Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29551 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1038 1 Shemes.com 1 Grabit 2025-04-09 5.0 MEDIUM N/A
Shemes.com Grabit 1.5.3, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a .nzb file with a subject field containing ';' (semicolon) characters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-0633 1 T-systems Solutions For Research Gmbh 1 Mynews 2025-04-09 7.5 HIGH N/A
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.
CVE-2007-0622 1 Mybb 1 Mybb 2025-04-09 5.0 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in MyBB (aka MyBulletinBoard) 1.2.2 allows remote attackers to send messages to arbitrary users. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2007-0766 1 Remotesoft 1 .net Explorer 2025-04-09 9.3 HIGH N/A
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file.
CVE-2006-7150 1 Mambo 1 Mambo Open Source 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.
CVE-2007-2630 1 Activecampaign 1 1-2-all Broadcast Email 2025-04-09 6.5 MEDIUM N/A
Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via unspecified vectors. NOTE: this issue is reachable through filemanager/browser/default/browser.html.
CVE-2006-5120 1 Scott Metoyer 1 Red Mombin 2025-04-09 4.0 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.
CVE-2006-6949 1 Conti 1 Ftpserver 2025-04-09 4.6 MEDIUM N/A
Conti FTPServer 1.0 Build 2.8 stores user passwords in cleartext in MyServerSettings.ini, which allows local users to obtain sensitive information by reading this file.
CVE-2006-3887 1 Aol 1 Ygp Screensaver Activex Control 2025-04-09 7.5 HIGH N/A
Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2006-6550 1 Phorum 1 Phorum 2025-04-09 7.5 HIGH N/A
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the db_file parameter. NOTE: CVE disputes this vulnerability because db_file is defined before use
CVE-2007-4251 1 Openoffice 1 Openoffice 2025-04-09 4.3 MEDIUM N/A
OpenOffice.org (OOo) 2.2 does not properly handle files with multiple extensions, which allows user-assisted remote attackers to cause a denial of service.
CVE-2007-1624 1 Realguestbook 1 Realguestbook 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in realGuestbook 5.01 allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, and (4) text parameters to save_entry.php, as reachable through add_entry.php; and possibly other unspecified parameters and files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVE-2006-6460 2 Short Url, Url Tracker Script 2 Short Url, Url Tracker Script 2025-04-09 10.0 HIGH N/A
Yourfreeworld.com Short Url & Url Tracker Script allows remote attackers to obtain sensitive information via an invalid id parameter to login.php, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2509.
CVE-2007-3230 1 Simian Systems Inc 1 Sitellite 2025-04-09 6.8 MEDIUM N/A
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the htmlclass_path parameter.
CVE-2006-6602 1 Microsoft 2 Windows Explorer, Windows Xp 2025-04-09 4.3 MEDIUM N/A
explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file.
CVE-2007-1039 1 Peanutkb 1 Peanut Knowledge Base 2025-04-09 10.0 HIGH N/A
Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors.
CVE-2007-0382 1 Letterman 1 Letterman 2025-04-09 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in letterman.class.php in the Letterman 1.2.3 (com_letterman) component for Joomla! before 1.0.12 allow remote attackers to execute arbitrary SQL commands via the id parameter, related to the (1) lm_sendMail, (2) saveNewsletter, and (3) cancelNewsletter functions.
CVE-2007-0560 1 Asp Edge 1 Asp Edge 2025-04-09 7.5 HIGH N/A
SQL injection vulnerability in user.asp in ASP EDGE 1.2b and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.
CVE-2007-3964 1 Itaka 1 Itaka 2025-04-09 5.0 MEDIUM N/A
Itaka before 0.2.1, when using Authentication mode, allows remote attackers to bypass authentication and obtain sensitive information by downloading screenshots via a direct request for /screenshot.
CVE-2006-6444 1 Divx 1 Divx Player 2025-04-09 6.8 MEDIUM N/A
Stack-based buffer overflow in Nostra DivX Player 2.1, 2.2.00.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long string in an M3U file. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.