|
283831
|
- |
|
libpng
|
libpng
|
Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG im…
|
CWE-189
Numeric Errors
|
CVE-2007-5267
|
2018-10-16 06:41 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283832
|
- |
|
adobe
|
acrobat acrobat_reader
|
Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on…
|
NVD-CWE-noinfo CWE-94
Code Injection
|
CVE-2007-5020
|
2018-10-16 06:40 |
2007-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283833
|
- |
|
dblog
|
dblog_cms
|
dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5026
|
2018-10-16 06:40 |
2007-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283834
|
- |
|
level_one
|
wbr3404tx
|
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2007-5027
|
2018-10-16 06:40 |
2007-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283835
|
- |
|
francisco_burzi
|
php-nuke
|
Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via an AddAuthor action with modified add_name and add_…
|
CWE-352
Origin Validation Error
|
CVE-2007-5032
|
2018-10-16 06:40 |
2007-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283836
|
- |
|
phpbb_xs
|
phpbb_xs
|
Cross-site scripting (XSS) vulnerability in profile.php in phpBB XS 2 allows remote attackers to inject arbitrary web script or HTML via the selfdes parameter in a profile_info editprofile action.
|
CWE-79
Cross-site Scripting
|
CVE-2007-5033
|
2018-10-16 06:40 |
2007-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283837
|
- |
|
elinks
|
elinks
|
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to snif…
|
CWE-200
Information Exposure
|
CVE-2007-5034
|
2018-10-16 06:40 |
2007-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283838
|
- |
|
mozilla
|
bugzilla
|
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the createemailregexp parameter, which allows remote at…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-5038
|
2018-10-16 06:40 |
2007-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283839
|
- |
|
ghostsecurity
|
ghost_security_suite
|
Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash…
|
CWE-264 CWE-20
Permissions, Privileges, and Access Controls Improper Input Validation
|
CVE-2007-5039
|
2018-10-16 06:40 |
2007-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283840
|
- |
|
ghostsecurity
|
ghost_security_suite
|
Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (cras…
|
CWE-264 CWE-20
Permissions, Privileges, and Access Controls Improper Input Validation
|
CVE-2007-5040
|
2018-10-16 06:40 |
2007-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|