Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2007-6640
Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to r…
Creammonkey
Mitigation only
MEDIUM 6.5
CVE-2007-6644
Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended…
Joomla
Mitigation only
HIGH 7.5
CVE-2007-6645
Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered use…
Joomla
Mitigation only
MEDIUM 5.8
CVE-2007-6636
Unspecified vulnerability in the StorageFarabDb module in Bitflu before 0.42 allows user-assisted remote attackers to create or append data to arbitr…
Bitflu
after 0.41
HIGH 10.0
CVE-2007-6638EPSS 13%
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain use…
3204 Dvr
No fix yet
HIGH 7.5
CVE-2007-6619
The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows r…
Jira
after 3.12
MEDIUM 5.0
CVE-2007-6603
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrato…
Hot Or Not Clone
No fix yet
MEDIUM 6.9
CVE-2007-6594
IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0…
Lotus Notes
after 8.0.1
MEDIUM 6.4
CVE-2007-5342EPSS 5%
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe…
Tomcat
Patch available
MEDIUM 5.0
CVE-2007-6512
PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…
Mysql Banner Exchange
Mitigation only
MEDIUM 5.0
CVE-2007-6334
Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the sa…
Ingres
Patch available
HIGH 10.0
CVE-2007-6507EPSS 37%
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.…
Serverprotect
Mitigation only
MEDIUM 6.5
CVE-2007-6495
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1…
Hosting Controller
No fix yet
MEDIUM 6.8
CVE-2007-6496
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the l…
Hosting Controller
No fix yet
HIGH 7.5
CVE-2007-6497
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6499
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions o…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6501
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a r…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6503
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary pl…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6504
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 6.4
CVE-2007-6470
phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values …
Phprpg
No fix yet
HIGH 9.4
CVE-2007-5856
Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote atta…
Mac Os X
Mitigation only
MEDIUM 6.4
CVE-2007-5857
Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which mig…
Mac Os X
Mitigation only
HIGH 9.3
CVE-2007-6413
Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup …
Solaris
Patch available
MEDIUM 5.0
CVE-2007-6395EPSS 6%
Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obt…
Board
after 1.2
MEDIUM 5.5
CVE-2007-6383
The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to c…
Chandler Server
after 0.10
MEDIUM 5.0
CVE-2007-6361
Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers…
Gekko
after 0.8.2
HIGH 8.5
CVE-2007-6350
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands includin…
Scponly
after 4.6
HIGH 7.1
CVE-2007-5969EPSS 14%
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a …
Mysql Server
after 5.0.50
HIGH 9.3
CVE-2007-6278
Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIM…
Libflac
after 1.2
MEDIUM 6.5
CVE-2007-6222
The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, whi…
Interleave
after 4.2.0