Show filters
820 Total Results
Displaying 731-740 of 820
Sort by:
Attacker Value
Unknown
CVE-2007-4952
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.
0
Attacker Value
Unknown
CVE-2007-4476
Disclosure Date: September 05, 2007 (last updated October 04, 2023)
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
0
Attacker Value
Unknown
CVE-2007-4638
Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed map, which triggers an out-of-bounds read during a minimap preview.
0
Attacker Value
Unknown
CVE-2007-4131
Disclosure Date: August 25, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.
0
Attacker Value
Unknown
CVE-2007-4246
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Unspecified vulnerability, possibly a buffer overflow, in Justsystem Ichitaro 2007 and earlier allows remote attackers to execute arbitrary code via a modified document, as actively exploited in August 2007 by malware such as Tarodrop.D (Tarodrop.Q), a different vulnerability than CVE-2006-4326, CVE-2006-5424, CVE-2006-6400, and CVE-2007-1938.
0
Attacker Value
Unknown
CVE-2007-3684
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Unobtrusive Ajax Star Rating Bar before 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) q and (2) t parameters in (a) db.php and (b) rpc.php.
0
Attacker Value
Unknown
CVE-2007-3685
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
0
Attacker Value
Unknown
CVE-2007-3686
Disclosure Date: July 11, 2007 (last updated October 04, 2023)
CRLF injection vulnerability in db.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary HTTP headers and data via CRLF sequences in the HTTP_REFERER parameter.
0
Attacker Value
Unknown
CVE-2007-2597
Disclosure Date: May 11, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) ordnertiefe parameter to site_conf.php; or the (2) tt_docroot parameter to (a) class.csv.php, (b) produkte_nach_serie.php, or (c) ref_kd_rubrik.php in functionen/; (d) hg_referenz_jobgalerie.php, (e) surfer_anmeldung_NWL.php, (f) produkte_nach_serie_alle.php, (g) surfer_aendern.php, (h) ref_kd_rubrik.php, or (i) referenz.php in module/; or (j) 1/lay.php or (k) 3/lay.php in standard/.
0
Attacker Value
Unknown
CVE-2007-1938
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
Ichitaro 2005 through 2007, and possibly related products, allows remote attackers to have an unknown impact via unspecified vectors in a document distributed through e-mail or a web site, possibly due to a buffer overflow or cross-site scripting (XSS).
0