267381
|
- |
|
apple
|
quicktime mac_os_x
|
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application …
|
NVD-CWE-Other
|
CVE-2007-0462
|
2017-07-29 10:30 |
2007-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267382
|
- |
|
apple
|
installer mac_os_x
|
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MP…
|
NVD-CWE-Other
|
CVE-2007-0465
|
2017-07-29 10:30 |
2007-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267383
|
- |
|
apple
|
mac_os_x
|
crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.
|
NVD-CWE-Other
|
CVE-2007-0467
|
2017-07-29 10:30 |
2007-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267384
|
- |
|
apple
|
mac_os_x
|
Successful exploitation requires that the attacker is already a part of the administrator group.
|
NVD-CWE-Other
|
CVE-2007-0467
|
2017-07-29 10:30 |
2007-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267385
|
- |
|
sun
|
ray_server_software
|
cgi-bin/main in Sun Ray Server Software 2.0 and 3.0 before 20070123 allows local users to obtain the utadmin password by reading a web server's log file, or by conducting a different, unspecified loc…
|
NVD-CWE-Other
|
CVE-2007-0482
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267386
|
- |
|
enthusiast
|
enthusiast
|
Multiple cross-site scripting (XSS) vulnerabilities in Enthusiast 3.1 allow remote attackers to inject arbitrary web script or HTML via the URI for (1) show_owned.php or (2) show_joined.php. NOTE: T…
|
NVD-CWE-Other
|
CVE-2007-0483
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267387
|
- |
|
enthusiast
|
enthusiast
|
Multiple SQL injection vulnerabilities in Enthusiast 3.1 allow remote attackers to execute arbitrary SQL commands via the cat parameter to (1) show_owned.php, (2) show_joined.php, and possibly other …
|
NVD-CWE-Other
|
CVE-2007-0484
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267388
|
- |
|
huawei
|
versatile_routing_platform
|
The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long sh…
|
NVD-CWE-Other
|
CVE-2007-0488
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267389
|
- |
|
webspell
|
webspell
|
Multiple SQL injection vulnerabilities in gallery.php in webSPELL 4.01.02 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) galleryID parameter. NOTE: The pr…
|
NVD-CWE-Other
|
CVE-2007-0492
|
2017-07-29 10:30 |
2007-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
267390
|
- |
|
drupal
|
project project_issue_tracking_module
|
Unrestricted file upload vulnerability in the Project issue tracking 4.7.0 through 5.x before 20070123, a module for Drupal, allows remote authenticated users to execute arbitrary code by attaching a…
|
NVD-CWE-Other
|
CVE-2007-0505
|
2017-07-29 10:30 |
2007-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|