Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29867 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-2567 1 Taltech 1 Tal Bar Code Activex Control 2025-04-09 9.3 HIGH N/A
Buffer overflow in the SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2007-3194 1 Mywebland 1 Mybloggie 2025-04-09 7.5 HIGH 9.8 CRITICAL
Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE: another researcher disputes the vulnerability because the files are protected against direct requests, contain no relevant include statements, or do not exist
CVE-2007-1252 1 Symantec 1 Mail Security 2025-04-09 9.3 HIGH N/A
Buffer overflow in Symantec Mail Security for SMTP 5.0 before Patch 175 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted headers in an e-mail message. NOTE: some information was obtained from third party sources.
CVE-2007-2822 1 Wavelink Media 1 Tutorialcms 2025-04-09 9.3 HIGH N/A
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.
CVE-2007-0093 1 Cms-center 1 Simple Web Cms 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2007-1855 1 Webasyst Llc 1 Shop-script 2025-04-09 7.5 HIGH N/A
Multiple PHP remote file inclusion vulnerabilities in smarty/smarty_class.php in Shop-Script FREE allow remote attackers to execute arbitrary PHP code via a URL in the (1) _smarty_compile_path, (2) smarty_compile_path, (3) get_plugin_filepath, (4) smarty_dir, and (5) filename parameters. NOTE: this issue might be related to CVE-2006-7105.
CVE-2007-4124 1 Hitachi 14 Cosminexus Application Server, Cosminexus Collaboration Portal, Cosminexus Developer and 11 more 2025-04-09 4.9 MEDIUM N/A
The session failover function in Cosminexus Component Container in Cosminexus 6, 6.7, and 7 before 20070731, as used in multiple Hitachi products, can use session data for the wrong user under unspecified conditions, which might allow remote authenticated users to obtain sensitive information, corrupt another user's session data, and possibly gain privileges.
CVE-2008-4394 1 Gentoo 1 Portage 2025-04-09 6.9 MEDIUM N/A
Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.
CVE-2006-7041 1 Atrium Software 1 Mercur Messaging 2005 2025-04-09 7.8 HIGH N/A
The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known.
CVE-2006-6766 1 Cwm-design 1 Cwmexplorer 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in cwmExplorer 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: The provenance of this information is unknown; details are obtained solely from third party information.
CVE-2007-0475 1 Smb4k 1 Smb4k 2025-04-09 4.4 MEDIUM N/A
Multiple stack-based buffer overflows in utilities/smb4k_*.cpp in Smb4K before 0.8.0 allow local users, when present on the Smb4K sudoers list, to gain privileges via unspecified vectors related to the args variable and unspecified other variables, in conjunction with the sudo configuration.
CVE-2006-5295 1 Clam Anti-virus 1 Clamav 2025-04-09 5.0 MEDIUM N/A
Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory location."
CVE-2007-2193 1 Acd Systems 2 Acdsee, Photo Editor 2025-04-09 9.3 HIGH N/A
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build 195 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string. NOTE: some of these details are obtained from third party information.
CVE-2006-7209 1 Zoneo-soft 1 Phptraffica 2025-04-09 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to keywords results in the (1) main, (2) daily, (3) weekly, (4) monthly, (5) new trends, (6) individual page, and (7) search engine statistics.
CVE-2007-4325 1 Mapos Scripts 1 Gaestebuch 2025-04-09 6.8 MEDIUM N/A
PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.
CVE-2007-1450 1 Phpnuke 1 Php-nuke 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to execute arbitrary SQL commands in the Top or News module via the lang parameter.
CVE-2007-1363 1 Dropafew 1 Dropafew 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.
CVE-2007-1433 1 Grayscale 1 Grayscale Blog 2025-04-09 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the comment fields to (1) scripts/addblog_comment.php and (2) detail.php.
CVE-2007-4405 1 Universal Ircd 1 Ircu 2025-04-09 7.8 HIGH N/A
ircu 2.10.12.02 through 2.10.12.04 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by creating a large number of unused channels (zannels).
CVE-2007-1867 1 Irfanview 1 Irfanview 2025-04-09 10.0 HIGH N/A
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.