Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-0297 | 1 Oracle | 2 Enterpriseone, Peoplesoft Enterprise | 2017-07-28 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.47.11 and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE03. | |||||
CVE-2007-0313 | 1 Gonicus | 1 Gonicus System Administration | 2017-07-28 | 9.0 HIGH | N/A |
Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests. | |||||
CVE-2007-0315 | 1 Filezilla | 1 Filezilla | 2017-07-28 | 9.3 HIGH | N/A |
Multiple buffer overflows in FileZilla before 2.2.30a allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors related to (1) Options.cpp when storing settings in the registry, and (2) the transfer queue (QueueCtrl.cpp). NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-0316 | 1 All In One Control Panel | 1 All In One Control Panel | 2017-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in All In One Control Panel (AIOCP) 1.3.010 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) xuser_name parameter to shared/code/cp_authorization.php, and the (2) did parameter to public/code/cp_downloads.php, different vectors than CVE-2007-0223. | |||||
CVE-2007-0317 | 1 Filezilla | 1 Filezilla | 2017-07-28 | 7.5 HIGH | N/A |
Format string vulnerability in the LogMessage function in FileZilla before 3.0.0-beta5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted arguments. NOTE: some of these details are obtained from third party information. | |||||
CVE-2007-0320 | 1 Macrovision | 1 Installfromtheweb | 2017-07-28 | 9.3 HIGH | N/A |
Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents. | |||||
CVE-2007-0321 | 1 Macrovision | 1 Flexnet Connect | 2017-07-28 | 9.3 HIGH | N/A |
Buffer overflow in the Update Service Agent ActiveX Control in isusweb.dll for Macrovision FLEXnet Connect (formerly InstallShield Update Service) allows remote attackers to execute arbitrary code via the Download method. | |||||
CVE-2007-0322 | 1 Intuit | 1 Quickbooks | 2017-07-28 | 9.3 HIGH | N/A |
Multiple stack-based buffer overflows in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2007-0326 | 1 Photochannel | 1 Pni Digital Media Upload Plugin Activex Control | 2017-07-28 | 9.3 HIGH | N/A |
Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2007-0328 | 1 Macrovision | 2 Flexnet Connect, Update Service | 2017-07-28 | 9.3 HIGH | N/A |
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method. | |||||
CVE-2007-0334 | 1 Ingate | 1 Firewall And Siparator | 2017-07-28 | 7.5 HIGH | N/A |
Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors. | |||||
CVE-2007-0346 | 1 Sme | 1 Filemailer | 2017-07-28 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter. | |||||
CVE-2007-0350 | 1 Sme | 1 Filemailer | 2017-07-28 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346. | |||||
CVE-2007-0357 | 1 Fritzdsl | 1 Fritzdsl | 2017-07-28 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in the AVM IGD CTRL Service in Fritz!DSL 02.02.29 allows remote attackers to read arbitrary files via ..%5C (URL-encoded dot dot backslash) sequences in a URI requested from the AR7 webserver. | |||||
CVE-2007-0358 | 1 Hp | 1 Jetdirect Firmware | 2017-07-28 | 7.8 HIGH | N/A |
Unspecified vulnerability in the FTP server implementation in HP Jetdirect firmware x.20.nn through x.24.nn allows remote attackers to cause a denial of service via unknown vectors. | |||||
CVE-2007-0362 | 1 Freshreader | 1 Freshreader | 2017-07-28 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the RSS feed component in FreshReader before 1.0.07010600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to tag attributes. | |||||
CVE-2007-0363 | 1 Openads | 1 Openads | 2017-07-28 | 6.8 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in admin-search.php in (1) Openads for PostgreSQL (aka phpPgAds) before 2.0.10 and (2) Openads (aka phpAdsNew) before 2.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |||||
CVE-2007-0365 | 1 Nicola Asuni | 1 All In One Control Panel | 2017-07-28 | 6.8 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in All In One Control Panel (AIOCP) 1.3.009 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this is probably a different vulnerability than CVE-2006-5830. | |||||
CVE-2007-0366 | 1 Maxum Development Corporation | 1 Rumpus Ftp Server | 2017-07-28 | 4.6 MEDIUM | N/A |
Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program. | |||||
CVE-2007-0404 | 1 Django Project | 1 Django | 2017-07-28 | 7.5 HIGH | N/A |
bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file. |