Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2007-4322 | 1 Ac Zoom | 1 Blockhosts | 2012-10-30 | 6.8 MEDIUM | N/A |
BlockHosts before 2.0.4 does not properly parse (1) sshd and (2) vsftpd log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by connecting through ssh with a client protocol version identification containing an IP address string, or connecting through ftp with a username containing an IP address string, different vectors than CVE-2007-2765. | |||||
CVE-2007-3842 | 1 8e6 | 1 R3000 Enterprise Filter | 2012-10-30 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the 8e6 R3000 Enterprise Filter before 2.0.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this may be the same as CVE-2007-2970. | |||||
CVE-2007-3527 | 1 Firebirdsql | 1 Firebird | 2012-10-30 | 6.8 MEDIUM | N/A |
Integer overflow in Firebird 2.0.0 allows remote authenticated users to cause a denial of service (CPU consumption) via certain database operations with multi-byte character sets that trigger an attempt to use the value 65536 for a 16-bit integer, which is treated as 0 and causes an infinite loop on zero-length data. | |||||
CVE-2007-3545 | 1 Warzone | 1 Warzone 2100 Resurrection | 2012-10-30 | 7.1 HIGH | N/A |
Buffer overflow in Warzone 2100 Resurrection before 2.0.7 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename when setting background music. | |||||
CVE-2007-3620 | 1 Maia Mailguard | 1 Maia Mailguard | 2012-10-30 | 5.0 MEDIUM | N/A |
Multiple directory traversal vulnerabilities in Maia Mailguard 1.0.2 and earlier might allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) prevlang and (2) super parameters to (a) php/login.php; the (3) charset parameter to (a) php/login.php, (b) php/internal-init.php, and (c) php/xlogin.php; the (4) lang parameter to (b) php/internal-init.php; and the (5) language parameter to (c) php/xlogin.php. | |||||
CVE-2007-3642 | 1 Linux | 1 Linux Kernel | 2012-10-30 | 7.8 HIGH | N/A |
The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.22 allows remote attackers to cause a denial of service (crash) via an encoded, out-of-range index value for a choice field, which triggers a NULL pointer dereference. | |||||
CVE-2007-3663 | 1 Media Player Classic | 1 Media Player Classic | 2012-10-30 | 6.8 MEDIUM | N/A |
Divide-by-zero error in Media Player Classic (MPC) 6.4.9.0 allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted MPA file. | |||||
CVE-2007-3699 | 1 Symantec | 13 Antivirus Scan Engine, Brightmail Antispam, Client Security and 10 more | 2012-10-30 | 9.3 HIGH | N/A |
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. | |||||
CVE-2007-3727 | 1 Valarsoft | 1 Webmatic | 2012-10-30 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in Webmatic before 2.7 have unknown impact and attack vectors, related to the "administration area." | |||||
CVE-2007-3779 | 1 Squirrelmail | 1 Gpg Plugin | 2012-10-30 | 4.3 MEDIUM | N/A |
PHP local file inclusion vulnerability in gpg_pop_init.php in the G/PGP (GPG) Plugin before 20070707 for Squirrelmail allows remote attackers to include and execute arbitrary local files, related to the MOD parameter. | |||||
CVE-2007-3818 | 1 Drupal | 1 Logintoboggan Module | 2012-10-30 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the LoginToboggan module 5.x-1.x-dev before 20070712 for Drupal allows remote authenticated users with "administer blocks" permission to inject arbitrary JavaScript and gain privileges via "the message displayed above the default user login block." | |||||
CVE-2007-3830 | 1 Ibm | 2 Proventia Network Ips Gx5008, Proventia Network Ips Gx5108 | 2012-10-30 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in alert.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to inject arbitrary web script or HTML via the reminder parameter. | |||||
CVE-2007-3831 | 1 Ibm | 2 Proventia Network Ips Gx5008, Proventia Network Ips Gx5108 | 2012-10-30 | 9.3 HIGH | N/A |
PHP remote file inclusion in main.php in ISS Proventia Network IPS GX5108 1.3 and GX5008 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |||||
CVE-2007-3284 | 1 Apple | 1 Safari | 2012-10-30 | 7.8 HIGH | N/A |
corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name. | |||||
CVE-2007-3315 | 1 Yourfreescreamer | 1 Yourfreescreamer | 2012-10-30 | 6.8 MEDIUM | N/A |
Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter to bodyTemplate.php in (1) templates/Classic/, (2) templates/Classic Guestbook/, (3) templates/DarkNights/, and (4) templates/Simplistic/, different vectors than CVE-2007-3271. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3368 | 1 Polycom | 1 Soundpoint Ip 650 | 2012-10-30 | 7.8 HIGH | N/A |
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of service (device reboot) via a malformed CGI parameter. | |||||
CVE-2007-3450 | 1 Gorani Network | 1 6alblog | 2012-10-30 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2007-3023 | 1 Clam Anti-virus | 1 Clamav | 2012-10-30 | 10.0 HIGH | N/A |
unsp.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 does not properly calculate the end of a certain buffer, with unknown impact and remote attack vectors. | |||||
CVE-2007-3116 | 1 Maradns | 1 Maradns | 2012-10-30 | 5.0 MEDIUM | N/A |
Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, a different set of affected versions than CVE-2007-3114 and CVE-2007-3115. | |||||
CVE-2007-2996 | 1 Ibm | 1 Aix | 2012-10-30 | 6.6 MEDIUM | N/A |
Unspecified vulnerability in perl.rte 5.8.0.10 through 5.8.0.95 on IBM AIX 5.2, and 5.8.2.10 through 5.8.2.50 on AIX 5.3, allows local users to gain privileges via unspecified vectors related to the installation and "waiting for a legitimate user to execute a binary that ships with Perl." |