Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-3442 | 1 Research In Motion Limited | 1 Blackberry 7270 | 2017-07-28 | 2.3 LOW | N/A |
Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header. | |||||
CVE-2007-3443 | 1 Research In Motion Limited | 1 Blackberry 7270 | 2017-07-28 | 2.3 LOW | N/A |
The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered. | |||||
CVE-2007-3444 | 1 Rim | 2 Blackberry 7270, Blackberry Software | 2017-07-28 | 4.3 MEDIUM | N/A |
The Research in Motion BlackBerry 7270 with 4.0 SP1 Bundle 83 allows remote attackers to cause a denial of service (blocked call reception) via a malformed SIP invite message, possibly related to multiple format string specifiers in the From field, a spoofed source IP address, and limitations of the function stack frame. | |||||
CVE-2007-3445 | 3 Microsoft, Securecomputing, Sj Labs | 3 Windows Mobile, Sch I730 Phone, Sjphone | 2017-07-28 | 4.3 MEDIUM | N/A |
Buffer overflow in SJ Labs SJphone 1.60.303c, running under Windows Mobile 2003 on the Samsung SCH-i730 phone, allows remote attackers to cause a denial of service (device hang and call termination) via a malformed SIP INVITE message, a different vulnerability than CVE-2007-3351. | |||||
CVE-2007-3454 | 1 Trend Micro | 1 Officescan | 2017-07-28 | 10.0 HIGH | N/A |
Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library. | |||||
CVE-2007-3455 | 1 Trend Micro | 1 Officescan | 2017-07-28 | 10.0 HIGH | N/A |
cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information." | |||||
CVE-2007-3457 | 1 Adobe | 1 Flash Player | 2017-07-28 | 4.3 MEDIUM | N/A |
Adobe Flash Player 8.0.34.0 and earlier insufficiently validates HTTP Referer headers, which might allow remote attackers to conduct a CSRF attack via a crafted SWF file. | |||||
CVE-2007-3483 | 1 Rim | 1 Blackberry Enterprise Server | 2017-07-28 | 10.0 HIGH | N/A |
Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of arbitrary third-party applications on BlackBerry devices, which might facilitate loading of malware. | |||||
CVE-2007-3498 | 1 Htmlpurifier | 1 Htmlpurifier | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "unescaped print_r output." | |||||
CVE-2007-3501 | 1 Directadmin | 1 Directadmin | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin 1.30.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the domain parameter, a different vector than CVE-2007-1508. | |||||
CVE-2007-3502 | 1 Kaspersky Lab | 1 Kaspersky Anti-spam | 2017-07-28 | 7.5 HIGH | N/A |
Unspecified vulnerability in the web-based product configuration system in Kaspersky Anti-Spam before 3.0 MP1 allows remote attackers to obtain access to certain directories. | |||||
CVE-2007-3508 | 1 Gentoo | 1 Glibc | 2017-07-28 | 7.2 HIGH | N/A |
** DISPUTED ** Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution. | |||||
CVE-2007-3509 | 1 Symantec | 1 Veritas Backup Exec | 2017-07-28 | 7.5 HIGH | N/A |
Heap-based buffer overflow in the RPC subsystem in Symantec Backup Exec for Windows Servers 10.0, 10d, and 11d allows remote attackers to cause a denial of service (process exit) and possibly execute arbitrary code via crafted ncacn_ip_tcp requests. | |||||
CVE-2007-3510 | 1 Ibm | 1 Lotus Domino | 2017-07-28 | 9.0 HIGH | N/A |
Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name. | |||||
CVE-2007-3512 | 1 Wakwak | 1 Lhaca File Archiver | 2017-07-28 | 9.3 HIGH | N/A |
Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375. | |||||
CVE-2007-3516 | 1 Gorki Online | 1 Santrac Sitesi | 2017-07-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in kayit.asp in Gorki Online Santrac Sitesi allow remote attackers to inject arbitrary web script or HTML via the (1) kullanici, (2) posta, or (3) takim_adi parameter to uyeler.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3525 | 1 Ripe Website Manager | 1 Ripe Website Manager | 2017-07-28 | 7.8 HIGH | N/A |
Ripe Website Manager 0.8.9 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3531 | 1 Gentoo | 2 Linux, Nvclock | 2017-07-28 | 6.6 MEDIUM | N/A |
The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file. | |||||
CVE-2007-3533 | 1 3com | 1 3cnj220 | 2017-07-28 | 5.0 MEDIUM | N/A |
The 3Com IntelliJack Switch NJ220 before 2.0.23 allows remote attackers to cause a denial of service (reboot and reporting outage) via a loopback packet with zero in the length field. | |||||
CVE-2007-3537 | 1 Ibm | 1 Os 400 | 2017-07-28 | 7.8 HIGH | N/A |
IBM OS/400 (aka i5/OS) V4R2M0 through V5R3M0 on iSeries machines sends responses to TCP SYN-FIN packets, which allows remote attackers to obtain system information and possibly bypass firewall rules. |