LiveActive security incident?Get immediate response
CVE archive

October 2007

Browse CVE records published in October 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 560 matching CVEs · Page 6 of 12.

Unknown · CVSS Not scored

CVE-2007-5436: Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow...

Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function. NOTE: this issue might not cross privilege boundaries in most environments, since it is not marked as safe for scripting.

Published Oct 13, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5378: Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and...

Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (segmentation fault) via an animated GIF in which the first subimage is smaller than a subsequent subimage, which triggers the overflow in the ReadImage function, a different vulnerability than CVE-2007-5137.

Published Oct 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5407: Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component fo...

Multiple PHP remote file inclusion vulnerabilities in the JContentSubscription (com_jcs) 1.5.8 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) jcs.function.php; (2) add.php, (3) history.php, and (4) register.php, in view/; and (5) list.sub.html.php, (6) list.user.sub.html.php, and (7) reports.html.php in views/.

Published Oct 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5467: Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and p...

Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.

Published Oct 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5468: Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI...

Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use sniffed Digest authentication credentials to call arbitrary telephone numbers or spoof caller ID (aka "toll fraud and authentication forward attack").

Published Oct 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5508: Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (...

Multiple SQL injection vulnerabilities in the CTXSYS Intermedia application for the Oracle Text component (CTX_DOC) in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) THEMES, (2) GIST, (3) TOKENS, (4) FILTER, (5) HIGHLIGHT, and (6) MARKUP procedures, aka DB03. NOTE: remote unauthenticated attack vectors exist when CTXSYS is used with oracle Application Server.

Published Oct 17, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5466: Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impa...

Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.

Published Oct 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5471: libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, te...

libgssapi before 0.6-13.7, as used by the ISC BIND named daemon in SUSE Linux Enterprise Server 10 SP 1, terminates upon an initialization error, which allows remote attackers to cause a denial of service (daemon exit) via a GSS-TSIG request. NOTE: this issue probably affects other daemons that attempt to initialize this library within a chroot configuration or other invalid configuration.

Published Oct 16, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5381: Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a),...

Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.

Published Oct 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5463: ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attacke...

ideal_process.php in the iDEAL payment module in ViArt Shop 3.3 beta and earlier might allow remote attackers to obtain the pathname for certificate and key files via an "iDEAL transaction", possibly involving fopen error messages for nonexistent files, a different issue than CVE-2007-5364. NOTE: this can be leveraged for reading certificate or key files if an installation places these files under the web document root.

Published Oct 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5413: httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infras...

httpd.tkd in Radia Integration Server in Hewlett-Packard (HP) OpenView Configuration Management (CM) Infrastructure 4.0 through 4.2i and Client Configuration Manager (CCM) 2.0 allows remote attackers to read arbitrary files via URLs containing tilde (~) references to home directories, as demonstrated by ~root.

Published Oct 29, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5430: Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL comman...

Multiple SQL injection vulnerabilities in Stride 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the p parameter to main.php in the Content Management System, (2) the id parameter in a sto cmd action to shop.php in the Merchant subsystem, or the (3) course or (4) provider parameter to detail.php in the Courses subsystem.

Published Oct 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5441: CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows r...

CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some administrative actions, as demonstrated by (1) adding a user via a direct request to admin/adduser.php and (2) reading the admin log via an "admin/adminlog.php?page=1" request.

Published Oct 14, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5462: Unspecified vulnerability in the Sun Solaris RPC services library (librpcsvc) on Solaris 8 through 10 allow...

Unspecified vulnerability in the Sun Solaris RPC services library (librpcsvc) on Solaris 8 through 10 allows remote attackers to cause a denial of service (mountd crash) via unspecified packets to a server that exports many filesystems, and allows local users to cause a denial of service (automountd crash) via unspecified requests to mount filesystems from a server that exports many filesystems.

Published Oct 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5414: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rend...

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

Published Oct 12, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5456: Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security W...

Microsoft Internet Explorer 7 and earlier allows remote attackers to bypass the "File Download - Security Warning" dialog box and download arbitrary .exe files by placing a '?' (question mark) followed by a non-.exe filename after the .exe filename, as demonstrated by (1) .txt, (2) .cda, (3) .log, (4) .dif, (5) .sol, (6) .htt, (7) .itpc, (8) .itms, (9) .dvr-ms, (10) .dib, (11) .asf, (12) .tif, and unspecified other extensions, a different issue than CVE-2004-1331. NOTE: this issue might not cross privilege boundaries, although it does bypass an intended protection mechanism.

Published Oct 14, 2007 · Updated Aug 7, 2024