Total
277437 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2007-0266 | 1 Ezboxx | 1 Ezboxx Portal System | 2024-11-21 | N/A |
SQL injection vulnerability in boxx/ShowAppendix.asp in Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the iid parameter. | ||||
CVE-2007-0265 | 1 Ezboxx | 1 Portal System Beta | 2024-11-21 | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Ezboxx Portal System Beta 0.7.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pic parameter to custom/piczoom.asp, (2) the nocatname parameter to boxx/user-upload.asp, or (3) the iid parameter to indexes/newscomments.asp. | ||||
CVE-2007-0264 | 1 Winzip | 1 Winzip | 2024-11-21 | N/A |
Buffer overflow in Winzip32.exe in WinZip 9.0 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long command line argument. NOTE: this issue may cross privilege boundaries if an application automatically invokes Winzip32.exe for untrusted input filenames, as in the case of a file upload application. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | ||||
CVE-2007-0263 | 1 Total Commander | 1 Total Commander | 2024-11-21 | N/A |
Unspecified vulnerability in Total Commander before 6.5.6 allows user-assisted remote attackers to delete arbitrary files and corrupt a filesystem via a crafted RAR file. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | ||||
CVE-2007-0262 | 1 Wordpress | 1 Wordpress | 2024-11-21 | N/A |
WordPress 2.0.6, and 2.1Alpha 3 (SVN:4662), does not properly verify that the m parameter value has the string data type, which allows remote attackers to obtain sensitive information via an invalid m[] parameter, as demonstrated by obtaining the path, and obtaining certain SQL information such as the table prefix. | ||||
CVE-2007-0261 | 1 Snews | 1 Snews | 2024-11-21 | N/A |
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter. | ||||
CVE-2007-0260 | 1 Naig | 1 Naig | 2024-11-21 | N/A |
PHP remote file inclusion vulnerability in index.php in Naig 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the this_path parameter. NOTE: a reliable third party disputes this vulnerability because this_path is defined before use | ||||
CVE-2007-0259 | 1 Ezboxx | 1 Ezboxx Portal System | 2024-11-21 | N/A |
Ezboxx Portal System Beta 0.7.6 and earlier allows remote attackers to obtain sensitive information via an invalid cat parameter to boxx/knowledgebase.asp, which reveals the path in an error message. | ||||
CVE-2007-0258 | 2 Fastilo, Opensolution | 2 Fastilo, Quick.car | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in index.php in (1) Fastilo 2.0 and (2) Open Solution Quick.Cart 2.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: some of these details are obtained from third party information. | ||||
CVE-2007-0257 | 1 Grsecurity | 1 Grsecurity Kernel Patch | 2024-11-21 | N/A |
Unspecified vulnerability in the expand_stack function in grsecurity PaX allows local users to gain privileges via unspecified vectors. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities." The developer also cites a past disclosure that was not proven. As of 20070120, the original researcher has released demonstration code | ||||
CVE-2007-0256 | 1 Videolan | 1 Vlc Media Player | 2024-11-21 | N/A |
VideoLAN VLC 0.8.6a allows remote attackers to cause a denial of service (application crash) via a crafted .wmv file. | ||||
CVE-2007-0255 | 1 Xine | 1 Xine | 2024-11-21 | N/A |
XINE 0.99.4 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain M3U file that contains a long #EXTINF line and contains format string specifiers in an invalid udp:// URI, possibly a variant of CVE-2007-0017. | ||||
CVE-2007-0254 | 1 Xine | 1 Xine-ui | 2024-11-21 | N/A |
Format string vulnerability in the errors_create_window function in errors.c in xine-ui allows attackers to execute arbitrary code via unknown vectors. | ||||
CVE-2007-0253 | 1 Grsecurity | 1 Grsecurity Kernel Patch | 2024-11-21 | N/A |
Unspecified vulnerability in the grsecurity patch has unspecified impact and remote attack vectors, a different vulnerability than the expand_stack vulnerability from the Digital Armaments 20070110 pre-advisory. NOTE: the grsecurity developer has disputed this issue, stating that "the function they claim the vulnerability to be in is a trivial function, which can, and has been, easily checked for any supposed vulnerabilities." The developer also cites a past disclosure that was not proven | ||||
CVE-2007-0252 | 1 Easy-content Filemanager | 1 Easy-content Filemanager | 2024-11-21 | N/A |
Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors. | ||||
CVE-2007-0251 | 1 Snort | 1 Snort | 2024-11-21 | N/A |
Integer underflow in the DecodeGRE function in src/decode.c in Snort 2.6.1.2 allows remote attackers to trigger dereferencing of certain memory locations via crafted GRE packets, which may cause corruption of log files or writing of sensitive information into log files. | ||||
CVE-2007-0250 | 1 Nwom | 1 Nwom Topsites | 2024-11-21 | N/A |
index.php in Nwom topsites 3.0 allows remote attackers to obtain potentially sensitive information via a ' (quote) character in the o parameter, which forces a SQL error. | ||||
CVE-2007-0249 | 1 Nwom | 1 Nwom Topsites | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Nwom topsites 3.0 allows remote attackers to inject arbitrary web script or HTML via the o parameter. | ||||
CVE-2007-0248 | 1 Squid | 1 Squid | 2024-11-21 | N/A |
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop. | ||||
CVE-2007-0247 | 1 Squid | 1 Squid | 2024-11-21 | N/A |
squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions. |