267241
|
- |
|
free-sa
|
free-sa
|
Multiple unspecified vulnerabilities in Free-SA before 1.2.2 allow remote attackers to execute arbitrary code via unspecified vectors involving certain (1) sprintf and (2) vsprintf calls in (a) r_ind…
|
NVD-CWE-Other
|
CVE-2007-2652
|
2017-07-29 10:31 |
2007-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267242
|
- |
|
netwin
|
surgemail webmail
|
Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format string vulnerability that allows remote code execution.
|
NVD-CWE-noinfo CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-2655
|
2017-07-29 10:31 |
2007-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267243
|
- |
|
netwin
|
surgemail webmail
|
The vendor has addressed this issue through a product update:
http://netwinsite.com/cgi-bin/keycgi.exe?cmd=download&product=surgemail
|
NVD-CWE-noinfo CWE-134
Use of Externally-Controlled Format String
|
CVE-2007-2655
|
2017-07-29 10:31 |
2007-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267244
|
- |
|
globalmegacorp
|
phpchain
|
Multiple cross-site scripting (XSS) vulnerabilities in PHPChain 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the catid parameter to (1) settings.php or (2) cat.ph…
|
NVD-CWE-Other
|
CVE-2007-2669
|
2017-07-29 10:31 |
2007-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267245
|
- |
|
globalmegacorp
|
phpchain
|
PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.
|
NVD-CWE-Other
|
CVE-2007-2670
|
2017-07-29 10:31 |
2007-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267246
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory acces…
|
NVD-CWE-Other
|
CVE-2007-2671
|
2017-07-29 10:31 |
2007-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267247
|
- |
|
adobe
|
creative_suite
|
The installer for Adobe Version Cue CS3 Server on Apple Mac OS X, as used in Adobe Creative Suite 3 (CS3), does not re-enable the personal firewall after completing the product installation, which al…
|
NVD-CWE-Other
|
CVE-2007-2682
|
2017-07-29 10:31 |
2007-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267248
|
- |
|
bea
|
weblogic_server
|
The HttpClusterServlet and HttpProxyServlet in BEA WebLogic Express and WebLogic Server 6.1 through SP7, 7.0 through SP7, 8.1 through SP5, 9.0, and 9.1, when SecureProxy is enabled, may process "exte…
|
NVD-CWE-Other
|
CVE-2007-2695
|
2017-07-29 10:31 |
2007-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267249
|
- |
|
bea
|
weblogic_server
|
The JMS Server in BEA WebLogic Server 6.1 through SP7, 7.0 through SP6, and 8.1 through SP5 enforces security access policies on the front end, which allows remote attackers to access protected queue…
|
NVD-CWE-Other
|
CVE-2007-2696
|
2017-07-29 10:31 |
2007-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267250
|
- |
|
bea
|
weblogic_server
|
The embedded LDAP server in BEA WebLogic Express and WebLogic Server 7.0 through SP6, 8.1 through SP5, 9.0, and 9.1, when in certain configurations, does not limit or audit failed authentication atte…
|
NVD-CWE-Other
|
CVE-2007-2697
|
2017-07-29 10:31 |
2007-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|