LiveActive security incident?Get immediate response
CVE archive

February 2007

Browse CVE records published in February 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 511 matching CVEs · Page 9 of 11.

Unknown · CVSS Not scored

CVE-2007-0768: Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo!

Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3) Nickname fields. NOTE: some of these details are obtained from third party information.

Published Feb 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0770: Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial o...

Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.

Published Feb 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0758: PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute ar...

PHP remote file inclusion vulnerability in lang.php in PHPProbid 5.24 allows remote attackers to execute arbitrary PHP code via a URL in the SRC attribute of an HTML element in the lang parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0759: Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL...

Multiple SQL injection vulnerabilities in EasyMoblog 0.5.1 allow remote attackers to execute arbitrary SQL commands via the (1) i or (2) post_id parameter to add_comment.php, which triggers an injection in libraries.inc.php; or (3) the i parameter to list_comments.php, which triggers an injection in libraries.inc.php.

Published Feb 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0695: Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote...

Multiple SQL injection vulnerabilities in Free LAN In(tra|ter)net Portal (FLIP) before 1.0-RC3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some sources mention the escape_sqlData, implode_sql, and implode_sqlIn functions, but these are protection schemes, not the vulnerable functions.

Published Feb 3, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0698: Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitr...

Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 3, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0708: cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate a...

cmdmon.sys in Comodo Firewall Pro (formerly Comodo Personal Firewall) before 2.4.16.174 does not validate arguments that originate in user mode for the (1) NtConnectPort and (2) NtCreatePort hooked SSDT functions, which allows local users to cause a denial of service (system crash) and possibly gain privileges via invalid arguments.

Published Feb 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0706: Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipn...

Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data. NOTE: some of these details are obtained from third party information.

Published Feb 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0646: Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows r...

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.

Published Feb 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0651: Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote att...

Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.

Published Feb 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0650: Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted r...

Buffer overflow in the open_sty function in mkind.c for makeindex 2.14 in teTeX might allow user-assisted remote attackers to overwrite files and possibly execute arbitrary code via a long filename. NOTE: other overflows exist but might not be exploitable, such as a heap-based overflow in the check_idx function.

Published Feb 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0672: LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk con...

LGSERVER.EXE in BrightStor Mobile Backup 4.0 allows remote attackers to cause a denial of service (disk consumption and daemon hang) via a value of 0xFFFFFF7F at a certain point in an authentication negotiation packet, which writes a large amount of data to a .USX file in CA_BABLDdata\Server\data\transfer\.

Published Feb 3, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0675: A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista,...

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

Published Feb 3, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-0663: SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote att...

SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter, a different vector than CVE-2007-0631. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Feb 1, 2007 · Updated Aug 7, 2024