LiveActive security incident?Get immediate response
CVE archive

April 2007

Browse CVE records published in April 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 639 matching CVEs · Page 7 of 13.

Unknown · CVSS Not scored

CVE-2007-2059: Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (E...

Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2107: SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS allows...

SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-1960. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2119: Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle E...

Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2083: vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments...

vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateKey and (2) NtDeleteFile functions.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2052: Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes...

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.

Published Apr 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2092: Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows...

Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) allows remote attackers to inject arbitrary PHP code into posts.txt via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2053: Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of se...

Multiple stack-based buffer overflows in AFFLIB before 2.2.6 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a long LastModified value in an S3 XML response in lib/s3.cpp; (2) a long (a) path or (b) bucket in an S3 URL in lib/vnode_s3.cpp; or (3) a long (c) EFW, (d) AFD, or (c) aimage file path. NOTE: the aimage vector (3c) has since been recalled from the researcher's original advisory, since the code is not called in any version of AFFLIB.

Published Apr 30, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2077: PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execut...

PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this issue was fixed last year and [no] is longer a problem."

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2082: Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote...

Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by remote unauthenticated attackers.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2076: PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execut...

PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this problem existed only briefly in v1.0."

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2028: Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory co...

Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.

Published Apr 13, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2047: CRLF injection vulnerability in www/delivery/ck.php in Openads 2.3 (aka Max Media Manager, MMM) before 0.3....

CRLF injection vulnerability in www/delivery/ck.php in Openads 2.3 (aka Max Media Manager, MMM) before 0.3.31-alpha-pr3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the destination parameter. NOTE: some of these details are obtained from third party information.

Published Apr 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2084: PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbi...

PHP remote file inclusion vulnerability in MobilePublisherphp 1.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the auth_method parameter to (1) index.php, (2) list.php, (3) postreview.php, (4) reindex.php, (5) sections.php, (6) templates.php, (7) userinfo.php, (8) users.php, and (9) view.php in admin/. NOTE: this issue has been disputed by a reliable third party, who states that $auth_method is defined before use

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2087: Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .h...

Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2064: Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1...

Multiple PHP remote file inclusion vulnerabilities in Robert Ladstaetter ActionPoll 1.1.0, and possibly 1.1.1, allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_POLLDB parameter to actionpoll.php or (2) the CONFIG_DB parameter to db/DataReaderWriter.php, different vectors than CVE-2001-1297.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2071: Multiple cross-site scripting (XSS) vulnerabilities in Open-gorotto 2.0a 2006/02/08 edition, 2006/03/19 edi...

Multiple cross-site scripting (XSS) vulnerabilities in Open-gorotto 2.0a 2006/02/08 edition, 2006/03/19 edition, and 2006/04/07 edition before 20070416 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) pub/modules/d/_top.html; (2) /pub/modules/a/_access.html; (3) _circletop.html or (4) _cir66.html in pub/modules/ci/; or (5) _fri66.html, (6) _inv66.html, (7) _top.html, (8) _friends.html, or (9) _fri33.html in pub/modules/f/.

Published Apr 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-2079: The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted i...

The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the database server hostname, which allows remote attackers to trigger a library buffer overflow and execute arbitrary code via a long host parameter, or have other unspecified impact. NOTE: it could be argued that this is an issue in mssql_connect (CVE-2007-1411.1) in PHP, or an issue in the ADOdb Library, and the proper fix should be in one of these products; if so, then this should not be treated as a vulnerability in XAMPP.

Published Apr 18, 2007 · Updated Aug 7, 2024