LiveActive security incident?Get immediate response
CVE archive

August 2007

Browse CVE records published in August 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 527 matching CVEs · Page 5 of 11.

Unknown · CVSS Not scored

CVE-2007-4412: Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authe...

Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (1) techs.php, (2) ticket_category.php, (3) ticket_priority.php, (4) ticket_workflow.php, (5) ticket_escalate.php, (6) fields_ticket.php, (7) ticket_rules_web.php, (8) ticket_displayfields.php, (9) ticket_rules_mail.php, (10) fields_user.php, (11) fields_faq.php, and (12) user_help.php, in (a) admincp/ and (b) possibly a directory on the "User side."

Published Aug 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4364: Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming...

Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote attackers to trigger a certain "unexpected / strange response" from an LDAP server, and (2) a reauthentication attempt that throws an exception, which allows remote attackers to trigger use of a cached authentication decision. NOTE: authentication can be bypassed by using vector 1 followed by vector 2, and possibly can be bypassed by using a single vector.

Published Aug 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4319: The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authentica...

The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege boundaries, and it might be resultant from CSRF; if so, then it should not be included in CVE.

Published Aug 13, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4425: Multiple buffer overflows in Live for Speed (LFS) demo, S1, and S2 allow remote authenticated users to (1)...

Multiple buffer overflows in Live for Speed (LFS) demo, S1, and S2 allow remote authenticated users to (1) cause a denial of service (server crash) and probably execute arbitrary code via an ID 3 packet with a long nickname field, and (2) cause a denial of service (server crash) via an ID 10 packet containing a long string corresponding to an unavailable track.

Published Aug 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4445: Image Space rFactor 1.250 and earlier allows remote attackers to cause a denial of service (daemon crash) v...

Image Space rFactor 1.250 and earlier allows remote attackers to cause a denial of service (daemon crash) via (1) an ID 0x30 packet, (2) an ID 0x38 packet, and an invalid 13-bit integer in (3) an ID 0x60 packet and (4) an ID 0x68 packet; and a denial of service (UDP port block) via (5) an ID 0x20 packet and (6) an ID 0x28 packet.

Published Aug 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4407: ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zann...

ircu 2.10.12.03 and 2.10.12.04 does not associate a timestamp with ops privilege on an unused channel (zannel), which allows remote attackers to (1) set or remove certain channel modes via a "netriding" attack or (2) take over a channel by joining an unlinked server with the A/Upass and then setting a new Apass.

Published Aug 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4442: Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used i...

Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII.

Published Aug 21, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4429: Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via u...

Unspecified vulnerability in Skype allows remote attackers to cause a denial of service (server hang) via unknown vectors related to sending long URIs, as claimed to be actively exploited on 20070817 using a "call to a specific number." NOTE: this identifier is for the en.securitylab.ru disclosure. According to the vendor, this issue is separate from the "sign-on issues" that reduced Skype service on 20070817, which appears to be a site-specific problem. As of 20070821, it is not clear whether this issue is simply a symptom of the larger sign-on problem.

Published Aug 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4424: Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows...

Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA attribute of an OBJECT element. NOTE: it could be argued that this is not a vulnerability because a dangerous file is not actually launched, but as of 2007, it is generally accepted that web browsers should prompt users before saving dangerous content.

Published Aug 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4430: Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a deni...

Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.

Published Aug 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4321: fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbit...

fail2ban 0.8 and earlier does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a client protocol version identification containing an IP address string, a different vector than CVE-2006-6302.

Published Aug 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4363: Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construct...

Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the autocomplete text field widget without Views.module.

Published Aug 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4420: Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw O...

Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the HttpDownloadFile method, a different vulnerability than CVE-2007-3168 and CVE-2007-3169.

Published Aug 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4332: SQL injection vulnerability in article.php in Article Dashboard, when magic_quotes_gpc is disabled, allows...

SQL injection vulnerability in article.php in Article Dashboard, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Aug 14, 2007 · Updated Aug 7, 2024