267051
|
- |
|
drupal
|
content_construction_kit
|
Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arb…
|
NVD-CWE-Other
|
CVE-2007-4363
|
2017-07-29 10:32 |
2007-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267052
|
- |
|
fedoraproject
|
commons
|
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination wit…
|
CWE-287
Improper Authentication
|
CVE-2007-4364
|
2017-07-29 10:32 |
2007-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267053
|
- |
|
symantec
|
altiris_deployment_solution
|
Aclient in Symantec Altiris Deployment Solution 6 before 6.8 SP2 (6.8.378) allows local users to gain local System privileges via the Log File Viewer.
|
NVD-CWE-Other
|
CVE-2007-4380
|
2017-07-29 10:32 |
2007-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267054
|
- |
|
yahoo
|
messenger
|
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, a…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2007-4391
|
2017-07-29 10:32 |
2007-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267055
|
- |
|
cisco
|
vpn_client
|
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the…
|
NVD-CWE-Other
|
CVE-2007-4414
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267056
|
- |
|
ibm
|
db2_universal_database
|
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine a…
|
NVD-CWE-Other
|
CVE-2007-4417
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267057
|
- |
|
ibm
|
db2_universal_database
|
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE:…
|
NVD-CWE-Other
|
CVE-2007-4418
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267058
|
- |
|
symantec
|
enterprise_firewall
|
The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid,…
|
NVD-CWE-Other
|
CVE-2007-4422
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267059
|
- |
|
lhaz
|
lhaz
|
Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-2006-4116.
|
NVD-CWE-Other
|
CVE-2007-4428
|
2017-07-29 10:32 |
2007-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267060
|
- |
|
torrenttrader
|
torrenttrader
|
Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2) account-settings.…
|
NVD-CWE-Other
|
CVE-2007-4435
|
2017-07-29 10:32 |
2007-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|