Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-1905 | 1 Pineapple Technologies | 1 Quizshock | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<". | |||||
CVE-2007-1925 | 1 Tru-zone | 1 Nukeet | 2017-07-28 | 6.5 MEDIUM | N/A |
The borrado function in modules/Your_Account/index.php in Tru-Zone Nuke ET 3.4 before fix 7 does not verify that account deletion requests come from the account owner, which allows remote authenticated users to delete arbitrary accounts via a modified cookie. | |||||
CVE-2007-1938 | 1 Ichitaro | 1 Ichitaro | 2017-07-28 | 4.3 MEDIUM | N/A |
Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS). | |||||
CVE-2007-1940 | 1 Ibm | 1 Tivoli Business Service Manager | 2017-07-28 | 4.9 MEDIUM | N/A |
IBM Tivoli Business Service Manager (TBSM) 4.1 before Interim Fix 1 logs passwords in plaintext, which allows local users to obtain sensitive information by reading (1) ncisetup.db or (2) msi.log. | |||||
CVE-2007-1945 | 5 Hp, Ibm, Linux and 2 more | 9 Hp-ux, Aix, I5os and 6 more | 2017-07-28 | 7.5 HIGH | N/A |
Unspecified vulnerability in the Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) before 6.1.0.7 has unknown impact and attack vectors. | |||||
CVE-2007-1954 | 1 Archivexpert | 1 Archivexpert | 2017-07-28 | 7.5 HIGH | N/A |
Multiple directory traversal vulnerabilities in ArchiveXpert 2.02 build 80 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .gz, (2) .jar, (3) .rar, (4) .tar.gz, (5) .zip, or (6) .tar file. | |||||
CVE-2007-1989 | 1 Dotclear | 1 Dotclear | 2017-07-28 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-1991 | 1 Youngzsoft | 1 Cmailserver | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927. | |||||
CVE-2007-1997 | 1 Clam Anti-virus | 1 Clamav | 2017-07-28 | 7.5 HIGH | N/A |
Integer signedness error in the (1) cab_unstore and (2) cab_extract functions in libclamav/cab.c in Clam AntiVirus (ClamAV) before 0.90.2 allow remote attackers to execute arbitrary code via a crafted CHM file that contains a negative integer, which passes a signed comparison and leads to a stack-based buffer overflow. | |||||
CVE-2007-2010 | 1 Bftpd | 1 Bftpd | 2017-07-28 | 6.8 MEDIUM | N/A |
Double free vulnerability in bftpd before 1.8 allows remote authenticated users to cause a denial of service (daemon crash) via a (1) get or (2) mget command. | |||||
CVE-2007-2012 | 1 Mimarsinan | 1 Comprexx | 2017-07-28 | 5.8 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in MimarSinan CompreXX 4.1 allow remote attackers to create files in arbitrary directories via a .. (dot dot) in a (1) .rar, (2) .jar or (3) .zip archive. | |||||
CVE-2007-2013 | 1 Jex-treme | 1 Einfacher Passworschutz | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in JEx-Treme Einfacher Passworschutz allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |||||
CVE-2007-2017 | 1 Alstrasoft | 1 Video Share Enterprise | 2017-07-28 | 7.5 HIGH | N/A |
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request. | |||||
CVE-2007-2018 | 1 Alstrasoft | 1 Video Share Enterprise | 2017-07-28 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in msg.php in AlstraSoft Video Share Enterprise allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2007-2029 | 2 Clam Anti-virus, Debian | 2 Clamav, Debian Linux | 2017-07-28 | 7.8 HIGH | N/A |
File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file. | |||||
CVE-2007-2030 | 1 Redhat | 2 Enterprise Linux, Fedora Core | 2017-07-28 | 4.9 MEDIUM | N/A |
lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked. | |||||
CVE-2007-2032 | 1 Cisco | 1 Wireless Control System | 2017-07-28 | 7.5 HIGH | N/A |
Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014. | |||||
CVE-2007-2033 | 1 Cisco | 1 Wireless Control System | 2017-07-28 | 6.5 MEDIUM | N/A |
Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.81.0 allows remote authenticated users to read any configuration page by changing the group membership of user accounts, aka Bug ID CSCse78596. | |||||
CVE-2007-2034 | 1 Cisco | 1 Wireless Control System | 2017-07-28 | 9.0 HIGH | N/A |
Unspecified vulnerability in Cisco Wireless Control System (WCS) before 4.0.87.0 allows remote authenticated users to gain the privileges of the SuperUsers group, and manage the application and its networks, related to the group membership of user accounts, aka Bug ID CSCsg05190. | |||||
CVE-2007-2035 | 1 Cisco | 1 Wireless Control System | 2017-07-28 | 7.8 HIGH | N/A |
Cisco Wireless Control System (WCS) before 4.0.66.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain network organization data via a direct request for files in certain directories, aka Bug ID CSCsg04301. |