LiveActive security incident?Get immediate response
CVE archive

June 2007

Browse CVE records published in June 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 558 matching CVEs · Page 5 of 12.

Unknown · CVSS Not scored

CVE-2007-3316: Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote a...

Multiple format string vulnerabilities in plugins in VideoLAN VLC Media Player before 0.8.6c allow remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in (1) an Ogg/Vorbis file, (2) an Ogg/Theora file, (3) a CDDB entry for a CD Digital Audio (CDDA) file, or (4) Service Announce Protocol (SAP) multicast packets.

Published Jun 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3294: Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other produc...

Multiple buffer overflows in libtidy, as used in the Tidy extension for PHP 5.2.3 and possibly other products, allow context-dependent attackers to execute arbitrary code via (1) a long second argument to the tidy_parse_string function or (2) an unspecified vector to the tidy_repair_string function. NOTE: this might only be an issue in environments where vsnprintf is implemented as a wrapper for vsprintf.

Published Jun 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3269: Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attacke...

Multiple cross-site scripting (XSS) vulnerabilities in Papoo Light 3.6 before 20070611 allow remote attackers to inject arbitrary web script or HTML via (1) the URI in a GET request or (2) the Title field of a visitor comment, and (3) allow remote authenticated users to inject arbitrary web script or HTML via a message to another user. NOTE: vector (2) might overlap CVE-2006-3571.1.

Published Jun 19, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3285: Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and...

Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.

Published Jun 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3303: Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service...

Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows local users to cause a denial of service via certain code sequences executed in a worker process that (1) stop request processing by killing all worker processes and preventing creation of replacements or (2) hang the system by forcing the master process to fork an arbitrarily large number of worker processes. NOTE: This might be an inherent design limitation of Apache with respect to worker processes in hosted environments.

Published Jun 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3275: MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blan...

MailWasher Server before 2.2.1, when used with LDAP or Active Directory (AD), does not properly handle blank passwords, which allows remote attackers to access an arbitrary user account and read the spam e-mail messages stored for that account, possibly related to the LoginCheck::doPost function in mwi/servlet/Login.cpp. NOTE: some of these details are obtained from third party information.

Published Jun 19, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3254: Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0...

Multiple cross-site scripting (XSS) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to inject arbitrary web script or HTML via (1) a saved Workflow name; (2) a Workflow name, related to deletion of a Workflow template; (3) the Content-Type HTTP header; or (4) the name of an uploaded file. NOTE: items 3 and 4 also affect the same version numbers of Xythos Digital Locker (XDL). Some or all vectors might also affect Xythos WebFile Server.

Published Jun 27, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3259: Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[]...

Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.

Published Jun 26, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3280: The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to...

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

Published Jun 19, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3255: Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) bef...

Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.

Published Jun 27, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3253: Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers t...

Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers to cause a denial of service via (1) certain email, which stops the SMTP Proxy during scanning; (2) certain HTTP traffic, which stops or slows down the HTTP proxy during HTTP responses containing virus scanned web pages; and (3) a disconnection during a streaming session.

Published Jun 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3238: Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remo...

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

Published Jun 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-3246: The do_set_password function in modules/chanserv/set.c in IRC Services before 5.0.60 preserves channel foun...

The do_set_password function in modules/chanserv/set.c in IRC Services before 5.0.60 preserves channel founder privileges across a channel password change (ChanServ SET PASSWORD), which allows remote authenticated users to obtain the new password through automated e-mail, or perform privileged actions without knowing the new password.

Published Jun 15, 2007 · Updated Aug 7, 2024