Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2007-5644
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote a…
Vanilla
after 1.1.3
HIGH 9.3
CVE-2007-5338
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Sc…
Firefox
after 2.0.0.7
MEDIUM 6.9
CVE-2007-5587
Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2…
Safedisc
No fix yet
MEDIUM 6.8
CVE-2007-5571
Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to by…
Firewall Services Module
after 3.2
MEDIUM 6.4
CVE-2007-5486
dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via …
Dotproject
after 2.0.4
MEDIUM 5.0
CVE-2007-5468
Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote atta…
Call Manager
Mitigation only
MEDIUM 5.0
CVE-2007-5469
OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use snif…
Openser
Mitigation only
MEDIUM 6.5
CVE-2007-5441
CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some …
Cms Made Simple
Mitigation only
MEDIUM 5.0
CVE-2007-5439
CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 stores sensitive user information in log files with predictable names, which allows…
Etrust Integrated Threat Management
Mitigation only
HIGH 10.0
CVE-2007-5328EPSS 7%
The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…
Brightstor Arcserve Backup
Patch available
HIGH 10.0
CVE-2007-5382
The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) crea…
Wireless Lan Solution Engine
after 4.1.91.0
HIGH 7.2
CVE-2007-5254
VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privilege…
Vba32 Antivirus
Patch available
MEDIUM 5.0
CVE-2007-5260
ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database co…
Asp Cms
Mitigation only
MEDIUM 5.4
CVE-2007-5236
Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restri…
Jdk
Patch available
HIGH 7.5
CVE-2007-5230
admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administr…
Zomplog
Patch available
MEDIUM 6.8
CVE-2007-5223
Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified imp…
Affiliate Network Pro
Mitigation only
MEDIUM 6.0
CVE-2007-5210
Arbor Networks Peakflow SP before 3.5.1 patch 14, and 3.6.x before 3.6.1 patch 5, allows remote authenticated users to bypass access restrictions and…
Peakflow Sp
Patch available
MEDIUM 6.9
CVE-2007-5194
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as …
Rmake
Mitigation only
MEDIUM 5.0
CVE-2007-5170
Unspecified vulnerability in the embedded service processor (SP) before 3.09 in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) all…
Embedded Lights Out Manager
Patch available
MEDIUM 5.0
CVE-2007-5171
Unspecified vulnerability in Quicksilver Forums before 1.4.1 allows remote attackers to delete arbitrary PMs via unspecified vectors.
Quicksilver Forums
after 1.4.0
MEDIUM 5.0
CVE-2007-4873
SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrar…
Simplenews
Mitigation only
MEDIUM 5.0
CVE-2007-5134
Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might …
Catalyst 6500
Patch available
HIGH 7.2
CVE-2007-5101
ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local us…
Chironfs
after 1.0_rc6
HIGH 7.5
CVE-2007-5090
Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt da…
Rational Clearquest
No fix yet
HIGH 7.2
CVE-2007-4573
The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero …
Linux Kernel
after 2.6.22.6
HIGH 7.5
CVE-2007-5062
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register acti…
Flip
after 3.0
HIGH 7.5
CVE-2007-5038
The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the c…
Bugzilla
Patch available
MEDIUM 6.9
CVE-2007-5044
ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows loc…
Zonealarm
Mitigation only
MEDIUM 5.5
CVE-2007-4497
Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Pl…
Ace
after 6.0.1
MEDIUM 6.8
CVE-2007-4569
backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to…
Kde
Patch available