CVE-2007-5594
- EPSS 0.48%
- Published 19.10.2007 23:17:00
- Last modified 09.04.2025 00:30:58
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
CVE-2007-5191
- EPSS 0.1%
- Published 04.10.2007 16:17:00
- Last modified 09.04.2025 00:30:58
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
CVE-2007-4000
- EPSS 10.43%
- Published 05.09.2007 10:17:00
- Last modified 09.04.2025 00:30:58
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow...
- EPSS 22.13%
- Published 23.08.2007 22:17:00
- Last modified 09.04.2025 00:30:58
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffe...
- EPSS 2.61%
- Published 27.07.2007 22:30:00
- Last modified 09.04.2025 00:30:58
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of s...
CVE-2006-5752
- EPSS 11.55%
- Published 27.06.2007 17:30:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...
CVE-2007-3304
- EPSS 0.21%
- Published 20.06.2007 22:30:00
- Last modified 09.04.2025 00:30:58
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...
CVE-2007-1320
- EPSS 0.16%
- Published 02.05.2007 17:19:00
- Last modified 09.04.2025 00:30:58
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to ...
CVE-2007-0455
- EPSS 4.93%
- Published 30.01.2007 17:28:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded...