CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apache CanonicalFedoraproject+3 more7Fedora Http ServerHttp Server+4 moreApr 23, 2026 Dec 13, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 a...Show more |
2Fedoraproject Wordpress2Fedora WordpressApr 23, 2026 Nov 19, 2007 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentic...Show more |
3Debian FedoraprojectQemu4Debian Linux FedoraFedora Core+1 moreApr 23, 2026 Oct 30, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks,...Show more |
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack. |
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLoop Aes Utils+2 moreApr 23, 2026 Oct 4, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. |
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy doe...Show more |
3Apache CanonicalFedoraproject4Fedora Fedora CoreHttp Server+1 moreApr 23, 2026 Aug 23, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted dat...Show more |
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that intr...Show more |
4Apache CanonicalFedoraproject+1 more7Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+4 moreApr 23, 2026 Jun 27, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject a...Show more |
4Apache CanonicalFedoraproject+1 more6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+3 moreApr 23, 2026 Jun 20, 2007 N/A· v4 N/A· v3 4.7 MEDIUM· v2 Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is se...Show more |
4Debian FedoraprojectOpensuse+1 more5Debian Linux FedoraFedora Core+2 moreApr 23, 2026 May 2, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via u...Show more |
5Canonical FedoraprojectGd Graphics Library Project+2 more7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+4 moreApr 23, 2026 Jan 30, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...Show more |