263941
|
- |
|
fedoraproject
|
commons
|
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination wit…
|
CWE-287
Improper Authentication
|
CVE-2007-4364
|
2017-07-29 10:32 |
2007-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263942
|
- |
|
symantec
|
altiris_deployment_solution
|
Aclient in Symantec Altiris Deployment Solution 6 before 6.8 SP2 (6.8.378) allows local users to gain local System privileges via the Log File Viewer.
|
NVD-CWE-Other
|
CVE-2007-4380
|
2017-07-29 10:32 |
2007-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263943
|
- |
|
yahoo
|
messenger
|
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, a…
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2007-4391
|
2017-07-29 10:32 |
2007-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263944
|
- |
|
cisco
|
vpn_client
|
Cisco VPN Client on Windows before 4.8.02.0010 allows local users to gain privileges by enabling the "Start Before Logon" (SBL) and Microsoft Dial-Up Networking options, and then interacting with the…
|
NVD-CWE-Other
|
CVE-2007-4414
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263945
|
- |
|
ibm
|
db2_universal_database
|
IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 does not properly revoke privileges on methods, which allows remote authenticated users to execute a method after revocation until the routine a…
|
NVD-CWE-Other
|
CVE-2007-4417
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263946
|
- |
|
ibm
|
db2_universal_database
|
IBM DB2 UDB 8 before Fixpak 15 does not properly check authorization, which allows remote authenticated users with a certain SELECT privilege to have an unknown impact via unspecified vectors. NOTE:…
|
NVD-CWE-Other
|
CVE-2007-4418
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263947
|
- |
|
symantec
|
enterprise_firewall
|
The login interface in Symantec Enterprise Firewall 6.x, when a VPN with pre-shared key (PSK) authentication is enabled, generates different responses depending on whether or not a username is valid,…
|
NVD-CWE-Other
|
CVE-2007-4422
|
2017-07-29 10:32 |
2007-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263948
|
- |
|
lhaz
|
lhaz
|
Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-2006-4116.
|
NVD-CWE-Other
|
CVE-2007-4428
|
2017-07-29 10:32 |
2007-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263949
|
- |
|
torrenttrader
|
torrenttrader
|
Multiple SQL injection vulnerabilities in TorrentTrader before 1.07 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) account-inbox.php, (2) account-settings.…
|
NVD-CWE-Other
|
CVE-2007-4435
|
2017-07-29 10:32 |
2007-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263950
|
- |
|
drupal
|
project project_issue_tracking_module
|
The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not properly enforce permissions, which allows remote …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4436
|
2017-07-29 10:32 |
2007-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|