Skip to main content

CWE archive

CWE-16 CVEs

Programmatic archive

318 CVEs tagged with CWE-1647 Critical, 77 High, 163 Medium, 31 Low, 0 Unrated.

CVE-2007-6409

Published Dec 17, 2007

The gg protocol handler in Gadu-Gadu, when this product is installed but not running, does not properly handle the skin attribute, which allows remote attackers to cause a denial…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6379

Published Dec 15, 2007

BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5964

Published Dec 13, 2007

The default configuration of autofs 5 in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 5, omits the nosuid option for the hosts (/net filesystem) map, which al…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6210

Published Dec 4, 2007

zabbix_agentd 1.1.4 in ZABBIX before 1.4.3 runs "UserParameter" scripts with gid 0, which might allow local users to gain privileges.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6199

Published Dec 1, 2007

rsync before 3.0.0pre6, when running a writable rsync daemon that is not using chroot, allows remote attackers to access restricted files via unknown vectors that cause rsync to c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6131

Published Nov 26, 2007

buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-4687

Published Nov 15, 2007

The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to es…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5943

Published Nov 14, 2007

Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5838

Published Nov 6, 2007

Aclient in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows local users to gain local System privileges via the "Enable key-based authentication to Deployment serv…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5715

Published Oct 30, 2007

DenyHosts 2.6 processes OpenSSH sshd "not listed in AllowUsers" log messages with an incorrect regular expression that does not match an IP address, which might allow remote attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5334

Published Oct 21, 2007

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5338

Published Oct 21, 2007

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativ…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5419

Published Oct 12, 2007

The 3Com 3CRWER100-75 router with 1.2.10ww software, when enabling an optional virtual server, configures this server to accept all source IP addresses on the external (Internet)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5420

Published Oct 12, 2007

The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might al…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-5422

Published Oct 12, 2007

Unspecified vulnerability in "Solaris Auditing" in the Basic Security Module (BSM) in Sun Solaris 10, when configured for auditing of networking (nt) events, allows local users to…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5375

Published Oct 11, 2007

Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-3759

Published Sep 27, 2007

Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to attacks that the user does not…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5071

Published Sep 24, 2007

Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4749

Published Sep 14, 2007

The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this i…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2216

Published Aug 14, 2007

The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3742

Published Aug 3, 2007

WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3380

Published Jul 20, 2007

The Distributed Lock Manager (DLM) in the cluster manager for Linux kernel 2.6.15 allows remote attackers to cause a denial of service (loss of lock services) by connecting to the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 318 CVEsPage 11 of 13