LiveActive security incident?Get immediate response
CVE archive

January 2007

Browse CVE records published in January 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 675 matching CVEs · Page 4 of 14.

Unknown · CVSS Not scored

CVE-2007-0603: PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for...

PGP Desktop before 9.5.1 does not validate data objects received over the (1) \pipe\pgpserv named pipe for PGPServ.exe or the (2) \pipe\pgpsdkserv named pipe for PGPsdkServ.exe, which allows remote authenticated users to gain privileges by sending a data object representing an absolute pointer, which causes code execution at the corresponding address.

Published Jan 30, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0639: Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attack...

Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory via (1) a REMOTE_ADDR cookie or (2) a cookie specifying an element of the msg array with an error number in the first dimension and 0 in the second dimension, as demonstrated by msg[999][0].

Published Jan 31, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0630: Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNew...

Multiple SQL injection vulnerabilities in the generate_csv function in classes/class.news.php in X-dev xNews 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) from, and (3) q parameters, different vectors than CVE-2007-0569. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Jan 31, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0588: The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Ma...

The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PICT file that triggers memory corruption in the _GetSrcBits32ARGB function. NOTE: this issue might overlap CVE-2007-0462.

Published Jan 30, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0585: include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers t...

include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. NOTE: some of these details are obtained from third party information. It is likely that this issue can be exploited to conduct directory traversal attacks.

Published Jan 30, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0599: Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwr...

Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET, (3) COOKIE, and (4) SERVER superglobal arrays.

Published Jan 30, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0628: Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6...

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Access Manager 6.1, 6.2, 6 2005Q1 (6.3), and 7 2005Q4 (7.0) before 20070129 allow remote attackers to inject arbitrary web script or HTML via the (1) goto or (2) gx-charset parameter. NOTE: some of these details are obtained from third party information.

Published Jan 31, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0574: SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordP...

SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via the wcHeadlines parameter, a different vector than CVE-2006-4715. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Jan 30, 2007 · Updated Aug 7, 2024