archive. | |||||
CVE-2007-6564 | 1 Limbo Cms | 1 Limbo Cms | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web script or HTML via the com_option parameter. | |||||
CVE-2007-6570 | 1 Sun | 2 Java System Web Proxy Server, Java System Web Server | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309. | |||||
CVE-2007-6571 | 1 Sun | 2 Java System Web Proxy Server, Java System Web Server | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356. | |||||
CVE-2007-6572 | 1 Sun | 2 Java System Web Proxy Server, Java System Web Server | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204. | |||||
CVE-2007-6587 | 1 Plogger | 1 Plogger | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. |