LiveActive security incident?Get immediate response
CVE archive

June 2007

Browse CVE records published in June 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 558 matching CVEs · Page 4 of 12.

Unknown · CVSS Not scored

CVE-2007-3405: Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote...

Multiple cross-site scripting (XSS) vulnerabilities in defter_yaz.asp in Lebisoft zdefter 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ad and (2) konu parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Jun 26, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3354: Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute...

Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.

Published Jun 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3334: Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Serve...

Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors.

Published Jun 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3336: Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as use...

Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input.

Published Jun 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3394: Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL com...

Multiple SQL injection vulnerabilities in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL commands via the (1) artid parameter to mod.php in a viewarticle action (publisher mod) and the (2) bid parameter to banners.php in a click action. NOTE: the mod.php viewdisk and viewlink vectors are already covered by CVE-2006-6873.

Published Jun 26, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3315: Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enable...

Multiple PHP remote file inclusion vulnerabilities in YourFreeScreamer 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the serverPath parameter to bodyTemplate.php in (1) templates/Classic/, (2) templates/Classic Guestbook/, (3) templates/DarkNights/, and (4) templates/Simplistic/, different vectors than CVE-2007-3271. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Jun 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3326: Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors...

Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and other attacks, a different vulnerability than CVE-2005-3025.2.

Published Jun 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3305: Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execu...

Heap-based buffer overflow in Cerulean Studios Trillian 3.x before 3.1.6.0 allows remote attackers to execute arbitrary code via a message sent through the MSN protocol, or possibly other protocols, with a crafted UTF-8 string, which triggers improper memory allocation for word wrapping when a window width is used as a buffer size, a different vulnerability than CVE-2007-2478.

Published Jun 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3344: Multiple cross-site scripting (XSS) vulnerabilities in netjukebox 4.01b allow remote attackers to inject ar...

Multiple cross-site scripting (XSS) vulnerabilities in netjukebox 4.01b allow remote attackers to inject arbitrary web script or HTML via the (1) album_id, (2) order, (3) sort, (4) filter, and (5) genre_id parameters to (a) index.php; and the (6) url parameter to (b) ridirect.php. NOTE: the attack also reveals the installation path.

Published Jun 22, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3366: Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x...

Cross-site scripting (XSS) vulnerability in Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Jun 22, 2007 · Updated Aug 7, 2024