Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-2836 | 1 Hiki | 1 Hiki | 2017-07-28 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout. | |||||
CVE-2007-2837 | 2 Debian, Fireflier | 2 Debian Linux, Fireflier | 2017-07-28 | 3.6 LOW | N/A |
The (1) getRule and (2) getChains functions in server/rules.cpp in fireflierd (fireflier-server) in FireFlier 1.1.6 allow local users to overwrite arbitrary files via a symlink attack on the /tmp/fireflier.rules temporary file. | |||||
CVE-2007-2838 | 2 Debian, Gsambad | 2 Debian Linux, Gsambad | 2017-07-28 | 7.2 HIGH | N/A |
The populate_conns function in src/populate_conns.c in GSAMBAD 0.1.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gsambadtmp temporary file. | |||||
CVE-2007-2839 | 1 Debian | 1 Gfax | 2017-07-28 | 7.2 HIGH | N/A |
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors. | |||||
CVE-2007-2848 | 1 Sky Software | 2 Shcombobox Activex Control, Shell Megapack Activex | 2017-07-28 | 10.0 HIGH | N/A |
Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-2849 | 1 Knowledgetree Document Management | 1 Knowledgetree Document Management | 2017-07-28 | 10.0 HIGH | N/A |
KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check. | |||||
CVE-2007-2850 | 1 Citrix | 2 Access Essentials, Metaframe | 2017-07-28 | 10.0 HIGH | N/A |
The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address:port string. | |||||
CVE-2007-2855 | 1 Dart | 1 Dart Ziplite Compression | 2017-07-28 | 9.3 HIGH | N/A |
Buffer overflow in a certain ActiveX control in DartZipLite.dll 1.8.5.3 in Dart ZipLite Compression for ActiveX allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip function, a related issue to CVE-2007-2856. | |||||
CVE-2007-2865 | 1 Phppgadmin | 1 Phppgadmin | 2017-07-28 | 9.3 HIGH | N/A |
Cross-site scripting (XSS) vulnerability in sqledit.php in phpPgAdmin 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the server parameter. | |||||
CVE-2007-2877 | 1 Tcl Tk | 1 Tcl Tk | 2017-07-28 | 7.2 HIGH | N/A |
Buffer overflow in tcl/win/tclWinReg.c in Tcl (Tcl/Tk) before 8.5a6 allows local users to gain privileges via long registry key paths. | |||||
CVE-2007-2881 | 1 Sun | 1 Java System Web Proxy Server | 2017-07-28 | 10.0 HIGH | N/A |
Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation. | |||||
CVE-2007-2886 | 1 Nortel | 1 Communications Server | 2017-07-28 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Nortel CS 1000 M media card in Enterprise VoIP-Core-CS 1000E, 1000M, and 1000S 04.50W before 20070523 in Meridian/CS 1000 allows remote attackers to cause a denial of service (card hang) via unspecified vectors. | |||||
CVE-2007-2892 | 1 Asp-nuke | 1 Asp-nuke | 2017-07-28 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in news.asp in ASP-Nuke 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-2895 | 1 Lead Technologies | 1 Leadtools Raster Dialog File Object | 2017-07-28 | 7.5 HIGH | N/A |
Buffer overflow in a certain ActiveX control in LTRDF14e.DLL 14.5.0.44 in LeadTools Raster Dialog File Object allows remote attackers to execute arbitrary code via a long Directory property value. | |||||
CVE-2007-2896 | 2 Microsoft, Symantec | 2 All Windows, Enterprise Security Manager | 2017-07-28 | 4.3 MEDIUM | N/A |
Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports. | |||||
CVE-2007-2897 | 1 Microsoft | 1 Internet Information Server | 2017-07-28 | 7.5 HIGH | N/A |
Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access to execute arbitrary code after connecting a data stream to a device COM port; via requests for a URI containing a '/' immediately before and after the name of a DOS device, as demonstrated by the /AUX/.aspx URI, which bypasses a blacklist for DOS device requests. | |||||
CVE-2007-2903 | 1 Microsoft | 1 Office | 2017-07-28 | 5.0 MEDIUM | N/A |
Buffer overflow in the HelpPopup method in the Microsoft Office 2000 Controllo UA di Microsoft Office ActiveX control (OUACTRL.OCX) 1.0.1.9 allows remote attackers to cause a denial of service (probably winhlp32.exe crash) via a long first argument. NOTE: it is not clear whether this issue crosses privilege boundaries. | |||||
CVE-2007-2911 | 1 Jelsoft | 1 Vbulletin | 2017-07-28 | 8.5 HIGH | N/A |
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related issue to CVE-2007-1573. | |||||
CVE-2007-2917 | 1 Authentium | 1 Command Antivirus | 2017-07-28 | 9.3 HIGH | N/A |
Multiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2007-2918 | 1 Logitech | 1 Videocall | 2017-07-28 | 6.8 MEDIUM | N/A |
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) StarClient.dll, (4) ComLink in (c) uicomlink.dll, and (5) WebCamXMP in (d) wcamxmp.dll in Logitech VideoCall allow remote attackers to cause a denial of service (browser crash) and execute arbitrary code via unspecified vectors. |