Total
277437 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2007-5957 | 1 Ibm | 1 Informix Dynamic Server | 2024-11-21 | N/A |
Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 10.00.TC3TL and 11.10.TB4TL on Windows allows attackers to cause a denial of service (application crash) via unspecified SQ_ONASSIST requests. | ||||
CVE-2007-5956 | 1 Ibm | 1 Informix Dynamic Server | 2024-11-21 | N/A |
Directory traversal vulnerability in IBM Informix Dynamic Server (IDS) before 10.00.xC7W1 allows local users to gain privileges by referencing modified NLS message files through directory traversal sequences in the DBLANG environment variable. | ||||
CVE-2007-5955 | 1 Updir | 1 Updir.net | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in updir.php in UPDIR.NET before 2.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||
CVE-2007-5954 | 1 Jlmforo System | 1 Jlmforo System | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in buscador.php in JLMForo System allows remote attackers to inject arbitrary web script or HTML via the clave parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | ||||
CVE-2007-5953 | 1 Really Simple Caldav Store | 1 Really Simple Caldav Store | 2024-11-21 | N/A |
Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors. | ||||
CVE-2007-5952 | 1 Helioscalendar | 1 Helios Calendar | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in admin/index.php in Helios Calendar 1.2.1 Beta allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | ||||
CVE-2007-5951 | 1 E-vendejo | 1 0.2 | 2024-11-21 | N/A |
SQL injection vulnerability in articles.php in E-Vendejo 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
CVE-2007-5950 | 1 Netcommons | 1 Netcommons | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in NetCommons before 1.0.11, and 1.1.x before 1.1.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2006-4165. | ||||
CVE-2007-5949 | 1 Ibm | 1 Tivoli Service Desk | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Service Desk 6.2 allows remote authenticated users to inject arbitrary web script or HTML via the Description parameter in a Maximo change action. | ||||
CVE-2007-5948 | 1 Script-fun | 1 Sf-shoutbox | 2024-11-21 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters. | ||||
CVE-2007-5947 | 2 Mozilla, Redhat | 4 Firefox, Seamonkey, Enterprise Linux and 1 more | 2024-11-21 | N/A |
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI. | ||||
CVE-2007-5946 | 1 Hp | 1 Hp-ux | 2024-11-21 | N/A |
Unspecified vulnerability in the Aries PA-RISC emulator on HP-UX B.11.23 and B.11.31 on the IA-64 platform allows local users to obtain unspecified access. | ||||
CVE-2007-5945 | 1 Usvn | 1 User-friendly Svn | 2024-11-21 | N/A |
USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors. | ||||
CVE-2007-5944 | 1 Ibm | 1 Websphere Application Server | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in Servlet Engine / Web Container in IBM WebSphere Application Server (WAS) 5.1.1.4 through 5.1.1.16 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header. NOTE: this might be the same issue as CVE-2006-3918, but there are insufficient details to be sure. | ||||
CVE-2007-5943 | 1 Simple Machines | 1 Simple Machines Forum | 2024-11-21 | N/A |
Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message. | ||||
CVE-2007-5942 | 1 Bandersnatch | 1 Bandersnatch | 2024-11-21 | N/A |
Bandersnatch 0.4 allows remote attackers to obtain sensitive information via a malformed request for index.php with (1) a certain func parameter value; or (2) certain func, jid, page, and limit parameter values; which reveals the path in various error messages. | ||||
CVE-2007-5941 | 1 Adobe | 1 Shockwave Player | 2024-11-21 | N/A |
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method. | ||||
CVE-2007-5940 | 1 Tug | 1 Texlive 2007 | 2024-11-21 | N/A |
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the feynmf$$.pl temporary file. | ||||
CVE-2007-5939 | 1 Heimdal | 1 Heimdal | 2024-11-21 | N/A |
The gss_userok function in appl/ftp/ftpd/gss_userok.c in Heimdal 0.7.2 does not allocate memory for the ticketfile pointer before calling free, which allows remote attackers to have an unknown impact via an invalid username. NOTE: the vulnerability was originally reported for ftpd.c, but this is incorrect. | ||||
CVE-2007-5938 | 2 Intel, Redhat | 3 Pro Wireless 3945abg, Wireless Wifi Link 4965agn, Enterprise Linux | 2024-11-21 | N/A |
The iwl_set_rate function in compatible/iwl3945-base.c in iwlwifi 1.1.21 and earlier dereferences an iwl_get_hw_mode return value without checking for NULL, which might allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors during module initialization. |