CVE-2007-3278
- EPSS 1.26%
- Veröffentlicht 19.06.2007 21:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:24
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host param...
CVE-2007-2875
- EPSS 0.44%
- Veröffentlicht 11.06.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:40:37
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading th...
CVE-2007-2691
- EPSS 2.85%
- Veröffentlicht 16.05.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:40:07
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
CVE-2007-2444
- EPSS 0.78%
- Veröffentlicht 14.05.2007 21:19:00
- Zuletzt bearbeitet 16.06.2026 22:39:36
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to ...
CVE-2007-2650
- EPSS 3.25%
- Veröffentlicht 14.05.2007 21:19:00
- Zuletzt bearbeitet 16.06.2026 22:40:02
The OLE2 parser in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service (resource consumption) via an OLE2 file with (1) a large property size or (2) a loop in the FAT file block chain that triggers an infinite loop, as demons...
- EPSS 11.31%
- Veröffentlicht 10.05.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:39:52
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL poin...
CVE-2007-1864
- EPSS 2.92%
- Veröffentlicht 09.05.2007 00:19:00
- Zuletzt bearbeitet 16.06.2026 22:38:27
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
CVE-2007-1320
- EPSS 0.49%
- Veröffentlicht 02.05.2007 17:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:20
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to ...
CVE-2007-1322
- EPSS 0.4%
- Veröffentlicht 02.05.2007 17:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:21
QEMU 0.8.2 allows local users to halt a virtual machine by executing the icebp instruction.
CVE-2007-1366
- EPSS 0.4%
- Veröffentlicht 02.05.2007 17:19:00
- Zuletzt bearbeitet 16.06.2026 22:37:26
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.