LiveActive security incident?Get immediate response
CVE archive

February 2007

Browse CVE records published in February 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 511 matching CVEs · Page 7 of 11.

Unknown · CVSS Not scored

CVE-2007-0850: scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are ref...

scripts/cronscript.php in SysCP 1.2.15 and earlier includes and executes arbitrary PHP scripts that are referenced by the panel_cronscript table in the SysCP database, which allows attackers with database write privileges to execute arbitrary code by constructing a PHP file and adding its filename to this table.

Published Feb 8, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0856: TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.100...

TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.

Published Feb 8, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0843: The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check...

The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.

Published Feb 23, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0889: Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names,...

Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.

Published Feb 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0897: Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allo...

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record length of zero, which causes a function to return without closing a file descriptor.

Published Feb 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0852: Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote attackers to inject arbitrary web sc...

Cross-site scripting (XSS) vulnerability in DevTrack 6.x allows remote attackers to inject arbitrary web script or HTML via the "Keyword search" form field and unspecified other form fields that populate a public saved query. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 8, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0829: avast!

avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements.

Published Feb 7, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0863: PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute ar...

PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state that the variable is set before use in config.php

Published Feb 9, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0836: admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to in...

admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 8, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0823: xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using...

xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.

Published Feb 7, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0854: Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote atta...

Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL in the obj parameter. NOTE: a third party claims that this issue is not file inclusion because the contents are not parsed, but the attack can be used to overwrite files in /var/cpanel/objcache or provide unexpected web page contents.

Published Feb 8, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0834: Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web...

Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 allows remote attackers to inject arbitrary web script or HTML via the user name field when the user joins a chat room, a different vulnerability than CVE-2007-0807. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 7, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0881: PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attacker...

PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the (1) config[oi_dir] and possibly (2) config[openi_dir] parameters to open-admin/plugins/site_protection/index.php. NOTE: vector 2 might be the same as CVE-2006-4750.

Published Feb 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0882: Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.1...

Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.

Published Feb 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0868: Unspecified vulnerability in the Chat Room functionality in Yahoo!

Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 9, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0869: Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBul...

Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field. NOTE: this might be a duplicate of CVE-2007-0830.5. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 9, 2007 · Updated Aug 7, 2024