|
285191
|
- |
|
realnetworks
|
helix_player realplayer
|
RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (app…
|
CWE-189
Numeric Errors
|
CVE-2007-4904
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285192
|
- |
|
nuclearbb
|
nuclearbb
|
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the …
|
CWE-94
Code Injection
|
CVE-2007-4906
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285193
|
- |
|
winscp
|
winscp
|
Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-4909
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285194
|
- |
|
boa
|
boa_webserver
|
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allo…
|
CWE-20
Improper Input Validation
|
CVE-2007-4915
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285195
|
- |
|
hp
|
photo_and_imaging_gallery all-in-on_printer
|
Heap-based buffer overflow in the FileFind::FindFile method in (1) MFC42.dll, (2) MFC42u.dll, (3) MFC71.dll, and (4) MFC71u.dll in Microsoft Foundation Class (MFC) Library 8.0, as used by the ListFil…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2007-4916
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285196
|
- |
|
php-stats
|
php-stats
|
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vect…
|
CWE-79
Cross-site Scripting
|
CVE-2007-4917
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285197
|
- |
|
gelatocms
|
gelatocms
|
SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL commands via the post parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2007-4918
|
2018-10-16 06:38 |
2007-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285198
|
- |
|
ekiga openh323_project
|
ekiga openh323
|
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remote attackers to cause a denial of service (crash) via an invalid Content-Length…
|
CWE-20
Improper Input Validation
|
CVE-2007-4924
|
2018-10-16 06:38 |
2007-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285199
|
- |
|
axis
|
207w_camera
|
The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive information by sniffing the wireless network or by lev…
|
CWE-310
Cryptographic Issues
|
CVE-2007-4926
|
2018-10-16 06:38 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285200
|
- |
|
axis
|
207w_network_camera
|
axis-cgi/buffer/command.cgi on the AXIS 207W camera allows remote authenticated users to cause a denial of service (reboot) via many requests with unique buffer names in the buffername parameter in a…
|
CWE-20
Improper Input Validation
|
CVE-2007-4927
|
2018-10-16 06:38 |
2007-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|