Show filters
548 Total Results
Displaying 481-490 of 548
Sort by:
Attacker Value
Unknown
CVE-2007-3701
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
TippingPoint IPS before 20070710 does not properly handle a hex-encoded alternate Unicode '/' (slash) character, which might allow remote attackers to send certain network traffic and avoid detection, as demonstrated by a cmd.exe attack.
0
Attacker Value
Unknown
CVE-2007-2365
Disclosure Date: April 30, 2007 (last updated October 04, 2023)
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
0
Attacker Value
Unknown
CVE-2007-2317
Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.
0
Attacker Value
Unknown
CVE-2007-2319
Disclosure Date: April 26, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to mod_as_category.php in (1) modules/mod_as_category/ or (2) modules/.
0
Attacker Value
Unknown
CVE-2007-2244
Disclosure Date: April 25, 2007 (last updated October 04, 2023)
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
0
Attacker Value
Unknown
CVE-2007-1724
Disclosure Date: March 28, 2007 (last updated October 04, 2023)
Unspecified vulnerability in ReactOS 0.3.1 has unknown impact and attack vectors, related to a fix for "dozens of win32k bugs and failures," in which the fix itself introduces a vulnerability, possibly related to user-mode and kernel-mode copy failures.
0
Attacker Value
Unknown
CVE-2007-1102
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.
0
Attacker Value
Unknown
CVE-2007-1106
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
0
Attacker Value
Unknown
CVE-2007-1101
Disclosure Date: February 26, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name field, or the (3) q parameter in a search action in index.php.
0
Attacker Value
Unknown
CVE-2007-0161
Disclosure Date: January 10, 2007 (last updated October 04, 2023)
The PML Driver HPZ12 (HPZipm12.exe) in the HP all-in-one drivers, as used by multiple HP products, uses insecure SERVICE_CHANGE_CONFIG DACL permissions, which allows local users to gain privileges and execute arbitrary programs, as demonstrated by modifying the binpath argument, a related issue to CVE-2006-0023.
0