LiveActive security incident?Get immediate response
CVE archive

August 2007

Browse CVE records published in August 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 527 matching CVEs · Page 6 of 11.

Unknown · CVSS Not scored

CVE-2007-4404: ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two cha...

ircu 2.10.12.01 allows remote attackers to (1) cause a denial of service (flood wallops) by joining two channels with certain long names that differ in the final character, which triggers a protocol violation and (2) cause a denial of service (daemon crash) via a "J 0:#channel" message on a channel without an apass; and (3) allows remote authenticated operators to cause a denial of service (daemon crash) via a remote "names -D" command.

Published Aug 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4326: Multiple PHP remote file inclusion vulnerabilities in Bilder Uploader 1.3 allow remote attackers to execute...

Multiple PHP remote file inclusion vulnerabilities in Bilder Uploader 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) gruppen.php, (2) bild.php, (3) feed.php, (4) mitglieder.php, (5) online.php, (6) profil.php, and possibly other unspecified PHP scripts.

Published Aug 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4357: Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a l...

Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded URL. NOTE: the severity of this issue has been disputed by a reliable third party, since the intended functionality of the status bar allows it to be modified.

Published Aug 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4396: Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4...

Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attackers to execute arbitrary IRC commands via CRLF sequences in the name of the song in a .mp3 file.

Published Aug 18, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4375: The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probabl...

The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.

Published Aug 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4391: Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo!

Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by sending an "invite to view my webcam" request, and then injecting a DLL into the attacker's peer Yahoo! Messenger application when this request is accepted.

Published Aug 17, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4322: BlockHosts before 2.0.4 does not properly parse (1) sshd and (2) vsftpd log files, which allows remote atta...

BlockHosts before 2.0.4 does not properly parse (1) sshd and (2) vsftpd log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by connecting through ssh with a client protocol version identification containing an IP address string, or connecting through ftp with a username containing an IP address string, different vectors than CVE-2007-2765.

Published Aug 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4372: Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote atta...

Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for tracking purposes, but duplicates with other CVEs are difficult to determine.

Published Aug 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4360: Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote...

Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to cause a denial of service (SSH daemon crash) via certain network traffic, as demonstrated by an "nmap -O" scan with nmap 4.03, possibly related to a Mocana (Mocanada) SSH vulnerability.

Published Aug 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4317: Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface in ZyNOS firmware 3....

Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allow remote attackers to perform certain actions as administrators, as demonstrated by a request to Forms/General_1 with the (1) sysSystemName and (2) sysDomainName parameters.

Published Aug 13, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4324: ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier ver...

ActionScript 3 (AS3) in Adobe Flash Player 9.0.47.0, and other versions and other 9.0.124.0 and earlier versions, allows remote attackers to bypass the Security Sandbox Model, obtain sensitive information, and port scan arbitrary hosts via a Flash (SWF) movie that specifies a connection to make, then uses timing discrepancies from the SecurityErrorEvent error to determine whether a port is open or not. NOTE: 9.0.115.0 introduces support for a workaround, but does not fix the vulnerability.

Published Aug 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4323: DenyHosts 2.6 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts...

DenyHosts 2.6 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a client protocol version identification containing an IP address string, a different vector than CVE-2006-6301.

Published Aug 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-4339: Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to...

Multiple PHP remote file inclusion vulnerabilities in PHPCentral Poll Script 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the _SERVER[DOCUMENT_ROOT] parameter in (1) poll.php and (2) pollarchive.php. NOTE: a reliable third party states that this issue is resultant from a variable extraction error in functions.php.

Published Aug 14, 2007 · Updated Aug 7, 2024