LiveActive security incident?Get immediate response
CVE archive

April 2007

Browse CVE records published in April 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 639 matching CVEs · Page 10 of 13.

Unknown · CVSS Not scored

CVE-2007-1868: The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not...

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

Published Apr 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1883: PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory...

PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to read arbitrary memory locations via an interruption that triggers a user space error handler that changes a parameter to an arbitrary pointer, as demonstrated via the iptcembed function, which calls certain convert_to_* functions with its input parameters.

Published Apr 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1924: Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrar...

Multiple PHP remote file inclusion vulnerabilities in phpContact allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) contact_business.php or (2) contact_person.php. NOTE: this issue is disputed by CVE and a reliable third party, because include_path is initialized to a fixed value before use

Published Apr 10, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1884: Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2...

Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers that arise in the php_formatted_print function because of 64 to 32 bit truncation, and bypass a check for the maximum allowable value; and (2) a width and precision of -1, which make it possible for the php_sprintf_appendstring function to place an internal buffer at an arbitrary memory location.

Published Apr 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1891: Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manag...

Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote attackers to execute arbitrary code, related to misinterpretation of the nSize parameter as a byte count instead of a wide character count.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1918: The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an...

The RFC_SET_REG_SERVER_PROPERTY function in the SAP RFC Library 6.40 and 7.00 before 20070109 implements an option for exclusive access to an RFC server, which allows remote attackers to cause a denial of service (client lockout) via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

Published Apr 10, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1878: Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the...

Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the runFile function, related to lack of HTML escaping in the property name.

Published Apr 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1914: The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers...

The RFC_START_PROGRAM function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to obtain sensitive information (external RFC server configuration data) via unspecified vectors, a different vulnerability than CVE-2006-6010. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.

Published Apr 10, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1850: Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers t...

Directory traversal vulnerability in classes/captcha/captcha.jpg.php in Drake CMS allows remote attackers to read arbitrary files or list arbitrary directories, and obtain the installation path, via a .. (dot dot) in the d_private parameter. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."

Published Apr 3, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1880: Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Worksta...

Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument," which results in a heap overflow.

Published Apr 6, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1849: Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute ar...

Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local arbitrary files via a .. (dot dot) in the d_private parameter. NOTE: some of these details are obtained from third party information. NOTE: Drake CMS has only a beta version available, and the vendor has previously stated "We do not consider security reports valid until the first official release of Drake CMS."

Published Apr 3, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-1874: Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories,...

Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5) license.txt, (6) Readme.htm, (7) .com.zerog.registry.xml, (8) k2adminstop, or (9) k2adminstart files; or (10) certain files in lib/wsconfig/.

Published Apr 11, 2007 · Updated Aug 7, 2024