CVE-2007-5000
- EPSS 58.82%
- Veröffentlicht 13.12.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inje...
CVE-2007-6013
- EPSS 1.55%
- Veröffentlicht 19.11.2007 21:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
CVE-2007-1321
- EPSS 0.04%
- Veröffentlicht 30.10.2007 22:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" int...
CVE-2007-5593
- EPSS 2.51%
- Veröffentlicht 19.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
CVE-2007-5594
- EPSS 0.51%
- Veröffentlicht 19.10.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
CVE-2007-5191
- EPSS 0.1%
- Veröffentlicht 04.10.2007 16:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
CVE-2007-4000
- EPSS 30.11%
- Veröffentlicht 05.09.2007 10:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow...
- EPSS 22.61%
- Veröffentlicht 23.08.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffe...
- EPSS 3.01%
- Veröffentlicht 27.07.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of s...
CVE-2006-5752
- EPSS 15.9%
- Veröffentlicht 27.06.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...