|
283941
|
- |
|
aol
|
aim_lite aim_pro instant_messenger
|
The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML funct…
|
NVD-CWE-noinfo
|
CVE-2007-4901
|
2018-10-16 06:38 |
2007-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283942
|
- |
|
realnetworks
|
helix_player realplayer
|
RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (app…
|
CWE-189
Numeric Errors
|
CVE-2007-4904
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283943
|
- |
|
nuclearbb
|
nuclearbb
|
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the …
|
CWE-94
Code Injection
|
CVE-2007-4906
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283944
|
- |
|
winscp
|
winscp
|
Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4909
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283945
|
- |
|
boa
|
boa_webserver
|
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allo…
|
CWE-20
Improper Input Validation
|
CVE-2007-4915
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283946
|
- |
|
hp
|
photo_and_imaging_gallery all-in-on_printer
|
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFil…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4916
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283947
|
- |
|
php-stats
|
php-stats
|
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vect…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4917
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283948
|
- |
|
gelatocms
|
gelatocms
|
SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2007-4918
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283949
|
- |
|
ekiga openh323_project
|
ekiga openh323
|
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length…
|
CWE-20
Improper Input Validation
|
CVE-2007-4924
|
2018-10-16 06:38 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283950
|
- |
|
axis
|
207w_camera
|
The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by lev…
|
CWE-310
Cryptographic Issues
|
CVE-2007-4926
|
2018-10-16 06:38 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|