LiveActive security incident?Get immediate response
CVE archive

November 2007

Browse CVE records published in November 2007, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 426 matching CVEs · Page 4 of 9.

Unknown · CVSS Not scored

CVE-2007-6041: Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR...

Buffer overflow in the Sequencer::queueMessage function in sequencer.cpp in the server in Rigs of Rods (RoR) before 0.33d SP1 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code by sending a nickname, then a vehicle name in a MSG2_USE_VEHICLE message, in which the combined length triggers the overflow.

Published Nov 20, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6009: Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code vi...

Multiple buffer overflows in ACD products allow user-assisted remote attackers to execute arbitrary code via a long section string in a (1) XBM or (2) XPM file to (a) ID_X.apl or (b) IDE_ACDStd.apl. NOTE: the PSP and LHA vectors are already covered by CVE-2007-4344 and CVE-2007-6007. NOTE: these might be integer overflows rather than buffer overflows.

Published Nov 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-6003: Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5....

Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Nov 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5982: Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions al...

Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) room parameter to sources/frame.php, the (2) theme_c parameter to help/index.php, or the (3) INSTALL_X7CHATVERSION parameter to upgradev1.php.

Published Nov 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5836: SQL injection vulnerability in Amazing Flash AFCommerce allows remote attackers to execute arbitrary SQL co...

SQL injection vulnerability in Amazing Flash AFCommerce allows remote attackers to execute arbitrary SQL commands via the firstname parameter to an unspecified component, a different issue than CVE-2006-3794. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Nov 5, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5977: Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authe...

Cross-site scripting (XSS) vulnerability in db_create.php in phpMyAdmin before 2.11.2.1 allows remote authenticated users with CREATE DATABASE privileges to inject arbitrary web script or HTML via a hex-encoded IMG element in the db parameter in a POST request, a different vulnerability than CVE-2006-6942.

Published Nov 15, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2007-5825: Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0....

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.

Published Nov 5, 2007 · Updated Aug 7, 2024